HEART Attacks: Healthcare Evaluation of Adversarial RobusTness
Rattachement africain : es. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
Large Vision-Language Models (LVLMs) have shown potential for integrating visual and textual information, yet they continue to exhibit limitations in visual reasoning and robustness, a particular concern in high-stakes domains such as healthcare. Prior robustness evaluations remain limited in breadth, typically focusing on a narrow set of medical modalities and tasks. Moreover, they study failure modes within a single modality (e.g., text negation or image swaps) overlooking one of the most sensitive aspects of LVLMs: how models leverage and combine information across modalities. To address this gap, we introduce BAIT (Blind-trust Adversarial Injection Toolkit), a general framework that converts vision datasets into controlled multimodal adversarial evaluations by injecting assistive or adversarial cues as prompt text and in-image overlays. Using BAIT, we build HEART (Healthcare Evaluation of Adversarial RobusTness), an adversarial benchmark created from several expert-annotated medical sources, covering multiple imaging modalities (e.g., radiology, ophthalmology, dermatology, etc.). We evaluate state-of-the-art LVLMs on HEART and observe that, despite moderate performance under non-adversarial conditions, even the most robust models exhibit catastrophic failures under adversarial conditions, with accuracy dropping below random chance due to LVLMs prioritizing injected misinformation over visual evidence. As a mitigation strategy, this work shows that out-of-distribution adversarial supervised fine-tuning and explicit system prompt warnings provide limited resilience to BAIT-style attacks. Together, BAIT and HEART define a scalable and flexible scheme for assessing the robustness of LVLMs in the context of multimodal information conflict, enabling the development of more reliable LVLMs for use in healthcare as well as in other multimodal domains.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- HEART Attacks: Healthcare Evaluation of Adversarial RobusTness
- Date Crossref
- 25/06/2026
- Éditeur
- ACM
- Type
- proceedings-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Où se fait cette recherche
-
Barcelona Supercomputing Center pays non établi dans la noticeStructure de recherche
-
Universitat Politècnica de Catalunya pays non établi dans la noticeUniversité ou école supérieure
Barcelona Supercomputing Center et Universitat Politècnica de Catalunya.
Une affiliation ne permet pas de déduire la nationalité d’un auteur.