acceptodds
Under review as a conference paper at ICLR 2027

Profiling Compression, Disrupting Distributions: Structured Adversarial Attacks on Token-Compressed Large Vision-Language Models

Abstract

Visual token compression offers a promising pathway to improve the efficiency of large vision-language models (LVLMs). However, it creates a fundamental mismatch for adversarial attacks: compression acts on token representations, whereas attack success is evaluated at the sequence level. Existing attacks typically identify tokens likely to survive compression and optimize perturbations over this predicted survivor set. Yet this strategy overlooks two challenges: token utility varies across compression schemes, and independent survival scores cannot capture the joint attack effect of retained tokens. To address these challenges, we propose Compression-Aware Profiling with Coordinated Distributional Disruption (CLOUD), a novel framework for conducting adversarial attacks that remain effective across distinct token-compression schemes. The key idea is to profile compression-dependent attack utility with a surrogate pool and then coordinate support construction with distributional perturbation. Specifically, we first introduce a utility-guided surrogate probing module, which applies Bayesian optimization over the surrogate configuration space to characterize compression-aware attack responses. Subsequently, we construct a dynamic cache to aggregate token-retention patterns and representation shifts across surrogates to calibrate the attack budget. Guided by these profiles, we leverage a determinantal point process (DPP) to construct a diverse support set by balancing compression resilience with complementary evidence coverage. Additionally, we maximize the discrepancy between clean evidence and its post-compression adversarial counterpart from the perspective of optimal transport (OT). This coordinated objective encourages the attack effect to persist after token reduction. Experiments across multiple LVLM backbones and compression schemes show that CLOUD consistently outperforms strong baselines. Code is available at https://anonymous.4open.science/r/CLOUD_For_Token_Compression_Robustness.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.