提出多面攻击框架,突破视觉大模型安全防线。
Effective Black-Box Multi-Faceted Attacks Breach Vision Large Language Model Guardrails
- 从视觉、对齐机制、文本结构三方面协同绕过安全防护
- 黑盒攻击成功率61.56%,较现有方法提升超42%
- 适合研究模型安全与对抗攻击的学者参考
视觉大语言模型(VLLMs)融合视觉处理能力,拓展了实际应用,但也增加了生成不安全内容的风险。为此,头部企业部署了多层安全防御,包括对齐训练、安全提示和内容审核。然而,这些防御在面对复杂对抗攻击时的有效性仍不清楚。本文提出多面攻击(MultiFaceted Attack)框架,系统性地绕过VLLM的多层安全机制。该框架包含三个互补攻击面:视觉攻击利用多模态特性,通过图像注入有毒系统提示;对齐破坏攻击操纵模型对齐机制,使其优先生成对立响应;对抗签名则通过在回答末尾放置误导信息,欺骗内容审核系统。在8个商用VLLM的黑盒设置下评估显示,该攻击成功率达61.56%,显著优于现有方法至少42.18%。
原文摘要 · Abstract (English)
Vision Large Language Models (VLLMs) integrate visual data processing, expanding their real-world applications, but also increasing the risk of generating unsafe responses. In response, leading companies have implemented Multi-Layered safety defenses, including alignment training, safety system prompts, and content moderation. However, their effectiveness against sophisticated adversarial attacks remains largely unexplored. In this paper, we propose MultiFaceted Attack, a novel attack framework designed to systematically bypass Multi-Layered Defenses in VLLMs. It comprises three complementary attack facets: Visual Attack that exploits the multimodal nature of VLLMs to inject toxic system prompts through images; Alignment Breaking Attack that manipulates the model's alignment mechanism to prioritize the generation of contrasting responses; and Adversarial Signature that deceives content moderators by strategically placing misleading information at the end of the response. Extensive evaluations on eight commercial VLLMs in a black-box setting demonstrate that MultiFaceted Attack achieves a 61.56% attack success rate, surpassing state-of-the-art methods by at least 42.18%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。