Chain-of-Jailbreak Attack for Image Generation Models via Editing Step by Step

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Wenxuan, Gao, Kuiyi, Yuan, Youliang, Huang, Jen-tse, Liu, Qiuzhi, Wang, Shuai, Jiao, Wenxiang, Tu, Zhaopeng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916775919091712
author Wang, Wenxuan
Gao, Kuiyi
Yuan, Youliang
Huang, Jen-tse
Liu, Qiuzhi
Wang, Shuai
Jiao, Wenxiang
Tu, Zhaopeng
author_facet Wang, Wenxuan
Gao, Kuiyi
Yuan, Youliang
Huang, Jen-tse
Liu, Qiuzhi
Wang, Shuai
Jiao, Wenxiang
Tu, Zhaopeng
contents Text-based image generation models, such as Stable Diffusion and DALL-E 3, hold significant potential in content creation and publishing workflows, making them the focus in recent years. Despite their remarkable capability to generate diverse and vivid images, considerable efforts are being made to prevent the generation of harmful content, such as abusive, violent, or pornographic material. To assess the safety of existing models, we introduce a novel jailbreaking method called Chain-of-Jailbreak (CoJ) attack, which compromises image generation models through a step-by-step editing process. Specifically, for malicious queries that cannot bypass the safeguards with a single prompt, we intentionally decompose the query into multiple sub-queries. The image generation models are then prompted to generate and iteratively edit images based on these sub-queries. To evaluate the effectiveness of our CoJ attack method, we constructed a comprehensive dataset, CoJ-Bench, encompassing nine safety scenarios, three types of editing operations, and three editing elements. Experiments on four widely-used image generation services provided by GPT-4V, GPT-4o, Gemini 1.5 and Gemini 1.5 Pro, demonstrate that our CoJ attack method can successfully bypass the safeguards of models for over 60% cases, which significantly outperforms other jailbreaking methods (i.e., 14%). Further, to enhance these models' safety against our CoJ attack method, we also propose an effective prompting-based method, Think Twice Prompting, that can successfully defend over 95% of CoJ attack. We release our dataset and code to facilitate the AI safety research.
format Preprint
id arxiv_https___arxiv_org_abs_2410_03869
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Chain-of-Jailbreak Attack for Image Generation Models via Editing Step by Step
Wang, Wenxuan
Gao, Kuiyi
Yuan, Youliang
Huang, Jen-tse
Liu, Qiuzhi
Wang, Shuai
Jiao, Wenxiang
Tu, Zhaopeng
Computation and Language
Artificial Intelligence
Cryptography and Security
Computer Vision and Pattern Recognition
Multimedia
Text-based image generation models, such as Stable Diffusion and DALL-E 3, hold significant potential in content creation and publishing workflows, making them the focus in recent years. Despite their remarkable capability to generate diverse and vivid images, considerable efforts are being made to prevent the generation of harmful content, such as abusive, violent, or pornographic material. To assess the safety of existing models, we introduce a novel jailbreaking method called Chain-of-Jailbreak (CoJ) attack, which compromises image generation models through a step-by-step editing process. Specifically, for malicious queries that cannot bypass the safeguards with a single prompt, we intentionally decompose the query into multiple sub-queries. The image generation models are then prompted to generate and iteratively edit images based on these sub-queries. To evaluate the effectiveness of our CoJ attack method, we constructed a comprehensive dataset, CoJ-Bench, encompassing nine safety scenarios, three types of editing operations, and three editing elements. Experiments on four widely-used image generation services provided by GPT-4V, GPT-4o, Gemini 1.5 and Gemini 1.5 Pro, demonstrate that our CoJ attack method can successfully bypass the safeguards of models for over 60% cases, which significantly outperforms other jailbreaking methods (i.e., 14%). Further, to enhance these models' safety against our CoJ attack method, we also propose an effective prompting-based method, Think Twice Prompting, that can successfully defend over 95% of CoJ attack. We release our dataset and code to facilitate the AI safety research.
title Chain-of-Jailbreak Attack for Image Generation Models via Editing Step by Step
topic Computation and Language
Artificial Intelligence
Cryptography and Security
Computer Vision and Pattern Recognition
Multimedia
url https://arxiv.org/abs/2410.03869