{"id":"https://openalex.org/W4407684119","doi":"https://doi.org/10.48550/arxiv.2502.10794","title":"Distraction is All You Need for Multimodal Large Language Model Jailbreaking","display_name":"Distraction is All You Need for Multimodal Large Language Model Jailbreaking","publication_year":2025,"publication_date":"2025-02-15","ids":{"openalex":"https://openalex.org/W4407684119","doi":"https://doi.org/10.48550/arxiv.2502.10794"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2502.10794","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2502.10794","pdf_url":"https://arxiv.org/pdf/2502.10794","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2502.10794","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5042849288","display_name":"Zuopeng Yang","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Yang, Zuopeng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011384417","display_name":"Jiluan Fan","orcid":"https://orcid.org/0009-0007-5593-3106"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fan, Jiluan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067313044","display_name":"Anli Yan","orcid":"https://orcid.org/0000-0002-2854-2931"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yan, Anli","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5116306956","display_name":"Erdun Gao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gao, Erdun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100398292","display_name":"Lin Xin","orcid":"https://orcid.org/0000-0003-2992-3338"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lin, Xin","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089412213","display_name":"Tao Li","orcid":"https://orcid.org/0000-0002-7089-624X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Tao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5116306957","display_name":"Kanghua mo","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mo, Kanghua","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5100767305","display_name":"Chen Dong","orcid":"https://orcid.org/0000-0002-0084-9130"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Dong, Changyu","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5042849288"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9617000222206116,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9617000222206116,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.9509000182151794,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/distraction","display_name":"Distraction","score":0.8423113822937012},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.4999368190765381},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.42279624938964844},{"id":"https://openalex.org/keywords/linguistics","display_name":"Linguistics","score":0.3616093397140503},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.3583916425704956},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.30749040842056274},{"id":"https://openalex.org/keywords/cognitive-psychology","display_name":"Cognitive psychology","score":0.2725812792778015},{"id":"https://openalex.org/keywords/philosophy","display_name":"Philosophy","score":0.09732997417449951}],"concepts":[{"id":"https://openalex.org/C2776378700","wikidata":"https://www.wikidata.org/wiki/Q3030775","display_name":"Distraction","level":2,"score":0.8423113822937012},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4999368190765381},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.42279624938964844},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.3616093397140503},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.3583916425704956},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.30749040842056274},{"id":"https://openalex.org/C180747234","wikidata":"https://www.wikidata.org/wiki/Q23373","display_name":"Cognitive psychology","level":1,"score":0.2725812792778015},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.09732997417449951}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2502.10794","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2502.10794","pdf_url":"https://arxiv.org/pdf/2502.10794","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2502.10794","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2502.10794","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2502.10794","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2502.10794","pdf_url":"https://arxiv.org/pdf/2502.10794","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W1984342691","https://openalex.org/W2470048815","https://openalex.org/W2324884046","https://openalex.org/W641612223","https://openalex.org/W2028203774","https://openalex.org/W2174716869","https://openalex.org/W4205873045","https://openalex.org/W2080126316"],"abstract_inverted_index":{"Multimodal":[0],"Large":[1],"Language":[2],"Models":[3],"(MLLMs)":[4],"bridge":[5],"the":[6,47,57,73,130,136,142,181,188,196],"gap":[7],"between":[8,49],"visual":[9,24,133],"and":[10,26,52,54,120,150,160,169,185,203],"textual":[11],"data,":[12],"enabling":[13],"a":[14,78,111],"range":[15],"of":[16,59,100,178,198],"advanced":[17],"applications.":[18],"However,":[19],"complex":[20],"internal":[21],"interactions":[22,131],"among":[23,132],"elements":[25,134],"their":[27,63],"alignment":[28,93],"with":[29],"text":[30],"can":[31],"introduce":[32],"vulnerabilities,":[33],"which":[34],"may":[35],"be":[36],"exploited":[37],"to":[38,87,128,148,201],"bypass":[39,204],"safety":[40],"mechanisms.":[41],"To":[42],"address":[43],"this,":[44],"we":[45,71],"analyze":[46],"relationship":[48],"image":[50],"content":[51],"task":[53],"find":[55],"that":[56,109,172],"complexity":[58],"subimages,":[60],"rather":[61],"than":[62],"content,":[64],"is":[65],"key.":[66],"Building":[67],"on":[68],"this":[69],"insight,":[70],"propose":[72],"Distraction":[74,84],"Hypothesis,":[75],"followed":[76],"by":[77,90,114,124],"novel":[79],"framework":[80],"called":[81],"Contrasting":[82],"Subimage":[83],"Jailbreaking":[85],"(CS-DJ),":[86],"achieve":[88],"jailbreaking":[89],"disrupting":[91],"MLLMs":[92],"through":[94,106],"multi-level":[95],"distraction":[96],"strategies.":[97,212],"CS-DJ":[98,173],"consists":[99],"two":[101],"components:":[102],"structured":[103],"distraction,":[104,122],"achieved":[105],"query":[107],"decomposition":[108],"induces":[110],"distributional":[112],"shift":[113],"fragmenting":[115],"harmful":[116,152],"prompts":[117],"into":[118],"sub-queries,":[119],"visual-enhanced":[121],"realized":[123],"constructing":[125],"contrasting":[126],"subimages":[127],"disrupt":[129],"within":[135],"model.":[137],"This":[138],"dual":[139],"strategy":[140],"disperses":[141],"model's":[143],"attention,":[144],"reducing":[145],"its":[146],"ability":[147],"detect":[149],"mitigate":[151],"content.":[153],"Extensive":[154],"experiments":[155],"across":[156],"five":[157],"representative":[158],"scenarios":[159],"four":[161],"popular":[162],"closed-source":[163],"MLLMs,":[164],"including":[165],"GPT-4o-mini,":[166],"GPT-4o,":[167],"GPT-4V,":[168],"Gemini-1.5-Flash,":[170],"demonstrate":[171],"achieves":[174],"average":[175],"success":[176,183,191],"rates":[177],"52.40%":[179],"for":[180,187,210],"attack":[182,190,211],"rate":[184],"74.10%":[186],"ensemble":[189],"rate.":[192],"These":[193],"results":[194],"reveal":[195],"potential":[197],"distraction-based":[199],"approaches":[200],"exploit":[202],"MLLMs'":[205],"defenses,":[206],"offering":[207],"new":[208],"insights":[209]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T06:51:31.235846","created_date":"2025-10-10T00:00:00"}
