GhostPrompt: Cross-Image Adversarial Prompt for Vision-Language Models
Li Zeng, Zeyu Ye, Meng Xie, Hangtao Zhang, Xianlong Wang, Yanchun Li, Zhetao Li
cs.CR
Submitted: 2026-07-22
Comments: Accepted to ACM MM 2026. Code: this https://github.com/Ye-ze-yu/GhostPrompt
Code: https://github.com/Ye-ze-yu/GhostPrompt
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- GPT-4 Technical Report
- Detecting Language Model Attacks with Perplexity
- Adversarial Patch
- ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents
- Jailbreaking Black Box Large Language Models in Twenty Queries
- Tex3D: Objects as Attack Surfaces via Adversarial 3D Textures for Vision-Language-Action Models
- Shaping the Safety Boundaries: Understanding and Defending Against Jailbreaks in Large Language Models
- Safety Layers in Aligned Large Language Models: The Key to LLM Security
- AmpleGCG: Learning a Universal and Transferable Generative Model of Adversarial Suffixes for Jailbreaking Both Open and Closed LLMs
- Visual Instruction Tuning
- Tree of Attacks: Jailbreaking Black-Box LLMs Automatically
- Towards Long-Horizon Interpretability: Efficient and Faithful Multi-Token Attribution for Reasoning LLMs
- Refusing Safe Prompts for Multi-modal Large Language Models
- Llama 2: Open Foundation and Fine-Tuned Chat Models
- Enhancing Adversarial Text Attacks on BERT Models with Projected Gradient Descent
- Robot Collapse: Supply Chain Backdoor Attacks Against VLM-based Robotic Manipulation
- Dual-branch Robust Unlearnable Examples
- Enhancing Cross-Prompt Transferability in Vision-Language Models through Contextual Injection of Target Tokens
- Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt
- Detector Collapse: Physical-World Backdooring Object Detection to Catastrophic Overload or Blindness in Autonomous Driving
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs