{"id":"https://openalex.org/W7140109194","doi":"https://doi.org/10.18653/v1/2026.eacl-long.202","title":"Zer0-Jack: A memory-efficient gradient-based jailbreaking method for black box Multi-modal Large Language Models","display_name":"Zer0-Jack: A memory-efficient gradient-based jailbreaking method for black box Multi-modal Large Language Models","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7140109194","doi":"https://doi.org/10.18653/v1/2026.eacl-long.202"},"language":null,"primary_location":{"id":"doi:10.18653/v1/2026.eacl-long.202","is_oa":true,"landing_page_url":"https://doi.org/10.18653/v1/2026.eacl-long.202","pdf_url":"https://aclanthology.org/2026.eacl-long.202.pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th Conference of the European Chapter of the Association for Computational Linguistics (Volume 1: Long Papers)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://aclanthology.org/2026.eacl-long.202.pdf","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Tiejin Chen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tiejin Chen","raw_affiliation_strings":["Arizona State University University of Maryland Arizona State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Arizona State University University of Maryland Arizona State University","institution_ids":[]}]},{"author_position":"middle","author":{"id":null,"display_name":"Kaishen Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kaishen Wang","raw_affiliation_strings":["Arizona State University University of Maryland Arizona State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Arizona State University University of Maryland Arizona State University","institution_ids":[]}]},{"author_position":"last","author":{"id":null,"display_name":"Hua Wei","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hua Wei","raw_affiliation_strings":["Arizona State University University of Maryland Arizona State University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Arizona State University University of Maryland Arizona State University","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.39673835,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"4328","last_page":"4344"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.421999990940094,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.421999990940094,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.18520000576972961,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10201","display_name":"Speech Recognition and Synthesis","score":0.07209999859333038,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.4359999895095825},{"id":"https://openalex.org/keywords/natural-language","display_name":"Natural language","score":0.33899998664855957},{"id":"https://openalex.org/keywords/sequence","display_name":"Sequence (biology)","score":0.25839999318122864},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.2531000077724457}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5587000250816345},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.4359999895095825},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4047999978065491},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3483000099658966},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.33899998664855957},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.289900004863739},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.26739999651908875},{"id":"https://openalex.org/C2778112365","wikidata":"https://www.wikidata.org/wiki/Q3511065","display_name":"Sequence (biology)","level":2,"score":0.25839999318122864},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.25679999589920044},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.2531000077724457}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.18653/v1/2026.eacl-long.202","is_oa":true,"landing_page_url":"https://doi.org/10.18653/v1/2026.eacl-long.202","pdf_url":"https://aclanthology.org/2026.eacl-long.202.pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th Conference of the European Chapter of the Association for Computational Linguistics (Volume 1: Long Papers)","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.18653/v1/2026.eacl-long.202","is_oa":true,"landing_page_url":"https://doi.org/10.18653/v1/2026.eacl-long.202","pdf_url":"https://aclanthology.org/2026.eacl-long.202.pdf","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th Conference of the European Chapter of the Association for Computational Linguistics (Volume 1: Long Papers)","raw_type":"proceedings-article"},"sustainable_development_goals":[{"score":0.4028674066066742,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G8707547214","display_name":"CAREER: The Next Frontier in Urban Data Analytics: From Prescriptive to Actionable","funder_award_id":"2442477","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320307791","display_name":"Cisco Systems","ror":"https://ror.org/03yt1ez60"},{"id":"https://openalex.org/F4320309835","display_name":"Arizona State University","ror":"https://ror.org/03efmqc40"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7140109194.pdf","grobid_xml":"https://content.openalex.org/works/W7140109194.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Multi-modal":[0],"large":[1],"language":[2,166],"models":[3,136],"(MLLMs)":[4],"have":[5],"recently":[6],"shown":[7],"impressive":[8],"capabilities":[9],"but":[10],"are":[11,38,154],"also":[12],"highly":[13],"vulnerable":[14],"to":[15,57,62,149],"jailbreak":[16,81,150],"attacks.While":[17],"white-box":[18],"methods":[19],"can":[20,145],"generate":[21],"adversarial":[22],"visual":[23],"inputs":[24],"via":[25],"gradient-based":[26],"optimization,":[27],"such":[28,137],"approaches":[29],"fail":[30],"in":[31],"realistic":[32],"black-box":[33,47,80],"settings":[34],"where":[35],"model":[36,69],"parameters":[37],"inaccessible.Zeroth-order":[39],"(ZO)":[40],"optimization":[41,112,144],"offers":[42],"a":[43,96],"natural":[44],"path":[45],"for":[46,83],"attacks":[48],"by":[49],"estimating":[50],"gradients":[51],"from":[52],"queries,":[53],"yet":[54],"its":[55],"application":[56],"MLLMs":[58,84],"is":[59,172],"challenging":[60],"due":[61],"sequenceconditioned":[63],"objectives,":[64],"limited":[65],"feedback,":[66],"and":[67,94,106,124,167,169],"massive":[68],"scales.To":[70],"address":[71],"these":[72],"issues,":[73],"we":[74],"propose":[75],"Zer0-Jack,":[76],"the":[77,127],"first":[78],"direct":[79],"framework":[82],"based":[85],"on":[86,90,113,122,126,156],"ZO":[87,143],"optimization.Zer0-Jack":[88],"focuses":[89],"generating":[91],"malicious":[92],"images":[93],"introduces":[95],"patchwise":[97],"block":[98],"coordinate":[99],"descent":[100],"strategy":[101],"that":[102,117,142],"stabilizes":[103],"gradient":[104],"estimation":[105],"reduces":[107],"query":[108],"complexity,":[109],"enabling":[110],"efficient":[111],"billion-scale":[114],"models.Experiments":[115],"show":[116],"Zer0-Jack":[118],"achieves":[119],"98.2%":[120],"success":[121],"MiniGPT-4":[123],"95%":[125],"Harmful":[128],"Behaviors":[129],"Multimodal":[130],"dataset,":[131],"while":[132],"directly":[133],"jailbreaking":[134],"commercial":[135],"as":[138],"GPT-4o.These":[139],"results":[140],"demonstrate":[141],"be":[146],"effectively":[147],"adapted":[148],"large-scale":[151],"multimodal":[152],"LLMs.Codes":[153],"provided":[155],"https:":[157],"//github.com/DaRL-GenAI/Zer0-Jack.":[158],"Warning:":[159],"This":[160],"paper":[161],"contains":[162],"examples":[163],"of":[164],"harmful":[165],"images,":[168],"reader":[170],"discretion":[171],"recommended.":[173]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-02-02T00:00:00"}
