{"id":"https://openalex.org/W7153990612","doi":"https://doi.org/10.48550/arxiv.2604.09253","title":"Mosaic: Multimodal Jailbreak against Closed-Source VLMs via Multi-View Ensemble Optimization","display_name":"Mosaic: Multimodal Jailbreak against Closed-Source VLMs via Multi-View Ensemble Optimization","publication_year":2026,"publication_date":"2026-04-10","ids":{"openalex":"https://openalex.org/W7153990612","doi":"https://doi.org/10.48550/arxiv.2604.09253"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.09253","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.09253","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.09253","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5091382580","display_name":"Yuqin Lan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lan, Yuqin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133524223","display_name":"Gen Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Gen","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049986768","display_name":"Yifan Hu","orcid":"https://orcid.org/0000-0002-9332-1852"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hu, Yuanze","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029846838","display_name":"Weihao Shen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shen, Weihao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133494080","display_name":"Zhaoxin Fan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fan, Zhaoxin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133502521","display_name":"Faguo Wu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wu, Faguo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133532303","display_name":"Xiao Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Xiao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133492374","display_name":"Laurence T. Yang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yang, Laurence T.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5133543999","display_name":"Zhiming Zheng","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zheng, Zhiming","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":9,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.871399998664856,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.871399998664856,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.030799999833106995,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.016599999740719795,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/overfitting","display_name":"Overfitting","score":0.6294999718666077},{"id":"https://openalex.org/keywords/surrogate-model","display_name":"Surrogate model","score":0.5537999868392944},{"id":"https://openalex.org/keywords/homogeneous","display_name":"Homogeneous","score":0.4941999912261963},{"id":"https://openalex.org/keywords/multi-objective-optimization","display_name":"Multi-objective optimization","score":0.43700000643730164},{"id":"https://openalex.org/keywords/optimization-problem","display_name":"Optimization problem","score":0.43470001220703125},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.4023999869823456},{"id":"https://openalex.org/keywords/dependency","display_name":"Dependency (UML)","score":0.3871000111103058},{"id":"https://openalex.org/keywords/term","display_name":"Term (time)","score":0.36559998989105225}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6920999884605408},{"id":"https://openalex.org/C22019652","wikidata":"https://www.wikidata.org/wiki/Q331309","display_name":"Overfitting","level":3,"score":0.6294999718666077},{"id":"https://openalex.org/C131675550","wikidata":"https://www.wikidata.org/wiki/Q7646884","display_name":"Surrogate model","level":2,"score":0.5537999868392944},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5527999997138977},{"id":"https://openalex.org/C66882249","wikidata":"https://www.wikidata.org/wiki/Q169336","display_name":"Homogeneous","level":2,"score":0.4941999912261963},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4738999903202057},{"id":"https://openalex.org/C68781425","wikidata":"https://www.wikidata.org/wiki/Q2052203","display_name":"Multi-objective optimization","level":2,"score":0.43700000643730164},{"id":"https://openalex.org/C137836250","wikidata":"https://www.wikidata.org/wiki/Q984063","display_name":"Optimization problem","level":2,"score":0.43470001220703125},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.4023999869823456},{"id":"https://openalex.org/C19768560","wikidata":"https://www.wikidata.org/wiki/Q320727","display_name":"Dependency (UML)","level":2,"score":0.3871000111103058},{"id":"https://openalex.org/C61797465","wikidata":"https://www.wikidata.org/wiki/Q1188986","display_name":"Term (time)","level":2,"score":0.36559998989105225},{"id":"https://openalex.org/C2780505938","wikidata":"https://www.wikidata.org/wiki/Q17093282","display_name":"Unavailability","level":2,"score":0.32330000400543213},{"id":"https://openalex.org/C45942800","wikidata":"https://www.wikidata.org/wiki/Q245652","display_name":"Ensemble learning","level":2,"score":0.29339998960494995},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2897999882698059},{"id":"https://openalex.org/C84945661","wikidata":"https://www.wikidata.org/wiki/Q7366567","display_name":"Root cause","level":2,"score":0.2888000011444092},{"id":"https://openalex.org/C119898033","wikidata":"https://www.wikidata.org/wiki/Q3433888","display_name":"Ensemble forecasting","level":2,"score":0.27090001106262207},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.2590999901294708},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.25270000100135803},{"id":"https://openalex.org/C112972136","wikidata":"https://www.wikidata.org/wiki/Q7595718","display_name":"Stability (learning theory)","level":2,"score":0.25060001015663147}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.09253","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.09253","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.09253","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.09253","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7105043530464172,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-Language":[0],"Models":[1],"(VLMs)":[2],"are":[3,39],"powerful":[4],"but":[5,42],"remain":[6],"vulnerable":[7],"to":[8,31,153,156,175],"multimodal":[9,102],"jailbreak":[10,103],"attacks.":[11],"Existing":[12],"attacks":[13,21],"mainly":[14],"rely":[15],"on":[16,56,118,181],"either":[17],"explicit":[18],"visual":[19,124,159],"prompt":[20],"or":[22],"gradient-based":[23],"adversarial":[24],"optimization.":[25],"While":[26],"the":[27,33],"former":[28],"is":[29,43],"easier":[30],"detect,":[32],"latter":[34],"produces":[35],"subtle":[36],"perturbations":[37,148],"that":[38,185],"less":[40],"perceptible,":[41],"usually":[44],"optimized":[45],"and":[46,73,80,123,161,192],"evaluated":[47],"under":[48,60,111,149],"homogeneous":[49,79],"open-source":[50],"surrogate-target":[51,71,113],"settings,":[52,82],"leaving":[53],"its":[54],"effectiveness":[55],"commercial":[57,196],"closed-source":[58,105,197],"VLMs":[59,174],"heterogeneous":[61,81,112],"settings":[62,72,114],"unclear.":[63],"To":[64],"examine":[65],"this":[66,91],"issue,":[67],"we":[68,85,93],"study":[69],"different":[70],"observe":[74],"a":[75,83,96,132,141,157,162],"consistent":[76],"gap":[77],"between":[78],"phenomenon":[84],"term":[86],"surrogate":[87,109,121,173],"dependency.":[88],"Motivated":[89],"by":[90,115],"finding,":[92],"propose":[94],"Mosaic,":[95],"Multi-view":[97],"ensemble":[98],"optimization":[99,169],"framework":[100],"for":[101],"against":[104,195],"VLMs,":[106],"which":[107,136,146,167],"alleviates":[108],"dependency":[110],"reducing":[116],"over-reliance":[117],"any":[119],"single":[120,158],"model":[122],"view.":[125],"Specifically,":[126],"Mosaic":[127,186],"incorporates":[128],"three":[129],"core":[130],"components:":[131],"Text-Side":[133],"Transformation":[134],"module,":[135,145,166],"perturbs":[137],"refusal-sensitive":[138],"lexical":[139],"patterns;":[140],"Multi-View":[142],"Image":[143],"Optimization":[144],"updates":[147],"diverse":[150],"cropped":[151],"views":[152],"avoid":[154],"overfitting":[155],"view;":[160],"Surrogate":[163],"Ensemble":[164],"Guidance":[165],"aggregates":[168],"signals":[170],"from":[171],"multiple":[172],"reduce":[176],"surrogate-specific":[177],"bias.":[178],"Extensive":[179],"experiments":[180],"safety":[182],"benchmarks":[183],"demonstrate":[184],"achieves":[187],"state-of-the-art":[188],"Attack":[189],"Success":[190],"Rate":[191],"Average":[193],"Toxicity":[194],"VLMs.":[198]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-14T00:00:00"}
