Skip to main navigation Skip to search Skip to main content

Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Large Vision Language Models (VLMs) extend and enhance the perceptual abilities of Large Language Models (LLMs). Despite offering new possibilities for LLM applications, these advancements raise significant security and ethical concerns, particularly regarding the generation of harmful content. While LLMs have undergone extensive security evaluations with the aid of red teaming frameworks, VLMs currently lack a well-developed one. To fill this gap, we introduce Arondight, a standardized red team framework tailored specifically for VLMs. Arondight is dedicated to resolving issues related to the absence of visual modality and inadequate diversity encountered when transitioning existing red teaming methodologies from LLMs to VLMs. Our framework features an automated multi-modal jailbreak attack, wherein visual jailbreak prompts are produced by a red team VLM, and textual prompts are generated by a red team LLM guided by a reinforcement learning agent. To enhance the comprehensiveness of VLM security evaluation, we integrate entropy bonuses and novelty reward metrics. These elements incentivize the RL agent to guide the red team LLM in creating a wider array of diverse and previously unseen test cases. Our evaluation of ten cutting-edge VLMs exposes significant security vulnerabilities, particularly in generating toxic images and aligning multi-modal prompts. In particular, our Arondight achieves an average attack success rate of 84.5% on GPT-4 in all fourteen prohibited scenarios defined by OpenAI in terms of generating toxic text. For a clearer comparison, we also categorize existing VLMs based on their safety levels and provide corresponding reinforcement recommendations. Our multimodal prompt dataset and red team code will be released after ethics committee approval. CONTENT WARNING: THIS PAPER CONTAINS HARMFUL MODEL RESPONSES. © 2024 Copyright held by the owner/author(s). Publication rights licensed to ACM.
Original languageEnglish
Title of host publicationMM '24: Proceedings of the 32nd ACM International Conference on Multimedia
PublisherAssociation for Computing Machinery
Pages3578-3586
ISBN (Electronic)979-8-4007-0686-8
DOIs
Publication statusPublished - Oct 2024
Event32nd ACM International Conference on Multimedia (MM 2024) - Melbourne, Australia
Duration: 28 Oct 20241 Nov 2024
https://2024.acmmm.org/

Conference

Conference32nd ACM International Conference on Multimedia (MM 2024)
Abbreviated titleACM MM’24
PlaceAustralia
CityMelbourne
Period28/10/241/11/24
Internet address

Funding

This work was supported by CityU of HK under Grants 9678146 and 9678126, in part by HK RGC under Grants CityU 11218521, 11218322, R6021-20F, R1012-21, RFS2122-1S04, C2004-21G, C1029-22G, and N_CityU139/21, in part by National Nature Science Foundation of China under Grant 62202398, Guangdong Basic and Applied Basic Research Foundation under Grant 2023A151514 0137, and by Guangdong-Hong Kong Joint Laboratory for Data Security and Privacy Preserving (Grant No. 2023B1212120007), in part by a project of CSIRO-NSF AI Research Collaboration Program, in part by Zhejiang Provincial Natural Science Foundation of China under Grant No. LQ23F020019, NSFC under Grant 62302452.

Research Keywords

  • Large Vision Language Model
  • Red Teaming
  • Jailbreak Attacks

RGC Funding Information

  • RGC-funded

Fingerprint

Dive into the research topics of 'Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts'. Together they form a unique fingerprint.

Cite this