Skip to content
InfoResearchPreprintLLM-specific

Visual Memory Attacks Can Persist Through The KV Cache

Published
Record updated
View JSON

Summary

Researchers show that adversarial images can plant a backdoor in a vision-language model that persists after the image is masked from attention. The persistent variant, Persistent Visual Memory Injection (P-VMI), reaches up to approximately 90% target success on Qwen3-VL-8B-Instruct, and a cache-swap ablation localizes the influence to the KV cache. The attacks also survive compaction that retains the KV cache of a model-generated summary.