2024

Jailbreaking Attack against Multimodal Large Language Model

Niu, Zhenxing, Ren, Haodong, Gao, Xinbo et al.

Understand

This paper focuses on jailbreaking attacks against multi-modal large language models (MLLMs), seeking to elicit MLLMs to generate objectionable responses to harmful user queries.

  • A maximum likelihood-based algorithm is proposed to find an \emph{image Jailbreaking Prompt} (imgJP), enabling jailbreaks against MLLMs across multiple unseen prompts and images (i.e., data-universal property).
  • Our approach exhibits strong model-transferability, as the generated imgJP can be transferred to jailbreak various models, including MiniGPT-v2, LLaVA, InstructBLIP, and mPLUG-Owl2, in a black-box manner.
  • Moreover, we reveal a connection between MLLM-jailbreaks and LLM-jailbreaks.

Reading the bibliography…