{"id":"W4416851502","doi":"10.1145/3733800.3763269","title":"When Vision Fails: Text Attacks Against ViT and OCR","year":2025,"lang":"","type":"article","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Vector Institute; University of Toronto","funders":"","keywords":"Unicode; Adversarial system; Comprehension; Character (mathematics); Class (philosophy); Key (lock); Optical character recognition; Language model","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":["metaepi_narrow","scholarly_communication"],"consensus_categories":[],"category_scores_codex":[0.001050137,0.0005258349,0.000561575,0.0004228438,0.0008245044,0.001759624,0.001609593,0.0003330214,0.0004290141],"category_scores_gemma":[0.000498239,0.0005048208,0.0001471961,0.0009168143,0.0003386553,0.002090374,0.003710972,0.000916429,0.0002307531],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0001514552,"about_ca_system_score_gemma":0.0002830209,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0001726182,"about_ca_topic_score_gemma":0.00004943019,"domain_scores_codex":[0.9960124,0.0004191475,0.0007303837,0.001491442,0.000562217,0.0007844184],"domain_scores_gemma":[0.9974645,0.0005912302,0.0002336453,0.001276019,0.0001883372,0.000246287],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.00004179541,0.0001135738,0.003008978,0.0001503615,0.00009575648,0.00004314198,0.002022536,0.009718394,0.0005705255,0.06801639,0.01503818,0.9011804],"study_design_scores_gemma":[0.001273177,0.0001535413,0.003933427,0.0004684288,0.00004889887,0.000007347621,0.0003918899,0.907262,0.0002279356,0.006059202,0.07954353,0.0006306218],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.007357946,0.001027434,0.8551086,0.01377542,0.00205794,0.0003873781,0.000001278303,0.0002550485,0.1200289],"genre_scores_gemma":[0.8728074,0.0002362348,0.09215233,0.003977892,0.000228545,0.00000891588,0.000003269674,0.00002977633,0.03055567],"genre_candidate":"methods","genre_consensus":null,"teacher_disagreement_score":0.9005498,"threshold_uncertainty_score":0.9997404,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.009273556421475487,"score_gpt":0.2879632870035365,"score_spread":0.278689730582061,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}