Once Poisoned, Arbitrarily Controlled: A Programmable Backdoor in VLMs
This work shows that a single poisoning phase can implant a programmable backdoor into a VLM, allowing an attacker to choose previously unseen target-caption semantics at inference time and synthesize corresponding stealthy triggers on demand.