כתבה
arXiv cs.CL ·
היפוך אינדקסים ויזואליים רב-ווקטוריים
Inverting Multi-Vector Visual Document Indices
חוקרים גילו כי ניתן להיפוך אינדקסים ויזואאליים רב-ווקטוריים, המשמשים לאחסון מסמכים, ולשחזר את המסמכים המקוריים. המחקר הראה כי ניתן לשחזר 47% מהמילים ו-45% מהטוקנים הרגישים. החוקרים בדקו גם שיטות הגנה זולות, כגון ריכוז טוקנים וערבוב וקטורים.
תקציר מקורי באנגליתarXiv:2610.09920v1 Announce Type: cross Abstract: Prevailing multi-vector visual document retrievers store each page as about a thousand patch vectors, often in vector databases run by a third party. Since no one can read a page from its vectors, this index is easily treated as less sensitive than the page. However, because the index keeps one vector per patch in raster order, and each vector is computed by a vision-language model pre-trained to read documents, we hypothesize that whoever runs or breaches the store can reproduce a page from its index alone. We frame inversion as conditional document image generation and infer from the vectors what the attack needs: the encoder, the page shape and, for shuffled vectors, their order. On the ViDoRe v3 benchmark, pages inverted from raw indice
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית