用视觉上下文隐藏恶意指令,突破多模态模型安全防线
Contextual Image Attack: How Visual Context Exposes Multimodal Safety Vulnerabilities
- 以图像为中心设计攻击,通过四种可视化策略嵌入恶意内容
- 对GPT-4o和Qwen2.5-VL-72B的攻击成功率超91%,毒性得分达4.83
- 适合研究多模态安全、对抗攻击或模型鲁棒性的学者参考
多模态大语言模型(MLLMs)虽具强大能力,但其安全对齐易受越狱攻击。现有方法多聚焦文本与图像的交互,将视觉模态视为次要提示,低估了图像承载复杂上下文信息的潜力。为此,我们提出一种以图像为中心的攻击方法——上下文图像攻击(CIA),利用多智能体系统,通过四种不同可视化策略将有害查询隐蔽嵌入看似无害的视觉上下文中。为进一步提升攻击效果,系统引入上下文元素增强与自动毒性混淆技术。在MMSafetyBench-tiny数据集上的实验表明,CIA对GPT-4o和Qwen2.5-VL-72B模型的毒性得分分别达到4.73和4.83,攻击成功率达86.31%和91.07%。结果表明,视觉模态本身即为突破先进MLLM安全防护的有效路径。
原文摘要 · Abstract (English)
While Multimodal Large Language Models (MLLMs) show remarkable capabilities, their safety alignments are susceptible to jailbreak attacks. Existing attack methods typically focus on text-image interplay, treating the visual modality as a secondary prompt. This approach underutilizes the unique potential of images to carry complex, contextual information. To address this gap, we propose a new image-centric attack method, Contextual Image Attack (CIA), which employs a multi-agent system to subtly embeds harmful queries into seemingly benign visual contexts using four distinct visualization strategies. To further enhance the attack's efficacy, the system incorporate contextual element enhancement and automatic toxicity obfuscation techniques. Experimental results on the MMSafetyBench-tiny dataset show that CIA achieves high toxicity scores of 4.73 and 4.83 against the GPT-4o and Qwen2.5-VL-72B models, respectively, with Attack Success Rates (ASR) reaching 86.31\% and 91.07\%. Our method significantly outperforms prior work, demonstrating that the visual modality itself is a potent vector for jailbreaking advanced MLLMs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。