A Frustratingly Simple Yet Highly Effective Attack Baseline: Over 90% Success Rate Against the Strong Black-box Models of GPT-4.5/4o/o1
Fuente:
arXiv
Saved in:
| Main Authors: | Li, Zhaoyi, Zhao, Xiaohan, Wu, Dong-Dong, Cui, Jiacheng, Shen, Zhiqiang |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Pushing the Frontier of Black-Box LVLM Attacks via Fine-Grained Detail Targeting
by: Zhao, Xiaohan, et al.
Published: (2026)
by: Zhao, Xiaohan, et al.
Published: (2026)
Voice Jailbreak Attacks Against GPT-4o
by: Shen, Xinyue, et al.
Published: (2024)
by: Shen, Xinyue, et al.
Published: (2024)
Open CaptchaWorld: A Comprehensive Web-based Platform for Testing and Benchmarking Multimodal LLM Agents
by: Luo, Yaxin, et al.
Published: (2025)
by: Luo, Yaxin, et al.
Published: (2025)
A Simple Yet Strong Baseline for Long-Term Conversational Memory of LLM Agents
by: Zhou, Sizhe, et al.
Published: (2025)
by: Zhou, Sizhe, et al.
Published: (2025)
AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents
by: Yang, Ke, et al.
Published: (2024)
by: Yang, Ke, et al.
Published: (2024)
LLMSurgeon: Diagnosing Data Mixture of Large Language Models
by: Luo, Yaxin, et al.
Published: (2026)
by: Luo, Yaxin, et al.
Published: (2026)
A Simple Yet Practical Backdoor Prompt Attack Against Black‐Box Code Summarization Engines
by: Yubin Qu, et al.
Published: (2025)
by: Yubin Qu, et al.
Published: (2025)
MolMix: A Simple Yet Effective Baseline for Multimodal Molecular Representation Learning
by: Manolache, Andrei, et al.
Published: (2024)
by: Manolache, Andrei, et al.
Published: (2024)
Pop Quiz Attack: Black-box Membership Inference Attacks Against Large Language Models
by: Chen, Zeyuan, et al.
Published: (2026)
by: Chen, Zeyuan, et al.
Published: (2026)
Scaling Laws for Black box Adversarial Attacks
by: Liu, Chuan, et al.
Published: (2024)
by: Liu, Chuan, et al.
Published: (2024)
FADRM: Fast and Accurate Data Residual Matching for Dataset Distillation
by: Cui, Jiacheng, et al.
Published: (2025)
by: Cui, Jiacheng, et al.
Published: (2025)
Next-Gen CAPTCHAs: Leveraging the Cognitive Gap for Scalable and Diverse GUI-Agent Defense
by: Liu, Jiacheng, et al.
Published: (2026)
by: Liu, Jiacheng, et al.
Published: (2026)
Hard Labels In! Rethinking the Role of Hard Labels in Mitigating Local Semantic Drift
by: Cui, Jiacheng, et al.
Published: (2025)
by: Cui, Jiacheng, et al.
Published: (2025)
Dataset Distillation via Committee Voting
by: Cui, Jiacheng, et al.
Published: (2025)
by: Cui, Jiacheng, et al.
Published: (2025)
Distributed Black-box Attack: Do Not Overestimate Black-box Attacks
by: Wu, Han, et al.
Published: (2022)
by: Wu, Han, et al.
Published: (2022)
Learning Robust Diffusion Models from Imprecise Supervision
by: Wu, Dong-Dong, et al.
Published: (2025)
by: Wu, Dong-Dong, et al.
Published: (2025)
Black-box Adversarial Attacks Against Image Quality Assessment Models
by: Ran, Yu, et al.
Published: (2024)
by: Ran, Yu, et al.
Published: (2024)
SimpleMatch: A Simple and Strong Baseline for Semantic Correspondence
by: Jin, Hailing, et al.
Published: (2026)
by: Jin, Hailing, et al.
Published: (2026)
Smoothness Really Matters: A Simple Yet Effective Approach for Unsupervised Graph Domain Adaptation
by: Chen, Wei, et al.
Published: (2024)
by: Chen, Wei, et al.
Published: (2024)
Online Poisoning Attack Against Reinforcement Learning under Black-box Environments
by: Li, Jianhui, et al.
Published: (2024)
by: Li, Jianhui, et al.
Published: (2024)
BETA: Automated Black-box Exploration for Timing Attacks in Processors
by: Chen, Congcong, et al.
Published: (2024)
by: Chen, Congcong, et al.
Published: (2024)
BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression Tasks
by: Cheng, Zhiyuan, et al.
Published: (2024)
by: Cheng, Zhiyuan, et al.
Published: (2024)
Dive into Claude Code: The Design Space of Today's and Future AI Agent Systems
by: Liu, Jiacheng, et al.
Published: (2026)
by: Liu, Jiacheng, et al.
Published: (2026)
Exploring 3D Dataset Pruning
by: Zhao, Xiaohan, et al.
Published: (2026)
by: Zhao, Xiaohan, et al.
Published: (2026)
GPT-4V Cannot Generate Radiology Reports Yet
by: Jiang, Yuyang, et al.
Published: (2024)
by: Jiang, Yuyang, et al.
Published: (2024)
Attack-in-the-Chain: Bootstrapping Large Language Models for Attacks Against Black-box Neural Ranking Models
by: Liu, Yu-An, et al.
Published: (2024)
by: Liu, Yu-An, et al.
Published: (2024)
Red Teaming GPT-4V: Are GPT-4V Safe Against Uni/Multi-Modal Jailbreak Attacks?
by: Chen, Shuo, et al.
Published: (2024)
by: Chen, Shuo, et al.
Published: (2024)
Strong Yet Tough Transparent Paper with Superb Foldability
by: Xiaoqi Lin, et al.
Published: (2024)
by: Xiaoqi Lin, et al.
Published: (2024)
NegotiaToR: Towards A Simple Yet Effective On-demand Reconfigurable Datacenter Network
by: Liang, Cong, et al.
Published: (2024)
by: Liang, Cong, et al.
Published: (2024)
No Mean Feat: Simple, Strong Baselines for Context Compression
by: Feldman, Yair, et al.
Published: (2025)
by: Feldman, Yair, et al.
Published: (2025)
BSPA: Exploring Black-box Stealthy Prompt Attacks against Image Generators
by: Tian, Yu, et al.
Published: (2024)
by: Tian, Yu, et al.
Published: (2024)
Short-Hair Black Holes and the Strong Cosmic Censorship Conjecture
by: Tu, Zhiqin, et al.
Published: (2024)
by: Tu, Zhiqin, et al.
Published: (2024)
DogeFuzz: A Simple Yet Efficient Grey-box Fuzzer for Ethereum Smart Contracts
by: Medeiros, Ismael, et al.
Published: (2024)
by: Medeiros, Ismael, et al.
Published: (2024)
Training Users Against Human and GPT-4 Generated Social Engineering Attacks
by: Malloy, Tailia, et al.
Published: (2025)
by: Malloy, Tailia, et al.
Published: (2025)
AgentTypo: Adaptive Typographic Prompt Injection Attacks against Black-box Multimodal Agents
by: Li, Yanjie, et al.
Published: (2025)
by: Li, Yanjie, et al.
Published: (2025)
R.I.P.: A Simple Black-box Attack on Continual Test-time Adaptation
by: Hoang, Trung-Hieu, et al.
Published: (2024)
by: Hoang, Trung-Hieu, et al.
Published: (2024)
Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks
by: Li, Ang, et al.
Published: (2025)
by: Li, Ang, et al.
Published: (2025)
Simple and Effective Baselines for Code Summarisation Evaluation
by: Robinson, Jade, et al.
Published: (2025)
by: Robinson, Jade, et al.
Published: (2025)
Out-of-the-box: Black-box Causal Attacks on Object Detectors
by: Navaratnarajah, Melane, et al.
Published: (2025)
by: Navaratnarajah, Melane, et al.
Published: (2025)
Class-feature Watermark: A Resilient Black-box Watermark Against Model Extraction Attacks
by: Xiao, Yaxin, et al.
Published: (2025)
by: Xiao, Yaxin, et al.
Published: (2025)
Similar Items
-
Pushing the Frontier of Black-Box LVLM Attacks via Fine-Grained Detail Targeting
by: Zhao, Xiaohan, et al.
Published: (2026) -
Voice Jailbreak Attacks Against GPT-4o
by: Shen, Xinyue, et al.
Published: (2024) -
Open CaptchaWorld: A Comprehensive Web-based Platform for Testing and Benchmarking Multimodal LLM Agents
by: Luo, Yaxin, et al.
Published: (2025) -
A Simple Yet Strong Baseline for Long-Term Conversational Memory of LLM Agents
by: Zhou, Sizhe, et al.
Published: (2025) -
AgentOccam: A Simple Yet Strong Baseline for LLM-Based Web Agents
by: Yang, Ke, et al.
Published: (2024)