This paper describes an architectural backdoor for vision-language model supply chains. A malicious provider embeds dormant, trigger-gated steering logic into model architecture or related executable artifacts. The modification is zero when the trigger is absent, preserving clean behavior, but shifts an intermediate representation toward an attacker-defined objective when activated. The authors report evaluations across multiple VLM families and tasks including visual question answering, text-to-image generation, retrieval, semantic response biasing, safety enforcement, and ranking fairness. The paper argues that auditing must inspect executable model logic, not only learned weights.
No heat snapshots are available in the last 24 hours.