← Latest papers
🤖 AI

From Clouds to Hallucinations: Atmospheric Retrieval Hijacking in Remote Sensing Vision-Language RAG

This paper introduces CloudWeb, the first atmospheric retrieval hijacking attack that subtly modifies remote sensing images with optimized cloud and haze patterns to force multimodal RAG systems to retrieve irrelevant weather-related evidence, thereby causing downstream hallucinations and semantic shifts in generated responses.

Original authors: Jiaju Han, Chao Li, Chengyin Hu, Qike Zhang, Xuemeng Sun, Xin Wang, Fengyu Zhang, Xiang Chen, Yiwei Wei, Jiahuan Long, Jiujiang Guo

Published 2026-05-11
📖 5 min read🧠 Deep dive

Original authors: Jiaju Han, Chao Li, Chengyin Hu, Qike Zhang, Xuemeng Sun, Xin Wang, Fengyu Zhang, Xiang Chen, Yiwei Wei, Jiahuan Long, Jiujiang Guo

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you have a super-smart AI assistant that acts like a remote sensing librarian. When you show it a satellite photo of a city, a farm, or a forest, this librarian doesn't just guess what it sees. Instead, it first runs to a massive digital library, finds the best matching descriptions or reports about that specific scene, and then uses those notes to write its final answer. This system is called RAG (Retrieval-Augmented Generation).

The paper introduces a new trick called CloudWeb, which is like a "magic fog" that tricks this librarian into pulling the wrong books off the shelf before it even starts writing.

Here is how it works, broken down into simple concepts:

1. The Setup: The Trusting Librarian

Normally, if you show the AI a photo of a sunny baseball field, the librarian looks at the photo, finds descriptions like "green grass," "diamond shape," and "sports field," and tells you, "This is a baseball field."

The system is designed to be very helpful, relying on external evidence to be accurate.

2. The Attack: The "Magic Fog" (CloudWeb)

The researchers discovered that they don't need to break the library, hack the computer, or rewrite the books. They only need to change the photo you show the librarian.

They developed a method to overlay a realistic-looking layer of clouds, haze, or fog onto the satellite image.

  • The Analogy: Imagine you take a photo of a sunny park. Then, you use a digital brush to paint a realistic-looking cloud over it. To a human eye, it still looks like a park, just a cloudy one.
  • The Trick: The researchers didn't just paint a cloud randomly. They used a computer algorithm to "tune" the cloud until it acted like a semantic magnet. They optimized the cloud so that when the librarian's computer "reads" the image, the cloud makes the image look more like a "weather report" than a "park."

3. The Hijack: Getting the Wrong Books

When the librarian (the retrieval system) sees this "cloudy" photo, it gets confused. Instead of looking for books about "baseball fields" or "farms," it suddenly thinks, "Oh, this looks like a weather event!"

It rushes to the library and pulls out the top 5 most relevant documents. But instead of finding descriptions of the ground, it finds documents about clouds, fog, low visibility, and mist.

  • The Result: The librarian is now "grounded" in the wrong evidence. It thinks the photo is about weather, even though the ground is still clearly visible.

4. The Hallucination: The Confused Storyteller

Once the librarian hands the wrong books to the AI writer (the generator), the writer follows the instructions in those books.

  • The Outcome: The AI, which was supposed to say "This is a baseball field," now says things like, "This image shows a baseball field obscured by heavy fog," or "The scene is covered in clouds."
  • The Danger: The AI isn't lying; it's just following the "evidence" it was given. But because the evidence was hijacked by the fake cloud, the final answer is a hallucination. It confidently describes weather that isn't the main feature of the image, or it misses the actual scene entirely.

5. Why This Matters

The paper shows that this attack works on seven different types of satellite datasets and five different types of AI librarians.

  • It's sneaky: The clouds look natural. They aren't weird, jagged computer noise that a human would spot immediately.
  • It's specific: The attack doesn't just break the system; it steers it specifically toward weather-related answers.
  • It's hard to stop: The researchers tested if blurring the image or compressing it would stop the attack, but the "magic fog" survived. It's built into the low-level structure of the image, not just the pixels.

The Bottom Line

The paper proves that in these advanced AI systems, changing the input image slightly (adding a cloud) can completely change the "facts" the AI relies on.

It's like if you showed a librarian a picture of a library, but you put a "Museum" sticker on the glass. The librarian would ignore the books inside and start talking about art history. The researchers showed that for remote sensing AI, a digital cloud can act as that sticker, hijacking the entire conversation before it even begins.

What the paper does NOT claim:

  • It does not say this works on medical images or clinical diagnoses.
  • It does not claim to have a fix for this yet (though it suggests checking for atmospheric patterns might help).
  • It does not say this is easy to do in the real world without powerful computers; it required significant computing power to "tune" the clouds for each attack.

The core message is a warning: If you trust an AI to find evidence for you, make sure the picture you show it hasn't been subtly "fogged" to point it in the wrong direction.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →