Related Experiment Videos
OCR-mediated modality dominance in vision-language models: implications for radiology AI trustworthiness
Izzet Turkalp Akbasli1,2, Baris Ozturk3, Oguzhan Serin2,4
1Hacettepe University Faculty of Medicine, Department of Pediatric Intensive Care Medicine, Ankara, Turkey.
Journal of Medical Imaging (Bellingham, Wash.)
|July 22, 2026
Summary
Vision-language models (VLMs) in radiology are vulnerable to text-based attacks that compromise diagnostic accuracy. Implementing robust system-level safeguards is crucial for secure clinical deployment of these AI tools.
Area of Science:
- Artificial Intelligence in Medical Imaging
- Computer Vision
- Radiology Decision Support Systems
Background:
- Vision-language models (VLMs) show promise for augmenting radiologic decision support.
- Security vulnerabilities of VLMs, particularly those with optical character recognition (OCR) capabilities, are not well understood in diagnostic workflows.
- Adversarial manipulation of image-embedded text poses a significant risk to diagnostic integrity.
Purpose of the Study:
- To evaluate the security implications of deploying OCR-capable VLMs in radiology.
- To assess the vulnerability of VLMs to adversarial attacks via embedded text.
- To investigate the effectiveness of prompt-level defenses against such attacks.
Main Methods:
- Ten VLMs were tested on 600 brain MRI studies for tumor detection.
- Evaluations included clean input, visible report injection, stealth OCR injection, and immune-prompt defense.
- A total of 27,000 inference calls were analyzed across five experimental conditions.
Main Results:
- Baseline VLM performance was heterogeneous (median accuracy 0.69).
- Visible and stealth OCR injection significantly degraded performance, causing specificity collapse (FPR 1.00) and reduced accuracy (median 0.43).
- Immune prompting offered only partial mitigation, with residual overcalling and persistent high false-positive rates.
Conclusions:
- Commercial VLMs exhibit a critical failure mode where OCR-readable text can override image evidence.
- Prompt-level defenses are insufficient to protect against these adversarial attacks.
- System-level safeguards, including OCR-aware input handling and human verification, are essential for safe clinical integration of VLMs.