{"id":"https://openalex.org/W4406110392","doi":"https://doi.org/10.1109/tcsvt.2025.3526248","title":"Align Is Not Enough: Multimodal Universal Jailbreak Attack Against Multimodal Large Language Models","display_name":"Align Is Not Enough: Multimodal Universal Jailbreak Attack Against Multimodal Large Language Models","publication_year":2025,"publication_date":"2025-01-06","ids":{"openalex":"https://openalex.org/W4406110392","doi":"https://doi.org/10.1109/tcsvt.2025.3526248"},"language":"en","primary_location":{"id":"doi:10.1109/tcsvt.2025.3526248","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tcsvt.2025.3526248","pdf_url":null,"source":{"id":"https://openalex.org/S115173108","display_name":"IEEE Transactions on Circuits and Systems for Video Technology","issn_l":"1051-8215","issn":["1051-8215","1558-2205"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Circuits and Systems for Video Technology","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5035229016","display_name":"Youze Wang","orcid":"https://orcid.org/0009-0003-5621-6310"},"institutions":[{"id":"https://openalex.org/I16365422","display_name":"Hefei University of Technology","ror":"https://ror.org/02czkny70","country_code":"CN","type":"education","lineage":["https://openalex.org/I16365422"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Youze Wang","raw_affiliation_strings":["School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China","institution_ids":["https://openalex.org/I16365422"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058191990","display_name":"Wenbo Hu","orcid":"https://orcid.org/0000-0002-0639-2012"},"institutions":[{"id":"https://openalex.org/I16365422","display_name":"Hefei University of Technology","ror":"https://ror.org/02czkny70","country_code":"CN","type":"education","lineage":["https://openalex.org/I16365422"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenbo Hu","raw_affiliation_strings":["School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China","institution_ids":["https://openalex.org/I16365422"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068755794","display_name":"Yinpeng Dong","orcid":"https://orcid.org/0000-0003-1299-683X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinpeng Dong","raw_affiliation_strings":["Department of Computer Science and Technology, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108392430","display_name":"Jing Liu","orcid":"https://orcid.org/0000-0003-0903-9131"},"institutions":[{"id":"https://openalex.org/I4210094879","display_name":"Shandong Institute of Automation","ror":"https://ror.org/00qdtba35","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210094879","https://openalex.org/I4210142748"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jing Liu","raw_affiliation_strings":["Institute of Automation, Chinese Academy of Science, Beijing, China","Institute of automation, Chinese academy of science, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Automation, Chinese Academy of Science, Beijing, China","institution_ids":["https://openalex.org/I4210094879"]},{"raw_affiliation_string":"Institute of automation, Chinese academy of science, Beijing, China","institution_ids":["https://openalex.org/I4210094879"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5042324027","display_name":"Hanwang Zhang","orcid":"https://orcid.org/0000-0001-7374-8739"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Hanwang Zhang","raw_affiliation_strings":["School of Computer Science and Engineering, Nanyang Technological University, Jurong West, Singapore"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanyang Technological University, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5051332325","display_name":"Richang Hong","orcid":"https://orcid.org/0000-0001-5461-3986"},"institutions":[{"id":"https://openalex.org/I16365422","display_name":"Hefei University of Technology","ror":"https://ror.org/02czkny70","country_code":"CN","type":"education","lineage":["https://openalex.org/I16365422"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Richang Hong","raw_affiliation_strings":["School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Information Engineering, Hefei University of Technology, Hefei, China","institution_ids":["https://openalex.org/I16365422"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5035229016"],"corresponding_institution_ids":["https://openalex.org/I16365422"],"apc_list":null,"apc_paid":null,"fwci":7.0705,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.95836825,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":"35","issue":"6","first_page":"5475","last_page":"5488"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9613000154495239,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9613000154495239,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12151","display_name":"Interpreting and Communication in Healthcare","score":0.9412000179290771,"subfield":{"id":"https://openalex.org/subfields/3600","display_name":"General Health Professions"},"field":{"id":"https://openalex.org/fields/36","display_name":"Health