Search papers, labs, and topics across Lattice.
This paper introduces Distributed Semantic Recomposition (DSR), a novel framework that enables cross-modal jailbreak attacks on Multimodal Large Language Models (MLLMs) by breaking down harmful intent into benign components. The study reveals that existing safety measures, which primarily focus on unimodal inputs, are ineffective against these sophisticated attacks, leading to a significant Utility-Safety Paradox where the model's strengths in instruction-following can be exploited. Experimental results show that DSR achieves high attack success rates while keeping input toxicity rates low, highlighting a critical vulnerability in current MLLM safety protocols.
MLLMs can be manipulated to produce harmful outputs from benign inputs, exposing a critical vulnerability in their safety mechanisms.
Multimodal Large Language Models (MLLMs) have recently demonstrated remarkable capabilities in content synthesis and autonomous reasoning. Previous safety guardrails are primarily designed for unimodal textual input interception, leaving them vulnerable to cross-modal jailbreak attacks. However, regardless unimodal textual attack or cross-modal jailbreak, typically inclusive part of explicit harmful or sensitive content at the input level, which is called Harm-Bearing. It allow the model's safety filters to detect and block such content easily. To address this limitations, we propose Distributed Semantic Recomposition (DSR), a novel cross-modal jailbreak framework that decomposes harmful intent into a set of benign textual and visual primitives. By exploiting the model's reasoning ability, DSR enables the latent fusion of these seemingly innocent components into harmful outputs during the cross-modal inference phase. Extensive experiments on multiple commercial MLLMs pipelines demonstrate that DSR achieves superior attack success rates while maintaining an extremely low or even negligible input toxicity rate. Our findings uncover a critical Utility-Safety Paradox in MLLMs, where the model's instruction-following proficiency facilitates its own cognitive exploitation. Content Warning: This paper contains harmful model responses.