Develop stronger online detectors

Develop stronger online detectors for identifying Feature-Aware Token Attack (FATA) inputs and related compression-triggered adversarial failures during vision-language model inference.

Background

The paper evaluates Feature Squeezing, Mahalanobis-Max, and the Multi-Level Activation Trajectory Detector (ML-ATD), but describes ML-ATD as not being an optimal defense. The conclusion therefore leaves unresolved the development of stronger online detection mechanisms capable of reliably identifying attacks that preserve full-token behavior while inducing errors after visual-token compression.

References

Black-box transfer, broader tasks, and stronger online detectors remain open.

— Feature-Aware Token Attack for Compression-Triggered Stealthy Failures in Large Vision-Language Models  (2609.39134 - Yan et al., 30 Sep 2026) in Section 6, Limitations