{"id":"https://openalex.org/W4415540040","doi":"https://doi.org/10.1145/3746027.3755211","title":"Manipulating Multimodal Agents via Cross-Modal Prompt Injection","display_name":"Manipulating Multimodal Agents via Cross-Modal Prompt Injection","publication_year":2025,"publication_date":"2025-10-25","ids":{"openalex":"https://openalex.org/W4415540040","doi":"https://doi.org/10.1145/3746027.3755211"},"language":null,"primary_location":{"id":"doi:10.1145/3746027.3755211","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3746027.3755211","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101601307","display_name":"Le Wang","orcid":"https://orcid.org/0009-0004-8296-7633"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Le Wang","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0004-8296-7633","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020945039","display_name":"Zonghao Ying","orcid":"https://orcid.org/0009-0007-7393-7362"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zonghao Ying","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0007-7393-7362","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023476317","display_name":"Tianyuan Zhang","orcid":"https://orcid.org/0000-0001-9874-6828"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tianyuan Zhang","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China and Shen Yuan Honors College, Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-9874-6828","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China and Shen Yuan Honors College, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081392445","display_name":"Siyuan Liang","orcid":"https://orcid.org/0000-0002-6154-0233"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Siyuan Liang","raw_affiliation_strings":["College of Computing and Data Science, Nanyang Technological University, Singapore, Singapore"],"raw_orcid":"https://orcid.org/0000-0002-6154-0233","affiliations":[{"raw_affiliation_string":"College of Computing and Data Science, Nanyang Technological University, Singapore, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081287468","display_name":"Shengshan Hu","orcid":"https://orcid.org/0000-0003-0042-9045"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shengshan Hu","raw_affiliation_strings":["School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China"],"raw_orcid":"https://orcid.org/0000-0003-0042-9045","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087014857","display_name":"Mingchuan Zhang","orcid":"https://orcid.org/0000-0002-2523-1089"},"institutions":[{"id":"https://openalex.org/I167383011","display_name":"Henan University of Science and Technology","ror":"https://ror.org/05d80kz58","country_code":"CN","type":"education","lineage":["https://openalex.org/I167383011"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mingchuan Zhang","raw_affiliation_strings":["School of Information Engineering, Henan University of Science and Technology, Luoyang, China"],"raw_orcid":"https://orcid.org/0000-0002-2523-1089","affiliations":[{"raw_affiliation_string":"School of Information Engineering, Henan University of Science and Technology, Luoyang, China","institution_ids":["https://openalex.org/I167383011"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014870180","display_name":"Aishan Liu","orcid":"https://orcid.org/0000-0002-4224-1318"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Aishan Liu","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-4224-1318","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5024067284","display_name":"Xianglong Liu","orcid":"https://orcid.org/0000-0001-8425-4195"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xianglong Liu","raw_affiliation_strings":["State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China, Zhongguancun Laboratory, Beijing, China, and Institute of Dataspace, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0001-8425-4195","affiliations":[{"raw_affiliation_string":"State Key Laboratory of Complex &amp; Critical Software Environment, Beihang University, Beijing, China, Zhongguancun Laboratory, Beijing, China, and Institute of Dataspace, Hefei, China","institution_ids":["https://openalex.org/I82880672"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5101601307"],"corresponding_institution_ids":["https://openalex.org/I82880672"],"apc_list":null,"apc_paid":null,"fwci":5.551,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.9592834,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"10955","last_page":"10964"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12031","display_name":"Speech and dialogue systems","score":0.980400025844574,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12031","display_name":"Speech and dialogue systems","score":0.980400025844574,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10456","display_name":"Multi-Agent Systems and Negotiation","score":0.9277999997138977,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.9082000255584717,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7906000018119812},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.7565000057220459},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.5651000142097473},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.551800012588501},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.545799970626831},{"id":"https://openalex.org/keywords/modalities","display_name":"Modalities","score":0.5321000218391418},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5217000246047974},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5163999795913696},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5051000118255615}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8210999965667725},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7906000018119812},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.7565000057220459},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.5651000142097473},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.551800012588501},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.545799970626831},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.5321000218391418},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5217000246047974},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5163999795913696},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5059999823570251},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5051000118255615},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.4948999881744385},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.4359000027179718},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.4246000051498413},{"id":"https://openalex.org/C774472","wikidata":"https://www.wikidata.org/wiki/Q6760393","display_name":"Margin (machine learning)","level":2,"score":0.3774999976158142},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.37610000371932983},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.37439998984336853},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.34450000524520874},{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.34209999442100525},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.33980000019073486},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3138999938964844},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.3093999922275543},{"id":"https://openalex.org/C66746571","wikidata":"https://www.wikidata.org/wiki/Q1134833","display_name":"ENCODE","level":3,"score":0.2883000075817108},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.2874999940395355},{"id":"https://openalex.org/C2780226545","wikidata":"https://www.wikidata.org/wiki/Q6888030","display_name":"Modality (human\u2013computer interaction)","level":2,"score":0.2847000062465668},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.2827000021934509},{"id":"https://openalex.org/C64543145","wikidata":"https://www.wikidata.org/wiki/Q162942","display_name":"Intersection (aeronautics)","level":2,"score":0.2786000072956085},{"id":"https://openalex.org/C13687954","wikidata":"https://www.wikidata.org/wiki/Q4826847","display_name":"Autonomous agent","level":2,"score":0.2750999927520752},{"id":"https://openalex.org/C2780719617","wikidata":"https://www.wikidata.org/wiki/Q1030752","display_name":"Salient","level":2,"score":0.27480000257492065},{"id":"https://openalex.org/C2780660688","wikidata":"https://www.wikidata.org/wiki/Q25052564","display_name":"Multimodal learning","level":2,"score":0.272599995136261},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.2605000138282776},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.25769999623298645}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3746027.3755211","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3746027.3755211","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 33rd ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"emergence":[1],"of":[2],"multimodal":[3,48,210],"large":[4,145],"language":[5,14,146],"models":[6],"has":[7],"redefined":[8],"the":[9,85,112,116,152,171],"agent":[10],"paradigm":[11],"by":[12],"integrating":[13],"and":[15,29,89,160],"vision":[16],"modalities":[17,73],"with":[18,76,177],"external":[19,81],"data":[20],"sources,":[21],"enabling":[22],"agents":[23],"to":[24,74,83,111,150],"better":[25,175],"interpret":[26],"human":[27],"instructions":[28,82,114],"execute":[30,90],"increasingly":[31],"complex":[32],"tasks.":[33,92,201],"However,":[34],"in":[35,47,65,115,195,208,224],"this":[36,56],"paper,":[37],"we":[38,58,101,107,138,203],"identify":[39],"a":[40,61,122,144,162,192],"critical":[41],"yet":[42],"previously":[43],"overlooked":[44],"security":[45],"vulnerability":[46],"agents:":[49],"cross-modal":[50],"prompt":[51,156],"injection":[52],"attacks.":[53],"To":[54],"exploit":[55],"vulnerability,":[57],"propose":[59],"CrossInject,":[60],"novel":[62],"attack":[63,196],"framework":[64],"which":[66],"attacker":[67],"embeds":[68],"adversarial":[69,109,128,158],"perturbations":[70],"across":[71,199],"multiple":[72],"align":[75],"target":[77],"malicious":[78,113,134,163],"content,":[79],"allowing":[80],"hijack":[84],"agents'":[86,172],"decision-making":[87],"process":[88],"unauthorized":[91],"Our":[93],"approach":[94],"incorporates":[95],"two":[96],"key":[97],"coordinated":[98],"components.":[99],"First,":[100],"introduce":[102],"Visual":[103],"Latent":[104],"Alignment,":[105],"where":[106,143],"optimize":[108],"features":[110],"visual":[117],"embedding":[118],"space":[119],"based":[120,166],"on":[121,167],"text-to-image":[123],"generative":[124],"model,":[125],"ensuring":[126],"that":[127,169,183],"images":[129],"subtly":[130],"encode":[131],"cues":[132],"for":[133,217],"task":[135],"execution.":[136],"Subsequently,":[137],"present":[139],"Textual":[140],"Guidance":[141],"Enhancement,":[142],"model":[147],"is":[148],"leveraged":[149],"construct":[151],"black-box":[153],"defensive":[154],"system":[155],"through":[157],"meta-prompting":[159],"generate":[161],"textual":[164],"command":[165],"it":[168],"steers":[170],"output":[173],"toward":[174],"compliance":[176],"attacker's":[178],"requests.":[179],"Extensive":[180],"experiments":[181],"demonstrate":[182],"our":[184,205],"method":[185],"outperforms":[186],"state-of-the-art":[187],"attacks,":[188],"achieving":[189],"at":[190],"least":[191],"+30.1%":[193],"increase":[194],"success":[197],"rates":[198],"diverse":[200],"Furthermore,":[202],"validate":[204],"attack's":[206],"effectiveness":[207],"real-world":[209],"autonomous":[211],"agents,":[212],"highlighting":[213],"its":[214],"potential":[215],"implications":[216],"safety-critical":[218],"applications.":[219],"Code":[220],"can":[221],"be":[222],"found":[223],"https://github.com/Larry0454/CrossInject.":[225]},"counts_by_year":[{"year":2026,"cited_by_count":3}],"updated_date":"2026-05-29T09:21:14.243279","created_date":"2025-10-25T00:00:00"}
