{"data":{"id":"31f9cb1e-b02c-4e21-8309-397af3f8b450","title":"Selective Channel Restoration for Backdoored Vision-Language Models","summary":"Researchers propose Perturb-Select-Restore (PSR), a post-training defense against backdoors in vision-language models (VLMs) implanted through poisoned fine-tuning data. PSR performs sparse updates to the projection interface and adds no computation at inference time. The authors report that backdoored VLM projectors are more sensitive to bounded perturbations than clean ones, a property they call projection fragility, and PSR reduces attack success rates to near zero while preserving clean-task performance.","solution":"PSR, a post-training defense that identifies the output channels most sensitive to perturbations in each projection layer of a backdoored VLM and restores their parameters to the corresponding pretrained values.","labels":["security","research"],"sourceUrl":"https://arxiv.org/abs/2609.37759v1","publishedAt":"2026-09-29T15:04:28.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["other"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["Vision-language models (VLMs)"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-09-29T15:04:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null}}