Once Poisoned, Arbitrarily Controlled: A Programmable Backdoor in VLMs
DGX agentarXiv:2608.10959v1 Announce Type: new Abstract: Existing vision-language model (VLM) backdoors are usually treated as static vulnerabilities: one-to-one and N-to-N attacks bind one or more triggers to