{"id":"W4416851502","doi":"10.1145/3733800.3763269","title":"When Vision Fails: Text Attacks Against ViT and OCR","year":2025,"lang":"","type":"article","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Vector Institute; University of Toronto","funders":"","keywords":"Unicode; Adversarial system; Comprehension; Character (mathematics); Class (philosophy); Key (lock); Optical character recognition; Language model","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001779091,0.0007828668,0.0005256612,0.0004943504,0.0005229977,0.0009489178,0.000946149,0.001927583,0.001769978],"category_scores_gemma":[0.01451097,0.0003172555,0.0006952189,0.0002376373,0.001786321,0.001989435,0.00180344,0.001716494,0.0006835792],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001021233,"about_ca_system_score_gemma":0.0004481654,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001999683,"about_ca_topic_score_gemma":0.001144008,"domain_scores_codex":[0.9977615,0.0007980244,0.00007734169,0.0003803934,0.0007970996,0.0001856734],"domain_scores_gemma":[0.9934965,0.003695565,0.0006095092,0.001679761,0.0003655125,0.0001531896],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001083853,0.0002003298,0.006825869,0.0002831797,0.0002815907,0.002177937,0.0008825399,0.6896025,0.08832863,0.07005209,0.01222208,0.1280594],"study_design_scores_gemma":[0.00002699116,0.0001688969,0.0007828271,0.00004087925,0.00002558331,0.0004978494,0.00006245742,0.9371967,0.04113175,0.0168156,0.003219457,0.0000309138],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.496073,0.0007095126,0.4706858,0.003446969,0.0003140309,0.0002122412,0.0004375998,0.006280954,0.02183992],"genre_scores_gemma":[0.9751652,0.00009512099,0.02184414,0.0004006058,0.00002268768,0.00003025233,0.00009842597,0.0001527589,0.002190817],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.001999683,"threshold_uncertainty_score":0.009408891,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.009273556421475487,"score_gpt":0.2879632870035365,"score_spread":0.278689730582061,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}