Related Experiment Videos
OCR-mediated modality dominance in vision-language models: implications for radiology AI trustworthiness
Izzet Turkalp Akbasli1,2, Baris Ozturk3, Oguzhan Serin2,4
1Hacettepe University Faculty of Medicine, Department of Pediatric Intensive Care Medicine, Ankara, Turkey.
Journal of Medical Imaging (Bellingham, Wash.)
|July 22, 2026
Summary
Vision-language models (VLMs) are vulnerable to security risks in radiology due to optical character recognition (OCR)-capable text injection. Adversarial text can override image data, compromising diagnostic accuracy and requiring robust system-level safeguards.
Area of Science:
- Artificial Intelligence in Medical Imaging
- Computer Vision Security
- Radiology Decision Support Systems
Background:
- Vision-language models (VLMs) show promise for augmenting radiologic decision-making.
- Security vulnerabilities of VLMs, particularly those with optical character recognition (OCR) capabilities, are not well understood in clinical contexts.
- Image-embedded text can be a vector for adversarial attacks, impacting diagnostic integrity.
Purpose of the Study:
- To evaluate the security implications of deploying OCR-capable VLMs in radiology workflows.
- To assess the susceptibility of VLMs to adversarial text injections, both visible and imperceptible.
- To determine the effectiveness of prompt-level defenses against such attacks.
Main Methods:
- Ten VLMs were tested on 600 brain MRI studies for tumor detection.
- Evaluations included clean input, visible report injection, stealth OCR injection, and immune-prompt defense.
- A total of 27,000 inference calls were analyzed across five conditions.
Main Results:
- Baseline VLM performance was heterogeneous (median accuracy 0.69).
- Visible and stealth OCR injections significantly degraded performance, causing specificity collapse (FPR 1.00) and reduced accuracy (median 0.43).
- Immune prompting offered only partial mitigation, with persistent false positives.
Conclusions:
- OCR-capable VLMs exhibit a critical failure mode where embedded text can override image evidence, even under stealth conditions.
- Prompt-level defenses are insufficient to protect against these vulnerabilities.
- Clinical deployment requires system-level safeguards like OCR-aware input handling and human verification.