{"id":"https://openalex.org/W4403791397","doi":"https://doi.org/10.1145/3664647.3681092","title":"White-box Multimodal Jailbreaks Against Large Vision-Language Models","display_name":"White-box Multimodal Jailbreaks Against Large Vision-Language Models","publication_year":2024,"publication_date":"2024-10-26","ids":{"openalex":"https://openalex.org/W4403791397","doi":"https://doi.org/10.1145/3664647.3681092"},"language":"en","primary_location":{"id":"doi:10.1145/3664647.3681092","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3664647.3681092","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 32nd ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5111717758","display_name":"Ruofan Wang","orcid":"https://orcid.org/0000-0002-0602-704X"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Ruofan Wang","raw_affiliation_strings":["Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078711649","display_name":"Xingjun Ma","orcid":"https://orcid.org/0000-0003-2099-4973"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xingjun Ma","raw_affiliation_strings":["Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101143164","display_name":"Hanxu Zhou","orcid":"https://orcid.org/0009-0008-8492-4492"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hanxu Zhou","raw_affiliation_strings":["School of Mathematical Sciences, Shanghai Jiaotong University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Mathematical Sciences, Shanghai Jiaotong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073480727","display_name":"Chuanjun Ji","orcid":"https://orcid.org/0000-0002-7747-5835"},"institutions":[{"id":"https://openalex.org/I4210128853","display_name":"China Datang Corporation (China)","ror":"https://ror.org/033mgm122","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210128853"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chuanjun Ji","raw_affiliation_strings":["DataGrand Co., Ltd, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"DataGrand Co., Ltd, Shanghai, China","institution_ids":["https://openalex.org/I4210128853"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003276783","display_name":"Guangnan Ye","orcid":"https://orcid.org/0009-0007-4973-7942"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guangnan Ye","raw_affiliation_strings":["Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5047962986","display_name":"Yu\u2013Gang Jiang","orcid":"https://orcid.org/0000-0002-1907-8567"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yu-Gang Jiang","raw_affiliation_strings":["Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Lab of Intell. Info. Processing, School of CS, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5111717758"],"corresponding_institution_ids":["https://openalex.org/I24943067"],"apc_list":null,"apc_paid":null,"fwci":2.4436,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.9064237,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"6920","last_page":"6928"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.9811000227928162,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6525219082832336},{"id":"https://openalex.org/keywords/white-box","display_name":"White box","score":0.6097401976585388},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5774970054626465},{"id":"https://openalex.org/keywords/white","display_name":"White (mutation)","score":0.49781370162963867},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.42946183681488037},{"id":"https://openalex.org/keywords/machine-vision","display_name":"Machine vision","score":0.4159998893737793},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.3261924386024475},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.11008152365684509}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6525219082832336},{"id":"https://openalex.org/C180932941","wikidata":"https://www.wikidata.org/wiki/Q997233","display_name":"White box","level":2,"score":0.6097401976585388},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5774970054626465},{"id":"https://openalex.org/C56273599","wikidata":"https://www.wikidata.org/wiki/Q3122841","display_name":"White (mutation)","level":3,"score":0.49781370162963867},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.42946183681488037},{"id":"https://openalex.org/C5339829","wikidata":"https://www.wikidata.org/wiki/Q1425977","display_name":"Machine vision","level":2,"score":0.4159998893737793},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3261924386024475},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.11008152365684509},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3664647.3681092","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3664647.3681092","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 32nd ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":3,"referenced_works":["https://openalex.org/W3134354193","https://openalex.org/W4225323055","https://openalex.org/W4390190425"],"related_works":["https://openalex.org/W4233030723","https://openalex.org/W2093526602","https://openalex.org/W2605535459","https://openalex.org/W2796653146","https://openalex.org/W4286828408","https://openalex.org/W2136594339","https://openalex.org/W57221518","https://openalex.org/W2331823140","https://openalex.org/W2968276623","https://openalex.org/W2301119896"],"abstract_inverted_index":{"Recent":[0],"advancements":[1],"in":[2,11,49,111],"Large":[3],"Vision-Language":[4],"Models":[5],"(VLMs)":[6],"have":[7],"underscored":[8],"their":[9],"superiority":[10],"various":[12,147,170],"multimodal":[13],"tasks.":[14],"However,":[15],"the":[16,85,112,119,134,140,176,184,211,216],"adversarial":[17,33,100,126,135,152],"robustness":[18,30],"of":[19,71,114,142,179,186,213],"VLMs":[20,180,214],"has":[21],"not":[22],"been":[23],"fully":[24],"explored.":[25],"Existing":[26],"methods":[27],"mainly":[28],"assess":[29],"through":[31],"unimodal":[32],"attacks":[34,60],"that":[35,58,196],"perturb":[36],"images,":[37],"while":[38],"assuming":[39],"inherent":[40],"resilience":[41],"against":[42],"text-based":[43],"attacks.":[44],"Different":[45],"from":[46,103],"existing":[47],"attacks,":[48],"this":[50],"work":[51],"we":[52,76],"propose":[53,77],"a":[54,68,78,162,206],"more":[55],"comprehensive":[56],"strategy":[57,200],"jointly":[59],"both":[61],"text":[62,115,127,156],"and":[63,131,155,181,215,233],"image":[64,101,120,136,153],"modalities":[65],"to":[66,87,106,138,146,183],"exploit":[67],"broader":[69],"spectrum":[70],"vulnerability":[72],"within":[73],"VLMs.":[74],"Specifically,":[75],"dual":[79],"optimization":[80],"objective":[81],"aimed":[82],"at":[83,225],"guiding":[84],"model":[86],"generate":[88,107],"highly":[89],"toxic":[90,122],"affirmative":[91,144],"responses.":[92],"Our":[93],"attack":[94,199],"method":[95],"begins":[96],"by":[97],"optimizing":[98],"an":[99,125],"prefix":[102,137,154],"random":[104],"noise":[105],"diverse":[108],"harmful":[109,148],"responses":[110,145],"absence":[113],"input,":[116],"thus":[117],"imbuing":[118],"with":[121,133,205],"semantics.":[123],"Subsequently,":[124],"suffix":[128,157],"is":[129],"integrated":[130,168],"co-optimized":[132],"maximize":[139],"probability":[141],"eliciting":[143],"instructions.":[149],"The":[150,192],"discovered":[151],"are":[158,223],"collectively":[159],"denoted":[160],"as":[161,190],"Universal":[163],"Master":[164],"Key":[165],"(UMK).":[166],"When":[167],"into":[169],"malicious":[171],"queries,":[172],"UMK":[173],"can":[174,201],"circumvent":[175],"alignment":[177,220],"defenses":[178],"lead":[182],"generation":[185],"objectionable":[187],"content,":[188],"known":[189],"jailbreaks.":[191],"experimental":[193],"results":[194],"demonstrate":[195],"our":[197],"universal":[198],"effectively":[202],"jailbreak":[203],"MiniGPT-4":[204],"96%":[207],"success":[208],"rate,":[209],"highlighting":[210],"fragility":[212],"exigency":[217],"for":[218],"new":[219],"strategies.":[221],"Codes":[222],"available":[224],"https://github.com/roywang021/UMK.":[226],"Disclaimer:":[227],"This":[228],"paper":[229],"contains":[230],"potentially":[231],"disturbing":[232],"offensive":[234],"content.":[235]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":6}],"updated_date":"2026-03-27T14:29:43.386196","created_date":"2025-10-10T00:00:00"}
