arXiv:2508.18805cs.CRcs.CV2025-08被引 2

让视觉语言模型生成超长输出,悄悄耗尽资源却不被察觉

Hidden Tail: Adversarial Image Causing Stealthy Resource Consumption in Vision-Language Models

  • 用不可见特殊标记诱导模型无限生成内容
  • 输出长度提升最高达19.2倍,突破最大令牌限制
  • 攻击隐蔽性强,适合研究模型安全漏洞的团队

视觉语言模型(VLMs)在现实应用中日益普及,但其高昂的推理成本使其易受资源消耗攻击。现有攻击通过优化对抗性图像延长输出序列,但常引入无关异常内容,影响攻击隐蔽性。该效果与隐蔽性之间的权衡是现有攻击的主要局限。为此,我们提出 extit{Hidden Tail},一种提示无关的隐蔽资源消耗攻击,通过生成不可见的特殊标记,诱导 VLM 生成最长输出。方法采用复合损失函数,动态平衡语义保持、重复特殊标记诱导与结束符(EOS)抑制。大量实验表明, extit{Hidden Tail} 显著优于现有攻击,输出长度最多提升19.2倍,达到最大令牌限制,同时保持攻击隐蔽性。结果凸显了提升 VLM 对效率导向对抗威胁鲁棒性的紧迫性。代码已公开于 https://github.com/zhangrui4041/Hidden_Tail。

原文摘要 · Abstract (English)

Vision-Language Models (VLMs) are increasingly deployed in real-world applications, but their high inference cost makes them vulnerable to resource consumption attacks. Prior attacks attempt to extend VLM output sequences by optimizing adversarial images, thereby increasing inference costs. However, these extended outputs often introduce irrelevant abnormal content, compromising attack stealthiness. This trade-off between effectiveness and stealthiness poses a major limitation for existing attacks. To address this challenge, we propose \textit{Hidden Tail}, a stealthy resource consumption attack that crafts prompt-agnostic adversarial images, inducing VLMs to generate maximum-length outputs by appending special tokens invisible to users. Our method employs a composite loss function that balances semantic preservation, repetitive special token induction, and suppression of the end-of-sequence (EOS) token, optimized via a dynamic weighting strategy. Extensive experiments show that \textit{Hidden Tail} outperforms existing attacks, increasing output length by up to 19.2$\times$ and reaching the maximum token limit, while preserving attack stealthiness. These results highlight the urgent need to improve the robustness of VLMs against efficiency-oriented adversarial threats. Our code is available at https://github.com/zhangrui4041/Hidden_Tail.

视觉语言模型对抗攻击资源消耗隐蔽攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。