{"id":"https://openalex.org/W4415707801","doi":"https://doi.org/10.1109/icme59968.2025.11210045","title":"PiCo: Jailbreaking Multimodal Large Language Models via Pictorial Code Contextualization","display_name":"PiCo: Jailbreaking Multimodal Large Language Models via Pictorial Code Contextualization","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4415707801","doi":"https://doi.org/10.1109/icme59968.2025.11210045"},"language":null,"primary_location":{"id":"doi:10.1109/icme59968.2025.11210045","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme59968.2025.11210045","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5010675602","display_name":"A. Q. Liu","orcid":"https://orcid.org/0000-0002-0126-5778"},"institutions":[{"id":"https://openalex.org/I4210164862","display_name":"Artificial Intelligence in Medicine (Canada)","ror":"https://ror.org/05p590m36","country_code":"CA","type":"company","lineage":["https://openalex.org/I4210164862"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Aofan Liu","raw_affiliation_strings":["Wuhan University,School of Artificial Intelligence"],"affiliations":[{"raw_affiliation_string":"Wuhan University,School of Artificial Intelligence","institution_ids":["https://openalex.org/I4210164862"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018805700","display_name":"Lulu Tang","orcid":"https://orcid.org/0000-0003-0612-9780"},"institutions":[{"id":"https://openalex.org/I4210164862","display_name":"Artificial Intelligence in Medicine (Canada)","ror":"https://ror.org/05p590m36","country_code":"CA","type":"company","lineage":["https://openalex.org/I4210164862"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Lulu Tang","raw_affiliation_strings":["Wuhan University,School of Artificial Intelligence"],"affiliations":[{"raw_affiliation_string":"Wuhan University,School of Artificial Intelligence","institution_ids":["https://openalex.org/I4210164862"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100783702","display_name":"Ting Pan","orcid":"https://orcid.org/0000-0002-4199-4756"},"institutions":[{"id":"https://openalex.org/I4210100255","display_name":"Beijing Academy of Artificial Intelligence","ror":"https://ror.org/016a74861","country_code":"CN","type":"other","lineage":["https://openalex.org/I4210100255"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ting Pan","raw_affiliation_strings":["Beijing Academy of Artificial Intelligence"],"affiliations":[{"raw_affiliation_string":"Beijing Academy of Artificial Intelligence","institution_ids":["https://openalex.org/I4210100255"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102514692","display_name":"Yuguo Yin","orcid":null},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuguo Yin","raw_affiliation_strings":["Peking University,School of Electronic and Computer Engineering"],"affiliations":[{"raw_affiliation_string":"Peking University,School of Electronic and Computer Engineering","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100372378","display_name":"Bin Wang","orcid":"https://orcid.org/0000-0002-6242-7726"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bin Wang","raw_affiliation_strings":["Peking University,School of Electronic and Computer Engineering"],"affiliations":[{"raw_affiliation_string":"Peking University,School of Electronic and Computer Engineering","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5102733593","display_name":"Ao Yang","orcid":"https://orcid.org/0009-0002-5393-191X"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ao Yang","raw_affiliation_strings":["Peking University,School of Electronic and Computer Engineering"],"affiliations":[{"raw_affiliation_string":"Peking University,School of Electronic and Computer Engineering","institution_ids":["https://openalex.org/I20231570"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5010675602"],"corresponding_institution_ids":["https://openalex.org/I4210164862"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.17502285,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9115999937057495,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9115999937057495,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.03959999978542328,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.003599999938160181,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.5515999794006348},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5375999808311462},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.5049999952316284},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.4794999957084656},{"id":"https://openalex.org/keywords/modalities","display_name":"Modalities","score":0.47360000014305115},{"id":"https://openalex.org/keywords/modality","display_name":"Modality (human\u2013computer interaction)","score":0.428600013256073},{"id":"https://openalex.org/keywords/contextualization","display_name":"Contextualization","score":0.38029998540878296},{"id":"https://openalex.org/keywords/metric","display_name":"Metric (unit)","score":0.3598000109195709}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8176000118255615},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.5515999794006348},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5375999808311462},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.5049999952316284},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.4794999957084656},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.47760000824928284},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.47360000014305115},{"id":"https://openalex.org/C2780226545","wikidata":"https://www.wikidata.org/wiki/Q6888030","display_name":"Modality (human\u2013computer interaction)","level":2,"score":0.428600013256073},{"id":"https://openalex.org/C2780712339","wikidata":"https://www.wikidata.org/wiki/Q5165204","display_name":"Contextualization","level":3,"score":0.38029998540878296},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.374099999666214},{"id":"https://openalex.org/C176217482","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Metric (unit)","level":2,"score":0.3598000109195709},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.3578000068664551},{"id":"https://openalex.org/C2780878386","wikidata":"https://www.wikidata.org/wiki/Q1659648","display_name":"Visual language","level":2,"score":0.34869998693466187},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.34150001406669617},{"id":"https://openalex.org/C124304363","wikidata":"https://www.wikidata.org/wiki/Q673661","display_name":"Abstraction","level":2,"score":0.33880001306533813},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.328000009059906},{"id":"https://openalex.org/C183322885","wikidata":"https://www.wikidata.org/wiki/Q17007702","display_name":"Context model","level":3,"score":0.30970001220703125},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.29739999771118164},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.28870001435279846},{"id":"https://openalex.org/C2781265381","wikidata":"https://www.wikidata.org/wiki/Q5710255","display_name":"Helpfulness","level":2,"score":0.2703000009059906},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.266400009393692},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.25440001487731934}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icme59968.2025.11210045","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icme59968.2025.11210045","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Multimedia and Expo (ICME)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W4389518968","https://openalex.org/W4389617257","https://openalex.org/W4393157467","https://openalex.org/W4395034112","https://openalex.org/W4401043746","https://openalex.org/W4402670087","https://openalex.org/W4402670570","https://openalex.org/W4404534381","https://openalex.org/W4404575065","https://openalex.org/W4404783010","https://openalex.org/W4404971291","https://openalex.org/W4405181600","https://openalex.org/W4407207546","https://openalex.org/W4409348010","https://openalex.org/W4410609100"],"related_works":[],"abstract_inverted_index":{"Multimodal":[0],"Large":[1,12],"Language":[2,13],"Models":[3,14],"(MLLMs),":[4],"which":[5],"integrate":[6],"vision":[7],"and":[8,34,74,105,132],"other":[9],"modalities":[10],"into":[11],"(LLMs),":[15],"significantly":[16],"enhance":[17],"AI":[18],"capabilities":[19],"but":[20],"also":[21],"introduce":[22],"new":[23,94],"security":[24],"vulnerabilities.":[25],"By":[26,111],"exploiting":[27],"the":[28,31,35,89,103,142,149],"vulnerabilities":[29],"of":[30,39,91,107,127],"visual":[32,117],"modality":[33],"long-tail":[36],"distribution":[37],"characteristic":[38],"code":[40],"training":[41],"data,":[42],"we":[43],"present":[44],"PiCo,":[45],"a":[46,62,93],"novel":[47],"jailbreaking":[48],"framework":[49],"designed":[50],"to":[51,70,82,100,155],"progressively":[52],"bypass":[53,83],"multi-tiered":[54],"defense":[55],"mechanisms":[56],"in":[57,145],"advanced":[58,157],"MLLMs.":[59,158],"PiCo":[60,119],"employs":[61],"tier-by-tier":[63],"jailbreak":[64],"strategy,":[65],"using":[66],"token-level":[67],"typographic":[68],"attacks":[69],"evade":[71],"input":[72],"filtering":[73],"embedding":[75,112],"harmful":[76,113],"intent":[77,114],"within":[78,115],"programming":[79],"context":[80],"instructions":[81],"runtime":[84],"monitoring.":[85],"To":[86],"comprehensively":[87],"assess":[88,101],"impact":[90],"attacks,":[92],"evaluation":[95],"metric":[96],"is":[97],"further":[98],"proposed":[99],"both":[102],"toxicity":[104],"helpfulness":[106],"model":[108],"outputs":[109],"post-attack.":[110],"code-style":[116],"instructions,":[118],"achieves":[120],"an":[121],"average":[122],"Attack":[123],"Success":[124],"Rate":[125],"(ASR)":[126],"84.13%":[128],"on":[129,134],"Gemini-Pro":[130],"Vision":[131],"52.66%":[133],"GPT-4,":[135],"surpassing":[136],"previous":[137],"methods.":[138],"Experimental":[139],"results":[140],"highlight":[141],"critical":[143],"gaps":[144],"current":[146],"defenses,":[147],"underscoring":[148],"need":[150],"for":[151],"more":[152],"robust":[153],"strategies":[154],"secure":[156],"Content":[159],"Warning:":[160],"This":[161],"paper":[162],"contains":[163],"examples":[164],"that":[165],"may":[166],"be":[167],"offensive.":[168]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-10-30T00:00:00"}
