Patch size theft: Adversarial manipulation of VLM

New model theft attack extracts patch size and preprocessing from VLMs like GPT and Claude. Critical implications for security.

jueves, 2 de julio de 2026 • 2 min read • Q2BSTUDIO Team

Side channel attack reveals tokenization secret

In the current landscape of artificial intelligence, Vision-Language Models (VLMs) have become fundamental tools for companies seeking to automate processes, analyze images, or interact with users through AI agents. However, their deployment in production environments poses cybersecurity risks that many organizations underestimate. Recent research has revealed a new type of internal configuration extraction attack: it is possible to recover the visual patch size and preprocessing pipeline of a proprietary VLM through a side channel based on grid alignment. This purely black-box method exploits the ViT (Vision Transformer) architecture and causes periodic drops in accuracy by overlaying synthetic images with the hidden patch grid. The attacker only needs to measure the model's performance against grid patterns of different sizes, and through consistency tests can determine whether the preprocessing uses dynamic or fixed resolution, as well as the exact rescaling value.

The implications for enterprise security are profound. Knowing these parameters allows building more effective transfer attacks and adversarially manipulating the target model. From our cybersecurity services at Q2BSTUDIO, we help organizations identify and mitigate this type of vulnerability before it is exploited. It is not enough to protect the logical layers; the artificial intelligence infrastructure must be continuously audited, including the configuration of tokenizers, image preprocessing, and the execution environment itself. Companies that integrate AI for businesses need robust solutions that span from custom application development to monitoring models deployed on AWS and Azure cloud services.

The described technique demonstrates that even proprietary models like GPT or Claude can leak sensitive information through seemingly innocuous responses. To counteract this, we recommend applying patch obfuscation, adding controlled noise to predictions, and limiting access to granular performance metrics. At Q2BSTUDIO we develop custom software that natively incorporates these protections, in addition to integrating business intelligence services with Power BI to monitor model behavior in real time. The convergence between artificial intelligence and cybersecurity requires a preventive approach: from architecture to deployment, including constant validation of potential side channels. Our team, specialized in AI agents and process automation, works to ensure every implementation is secure, efficient, and scalable.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.