arXiv:2507.18053cs.CRcs.CL2025-07被引 2

用视觉输入诱导大模型无限生成,暴露资源耗尽漏洞。

Resource Consumption Red-Teaming for Large Vision-Language Models

  • 通过像素级优化生成可触发重复输出的对抗扰动
  • 使服务延迟提升26倍,显存与GPU占用增加20%
  • 首个针对视觉模态的资源消耗红队测试框架

资源消耗攻击(RCAs)已成为大型语言模型部署中的重大威胁。随着视觉模态的引入,大视觉语言模型(LVLMs)面临更多攻击面,现有红队研究却忽视了视觉输入这一潜在攻击途径,导致对LVLMs中RCAs的防御不足。为此,我们提出RECITE(Resource Consumption Red-Teaming for LVLMs),首个利用视觉模态触发无界资源消耗攻击的红队方法。首先,提出视觉引导优化(Vision Guided Optimization),在像素级别进行精细优化,生成可诱导重复输出的“输出召回目标”对抗扰动;随后将扰动注入视觉输入,引发无界生成以实现资源耗尽攻击。实验表明,RECITE使服务响应延迟提升超26倍,额外导致GPU利用率和内存消耗各增加20%。本研究揭示了LVLMs的安全隐患,并建立了一个可推动未来防御发展的红队测试框架。

原文摘要 · Abstract (English)

Resource Consumption Attacks (RCAs) have emerged as a significant threat to the deployment of Large Language Models (LLMs). With the integration of vision modalities, additional attack vectors exacerbate the risk of RCAs in large vision-language models (LVLMs). However, existing red-teaming studies have mainly overlooked visual inputs as a potential attack surface, resulting in insufficient mitigation strategies against RCAs in LVLMs. To address this gap, we propose RECITE ($\textbf{Re}$source $\textbf{C}$onsumpt$\textbf{i}$on Red-$\textbf{Te}$aming for LVLMs), the first approach for exploiting visual modalities to trigger unbounded RCAs red-teaming. First, we present $\textit{Vision Guided Optimization}$, a fine-grained pixel-level optimization to obtain \textit{Output Recall Objective} adversarial perturbations, which can induce repeating output. Then, we inject the perturbations into visual inputs, triggering unbounded generations to achieve the goal of RCAs. Empirical results demonstrate that RECITE increases service response latency by over 26 $\uparrow$, resulting in an additional 20\% increase in GPU utilization and memory consumption. Our study reveals security vulnerabilities in LVLMs and establishes a red-teaming framework that can facilitate the development of future defenses against RCAs.

视觉语言模型安全攻击红队测试资源消耗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。