Professions"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.9111999869346619,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7707351446151733},{"id":"https://openalex.org/keywords/modalities","display_name":"Modalities","score":0.6385335326194763},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5573545694351196},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5118247866630554},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.45700016617774963},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4185869097709656},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.34267789125442505},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.32760298252105713}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7707351446151733},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.6385335326194763},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5573545694351196},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5118247866630554},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.45700016617774963},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4185869097709656},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.34267789125442505},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.32760298252105713},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tcsvt.2025.3526248","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tcsvt.2025.3526248","pdf_url":null,"source":{"id":"https://openalex.org/S115173108","display_name":"IEEE Transactions on Circuits and Systems for Video Technology","issn_l":"1051-8215","issn":["1051-8215","1558-2205"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Circuits and Systems for Video Technology","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2711818151","display_name":null,"funder_award_id":"62306098","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5121304569","display_name":null,"funder_award_id":"No. 62306098","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5586753922","display_name":null,"funder_award_id":"U23B2031","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8604869356","display_name":null,"funder_award_id":"JZ2024HGTB0256","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W3171288285","https://openalex.org/W4283317927","https://openalex.org/W4315929005","https://openalex.org/W4361991035","https://openalex.org/W4376607895","https://openalex.org/W4386038437","https://openalex.org/W4389988150","https://openalex.org/W4390778981","https://openalex.org/W4393157467","https://openalex.org/W4401043746","https://openalex.org/W4402510626","https://openalex.org/W4402727669","https://openalex.org/W4404356490","https://openalex.org/W6739868092","https://openalex.org/W6766978945","https://openalex.org/W6846645824","https://openalex.org/W6851592950","https://openalex.org/W6851950068","https://openalex.org/W6852776751","https://openalex.org/W6852818750","https://openalex.org/W6853116092","https://openalex.org/W6853469104","https://openalex.org/W6854337558","https://openalex.org/W6855391713","https://openalex.org/W6855447051","https://openalex.org/W6855469472","https://openalex.org/W6856397199","https://openalex.org/W6857049399","https://openalex.org/W6857320562","https://openalex.org/W6857872576","https://openalex.org/W6858033984","https://openalex.org/W6858268588","https://openalex.org/W6860041859","https://openalex.org/W6861352133","https://openalex.org/W6861848220","https://openalex.org/W6869261340","https://openalex.org/W6869597577","https://openalex.org/W6869609294","https://openalex.org/W6873338258","https://openalex.org/W6876048176"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W4288019534"],"abstract_inverted_index":{"Large":[0,8],"Language":[1,9],"Models":[2,10],"(LLMs)":[3],"have":[4,65],"evolved":[5],"into":[6],"Multimodal":[7],"(MLLMs),":[11],"significantly":[12],"enhancing":[13],"their":[14],"capabilities":[15],"by":[16,60,70,76,82],"integrating":[17],"visual":[18],"information":[19],"and":[20,87,106,115,163,165,200],"other":[21],"types,":[22],"thus":[23],"aligning":[24],"more":[25],"closely":[26],"with":[27,210],"the":[28,45,77,83,122,152,173,186],"nature":[29],"of":[30,37,48,85,124,156,175,202],"human":[31],"intelligence,":[32],"which":[33,64],"processes":[34],"a":[35,52,67,94,111,131,197],"variety":[36],"data":[38],"forms":[39],"beyond":[40],"just":[41],"text.":[42],"Despite":[43],"advancements,":[44],"undesirable":[46,145,153],"generation":[47,155],"these":[49],"models":[50],"remains":[51],"critical":[53,132],"concern,":[54],"particularly":[55],"due":[56],"to":[57,109,205],"vulnerabilities":[58],"exposed":[59],"text-based":[61],"jailbreak":[62,98,140],"attacks,":[63],"represented":[66],"significant":[68,167],"threat":[69],"challenging":[71],"existing":[72],"safety":[73,169,177,191],"protocols.":[74],"Motivated":[75],"unique":[78],"security":[79,203],"risks":[80,208],"posed":[81],"integration":[84],"new":[86],"old":[88],"modalities":[89,126],"for":[90,189,196],"MLLMs,":[91,194],"we":[92],"propose":[93],"unified":[95],"multimodal":[96,138,168,181,211],"universal":[97,112,139],"attack":[99],"framework":[100],"that":[101,137],"leverages":[102],"iterative":[103],"image-text":[104,125],"interactions":[105],"transfer-based":[107],"strategy":[108],"generate":[110],"adversarial":[113],"suffix":[114],"image.":[116],"Our":[117],"work":[118],"not":[119],"only":[120],"highlights":[121],"interaction":[123],"can":[127,142],"be":[128],"used":[129],"as":[130],"vulnerability":[133],"but":[134],"also":[135],"validates":[136],"attacks":[141],"bring":[143],"higher-quality":[144],"generations":[146],"across":[147],"different":[148],"MLLMs.":[149],"We":[150],"evaluate":[151],"context":[154],"MLLMs":[157],"like":[158],"LLaVA,":[159],"Yi-VL,":[160],"MiniGPT4,":[161],"MiniGPT-v2,":[162],"InstructBLIP,":[164],"reveal":[166],"alignment":[170],"issues,":[171],"highlighting":[172],"inadequacy":[174],"current":[176],"mechanisms":[178],"against":[179],"sophisticated":[180],"attacks.":[182],"This":[183],"study":[184],"underscores":[185],"urgent":[187],"need":[188],"robust":[190],"measures":[192],"in":[193],"advocating":[195],"comprehensive":[198],"review":[199],"enhancement":[201],"protocols":[204],"mitigate":[206],"potential":[207],"associated":[209],"capabilities.":[212]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":2}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
