DeepSeek on a Trip: Inducing Targeted Visual Hallucinations via Representation Vulnerabilities

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Islam, Chashi Mahiul, Chacko, Samuel Jacob, Horne, Preston, Liu, Xiuwen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912229733957632
author Islam, Chashi Mahiul
Chacko, Samuel Jacob
Horne, Preston
Liu, Xiuwen
author_facet Islam, Chashi Mahiul
Chacko, Samuel Jacob
Horne, Preston
Liu, Xiuwen
contents Multimodal Large Language Models (MLLMs) represent the cutting edge of AI technology, with DeepSeek models emerging as a leading open-source alternative offering competitive performance to closed-source systems. While these models demonstrate remarkable capabilities, their vision-language integration mechanisms introduce specific vulnerabilities. We implement an adapted embedding manipulation attack on DeepSeek Janus that induces targeted visual hallucinations through systematic optimization of image embeddings. Through extensive experimentation across COCO, DALL-E 3, and SVIT datasets, we achieve hallucination rates of up to 98.0% while maintaining high visual fidelity (SSIM > 0.88) of the manipulated images on open-ended questions. Our analysis demonstrates that both 1B and 7B variants of DeepSeek Janus are susceptible to these attacks, with closed-form evaluation showing consistently higher hallucination rates compared to open-ended questioning. We introduce a novel multi-prompt hallucination detection framework using LLaMA-3.1 8B Instruct for robust evaluation. The implications of these findings are particularly concerning given DeepSeek's open-source nature and widespread deployment potential. This research emphasizes the critical need for embedding-level security measures in MLLM deployment pipelines and contributes to the broader discussion of responsible AI implementation.
format Preprint
id arxiv_https___arxiv_org_abs_2502_07905
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DeepSeek on a Trip: Inducing Targeted Visual Hallucinations via Representation Vulnerabilities
Islam, Chashi Mahiul
Chacko, Samuel Jacob
Horne, Preston
Liu, Xiuwen
Computer Vision and Pattern Recognition
Machine Learning
Multimodal Large Language Models (MLLMs) represent the cutting edge of AI technology, with DeepSeek models emerging as a leading open-source alternative offering competitive performance to closed-source systems. While these models demonstrate remarkable capabilities, their vision-language integration mechanisms introduce specific vulnerabilities. We implement an adapted embedding manipulation attack on DeepSeek Janus that induces targeted visual hallucinations through systematic optimization of image embeddings. Through extensive experimentation across COCO, DALL-E 3, and SVIT datasets, we achieve hallucination rates of up to 98.0% while maintaining high visual fidelity (SSIM > 0.88) of the manipulated images on open-ended questions. Our analysis demonstrates that both 1B and 7B variants of DeepSeek Janus are susceptible to these attacks, with closed-form evaluation showing consistently higher hallucination rates compared to open-ended questioning. We introduce a novel multi-prompt hallucination detection framework using LLaMA-3.1 8B Instruct for robust evaluation. The implications of these findings are particularly concerning given DeepSeek's open-source nature and widespread deployment potential. This research emphasizes the critical need for embedding-level security measures in MLLM deployment pipelines and contributes to the broader discussion of responsible AI implementation.
title DeepSeek on a Trip: Inducing Targeted Visual Hallucinations via Representation Vulnerabilities
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2502.07905