JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nian, Yi, Zhu, Shenzhe, Qin, Yuehan, Li, Li, Wang, Ziyi, Xiao, Chaowei, Zhao, Yue
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909692305866752
author Nian, Yi
Zhu, Shenzhe
Qin, Yuehan
Li, Li
Wang, Ziyi
Xiao, Chaowei
Zhao, Yue
author_facet Nian, Yi
Zhu, Shenzhe
Qin, Yuehan
Li, Li
Wang, Ziyi
Xiao, Chaowei
Zhao, Yue
contents Multimodal large language models (MLLMs) excel in vision-language tasks but also pose significant risks of generating harmful content, particularly through jailbreak attacks. Jailbreak attacks refer to intentional manipulations that bypass safety mechanisms in models, leading to the generation of inappropriate or unsafe content. Detecting such attacks is critical to ensuring the responsible deployment of MLLMs. Existing jailbreak detection methods face three primary challenges: (1) Many rely on model hidden states or gradients, limiting their applicability to white-box models, where the internal workings of the model are accessible; (2) They involve high computational overhead from uncertainty-based analysis, which limits real-time detection, and (3) They require fully labeled harmful datasets, which are often scarce in real-world settings. To address these issues, we introduce a test-time adaptive framework called JAILDAM. Our method leverages a memory-based approach guided by policy-driven unsafe knowledge representations, eliminating the need for explicit exposure to harmful data. By dynamically updating unsafe knowledge during test-time, our framework improves generalization to unseen jailbreak strategies while maintaining efficiency. Experiments on multiple VLM jailbreak benchmarks demonstrate that JAILDAM delivers state-of-the-art performance in harmful content detection, improving both accuracy and speed.
format Preprint
id arxiv_https___arxiv_org_abs_2504_03770
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model
Nian, Yi
Zhu, Shenzhe
Qin, Yuehan
Li, Li
Wang, Ziyi
Xiao, Chaowei
Zhao, Yue
Cryptography and Security
Artificial Intelligence
Multimodal large language models (MLLMs) excel in vision-language tasks but also pose significant risks of generating harmful content, particularly through jailbreak attacks. Jailbreak attacks refer to intentional manipulations that bypass safety mechanisms in models, leading to the generation of inappropriate or unsafe content. Detecting such attacks is critical to ensuring the responsible deployment of MLLMs. Existing jailbreak detection methods face three primary challenges: (1) Many rely on model hidden states or gradients, limiting their applicability to white-box models, where the internal workings of the model are accessible; (2) They involve high computational overhead from uncertainty-based analysis, which limits real-time detection, and (3) They require fully labeled harmful datasets, which are often scarce in real-world settings. To address these issues, we introduce a test-time adaptive framework called JAILDAM. Our method leverages a memory-based approach guided by policy-driven unsafe knowledge representations, eliminating the need for explicit exposure to harmful data. By dynamically updating unsafe knowledge during test-time, our framework improves generalization to unseen jailbreak strategies while maintaining efficiency. Experiments on multiple VLM jailbreak benchmarks demonstrate that JAILDAM delivers state-of-the-art performance in harmful content detection, improving both accuracy and speed.
title JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2504.03770