Figureure 1 · : Overview of DIFEFigure 1: Overview of DIFE. Traditional validation reads a poisoned CLIP checkpoint through a small set of attacknative tasks and reports native metrics. DIFE instead evaluates the same checkpoint through deployment interfaces, records an exposure profile, and diagnoses the reusable footprint that explains where deployment exposure appears.这张图概括 Beyond Native Success 的整体方法流程。阅读时先看模块之间传递的训练信号,再看作者如何把目标拆成可优化的子问题。Figureure 2 · : Deployment-interface exposure matrixFigure 2: Deployment-interface exposure matrix. Rows are poisoned checkpoints and columns are deployment interfaces. Each valid cell reports an interface-specific exposure metric; N.E. denotes no semantically valid exposure readout. The BADTEXTTOWER row is a forward reference to Section 5.这张图来自论文 PDF 的结构化抽取。当前用于辅助理解 Beyond Native Success 的方法或实验,请结合正文精读段落一起看。