Imagine you inherited a house and suspect the previous owner hid a few fake load-bearing walls—walls that look structural but actually conceal trap doors. You could tear the whole thing down and rebuild (expensive), or you could tap each wall with a hammer, listen for the hollow ones, and replace just those studs with originals from the architect's blueprint. That hammer-tap-and-replace is exactly what PSR does to a backdoored vision-language model's projection layers. The committed claim: backdoored VLM projectors exhibit a measurable property the authors call "projection fragility"—their output channels are substantially more sensitive to bounded perturbations than clean projectors. PSR exploits this asymmetry by perturbing projection layers, ranking channels by sensitivity, and surgically restoring the most fragile channels to their pretrained (clean) values. The result is near-zero attack success rates with negligible degradation to clean-task performance, all without retraining or per-query computational overhead. This sits in the broader fight over where to intervene in the VLM security pipeline. One camp says you defend during fine-tuning—adding regularization, filtering suspicious samples, constraining parameter drift. The other says post-hoc is better: inspect the trained model, find the damage, fix it. PSR plants its flag firmly in the post-hoc camp, and it does so with an unusually lightweight mechanism. Existing post-training defenses like pruning, mode connectivity analysis, or neural cleanse tend to require either full-model sweeps or auxiliary optimization. PSR's perturbation-based channel ranking is structurally simpler. The architectural insight is specific: the projection interface between the vision encoder and the language model is where backdoor behavior concentrates. This makes sense—the projector is the bottleneck where visual features get translated into the language model's token space, so poisoned fine-tuning data naturally leaves its heaviest fingerprint there. By restricting the defense to this interface, PSR avoids touching the much larger vision encoder or LLM backbone entirely. Integrity-wise, the paper reports experiments across multiple tasks, though the abstract does not name specific benchmarks, attack types, or baseline defenses with numbers. The claim of "near-zero attack success rates" is strong but needs the specifics of which attacks (BadNets, blended, WaNet, etc.) and which VLM architectures were tested. The 14-page length suggests reasonable experimental coverage, but without named SOTA comparisons in the abstract, we're trusting the full paper to deliver. The milestone question is practical: can this generalize beyond the projection layer? If future VLM architectures distribute the vision-language interface differently—say, through cross-attention at every layer rather than a single projection block—PSR's channel-restoration logic would need to be extended. The next number to watch is whether fragility detection holds across architecturally diverse VLMs (LLaVA, InstructBLIP, Qwen-VL, etc.) and across more sophisticated adaptive attacks designed to minimize projection fragility. The obvious experiment not run: adaptive attacks where the adversary knows PSR exists and specifically crafts backdoors to distribute fragility evenly across channels, defeating the sensitivity-ranking mechanism. This is the standard arms-race test in backdoor defense. The honest read is (a)—this is likely a compute and scope constraint for a first paper establishing the fragility phenomenon. Expect the adaptive-attack robustness study in a follow-up.