Skip to content
InfoResearchPreprintLLM-specific

Transferable Spatial Temporal Coherence Adversarial Attack on Black-Box Vision Language Models for Autonomous Driving

Published
Record updated
View JSON

Summary

Researchers introduce STCA (Spatial Temporal Coherence Adversarial Attack), a black-box method that perturbs driving video to fool Vision Language Models. The attack selects semantically important frames with caption guidance, applies a spatial perturbation that preserves high SSIM, then disrupts cross-frame temporal coherence with a motion-guided mask. Tested on BDD100K and nuScenes against Video LLaVA-7B, Qwen2.5-VL-7B and Dolphin, the spatial attack reaches a high ASR while keeping SSIM high, showing these models remain highly susceptible.