{"id":"https://openalex.org/W4416830346","doi":"https://doi.org/10.1109/icmla66185.2025.00208","title":"JaiLIP: Jailbreaking Vision-Language Models via Loss Guided Image Perturbation","display_name":"JaiLIP: Jailbreaking Vision-Language Models via Loss Guided Image Perturbation","publication_year":2025,"publication_date":"2025-12-03","ids":{"openalex":"https://openalex.org/W4416830346","doi":"https://doi.org/10.1109/icmla66185.2025.00208"},"language":"en","primary_location":{"id":"doi:10.1109/icmla66185.2025.00208","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icmla66185.2025.00208","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Conference on Machine Learning and Applications (ICMLA)","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2509.21401","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5114403249","display_name":"Md Jueal Mia","orcid":null},"institutions":[{"id":"https://openalex.org/I19700959","display_name":"Florida International University","ror":"https://ror.org/02gz6gg07","country_code":"US","type":"education","lineage":["https://openalex.org/I19700959"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Md Jueal Mia","raw_affiliation_strings":["Florida International University,Knight Foundation School of Computing and Information Sciences (KFSCIS),Miami,Florida,USA"],"affiliations":[{"raw_affiliation_string":"Florida International University,Knight Foundation School of Computing and Information Sciences (KFSCIS),Miami,Florida,USA","institution_ids":["https://openalex.org/I19700959"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5032642808","display_name":"M. Hadi Amini","orcid":"https://orcid.org/0000-0002-2768-3601"},"institutions":[{"id":"https://openalex.org/I19700959","display_name":"Florida International University","ror":"https://ror.org/02gz6gg07","country_code":"US","type":"education","lineage":["https://openalex.org/I19700959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"M. Hadi Amini","raw_affiliation_strings":["Florida International University,Knight Foundation School of Computing and Information Sciences (KFSCIS),Miami,Florida,USA"],"affiliations":[{"raw_affiliation_string":"Florida International University,Knight Foundation School of Computing and Information Sciences (KFSCIS),Miami,Florida,USA","institution_ids":["https://openalex.org/I19700959"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5114403249"],"corresponding_institution_ids":["https://openalex.org/I19700959"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19474493,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1362","last_page":"1368"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.970300018787384,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.970300018787384,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.00559999980032444,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.00279999990016222,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.766700029373169},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5374000072479248},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.46140000224113464},{"id":"https://openalex.org/keywords/perturbation","display_name":"Perturbation (astronomy)","score":0.38929998874664307},{"id":"https://openalex.org/keywords/image-restoration","display_name":"Image restoration","score":0.3098999857902527}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.766700029373169},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.641700029373169},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5374000072479248},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4681999981403351},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.46140000224113464},{"id":"https://openalex.org/C177918212","wikidata":"https://www.wikidata.org/wiki/Q803623","display_name":"Perturbation (astronomy)","level":2,"score":0.38929998874664307},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3714999854564667},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3400000035762787},{"id":"https://openalex.org/C106430172","wikidata":"https://www.wikidata.org/wiki/Q6002272","display_name":"Image restoration","level":4,"score":0.3098999857902527},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3052999973297119},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2906000018119812},{"id":"https://openalex.org/C9417928","wikidata":"https://www.wikidata.org/wiki/Q1070689","display_name":"Image processing","level":3,"score":0.27379998564720154}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/icmla66185.2025.00208","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icmla66185.2025.00208","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Conference on Machine Learning and Applications (ICMLA)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2509.21401","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.21401","pdf_url":"https://arxiv.org/pdf/2509.21401","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2509.21401","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2509.21401","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2509.21401","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2509.21401","pdf_url":"https://arxiv.org/pdf/2509.21401","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-Language":[0],"Models":[1],"(VLMs)":[2],"have":[3,20,36,54,144],"remarkable":[4],"abilities":[5],"in":[6,44,81,139,148,161],"generating":[7,45],"multimodal":[8],"reasoning":[9],"tasks.":[10],"However,":[11],"potential":[12],"misuse":[13],"or":[14],"safety":[15],"alignment":[16],"concerns":[17],"of":[18,27,170],"VLMs":[19,113],"increased":[21],"significantly":[22],"due":[23],"to":[24,57,61,152],"different":[25],"categories":[26],"attack":[28,32,80],"vectors.":[29],"Among":[30],"various":[31],"vectors,":[33],"recent":[34],"studies":[35],"demonstrated":[37],"that":[38,85,126],"image-based":[39,171],"perturbations":[40],"are":[41],"particularly":[42],"effective":[43,131],"harmful":[46],"outputs.":[47],"In":[48,67],"the":[49,82,91,103,149,154,167,175],"literature,":[50],"many":[51],"existing":[52,137],"techniques":[53],"been":[55],"proposed":[56,110],"jailbreak":[58,172],"VLMs,":[59],"leading":[60],"unstable":[62],"performance":[63],"and":[64,99,121,132,174],"visible":[65],"perturbations.":[66],"this":[68],"study,":[69],"we":[70,143],"propose":[71],"Jailbreaking":[72],"with":[73,102],"Loss-guided":[74],"Image":[75],"Perturbation":[76],"(JaiLIP),":[77],"a":[78,87],"jailbreaking":[79],"image":[83,101],"space":[84],"minimizes":[86],"joint":[88],"objective":[89],"combining":[90],"mean":[92],"squared":[93],"error":[94],"(MSE)":[95],"loss":[96],"between":[97],"clean":[98],"adversarial":[100,134],"model\u2019s":[104],"harmful-output":[105],"loss.":[106],"We":[107],"evaluate":[108],"our":[109,127,146],"method":[111,128,147],"on":[112],"using":[114],"standard":[115],"toxicity":[116],"metrics":[117],"from":[118],"Perspective":[119],"API":[120],"Detoxify.":[122],"Experimental":[123],"results":[124],"demonstrate":[125,153],"generates":[129],"highly":[130],"imperceptible":[133],"images,":[135],"outperforming":[136],"methods":[138],"producing":[140],"toxicity.":[141],"Moreover,":[142],"evaluated":[145],"transportation":[150],"domain":[151],"attack\u2019s":[155],"practicality":[156],"beyond":[157],"toxic":[158],"text":[159],"generation":[160],"specific":[162],"domain.":[163],"Our":[164],"findings":[165],"emphasize":[166],"practical":[168],"challenges":[169],"attacks":[173],"need":[176],"for":[177,181],"efficient":[178],"defense":[179],"mechanisms":[180],"VLMs.":[182]},"counts_by_year":[],"updated_date":"2026-04-09T06:08:40.794217","created_date":"2025-10-10T00:00:00"}
