Resource Consumption Red-Teaming for Large Vision-Language Models

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Gao, Haoran, Zhang, Yuanhe, Zhou, Zhenhong, Jiang, Lei, Meng, Fanyu, Xiao, Yujia, Sun, Li, Wang, Kun, Liu, Yang, Feng, Junlan
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866912607400624128
author Gao, Haoran
Zhang, Yuanhe
Zhou, Zhenhong
Jiang, Lei
Meng, Fanyu
Xiao, Yujia
Sun, Li
Wang, Kun
Liu, Yang
Feng, Junlan
author_facet Gao, Haoran
Zhang, Yuanhe
Zhou, Zhenhong
Jiang, Lei
Meng, Fanyu
Xiao, Yujia
Sun, Li
Wang, Kun
Liu, Yang
Feng, Junlan
contents Resource Consumption Attacks (RCAs) have emerged as a significant threat to the deployment of Large Language Models (LLMs). With the integration of vision modalities, additional attack vectors exacerbate the risk of RCAs in large vision-language models (LVLMs). However, existing red-teaming studies have mainly overlooked visual inputs as a potential attack surface, resulting in insufficient mitigation strategies against RCAs in LVLMs. To address this gap, we propose RECITE ($\textbf{Re}$source $\textbf{C}$onsumpt$\textbf{i}$on Red-$\textbf{Te}$aming for LVLMs), the first approach for exploiting visual modalities to trigger unbounded RCAs red-teaming. First, we present $\textit{Vision Guided Optimization}$, a fine-grained pixel-level optimization to obtain \textit{Output Recall Objective} adversarial perturbations, which can induce repeating output. Then, we inject the perturbations into visual inputs, triggering unbounded generations to achieve the goal of RCAs. Empirical results demonstrate that RECITE increases service response latency by over 26 $\uparrow$, resulting in an additional 20\% increase in GPU utilization and memory consumption. Our study reveals security vulnerabilities in LVLMs and establishes a red-teaming framework that can facilitate the development of future defenses against RCAs.
format Preprint
id arxiv_https___arxiv_org_abs_2507_18053
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Resource Consumption Red-Teaming for Large Vision-Language Models
Gao, Haoran
Zhang, Yuanhe
Zhou, Zhenhong
Jiang, Lei
Meng, Fanyu
Xiao, Yujia
Sun, Li
Wang, Kun
Liu, Yang
Feng, Junlan
Cryptography and Security
Computation and Language
Resource Consumption Attacks (RCAs) have emerged as a significant threat to the deployment of Large Language Models (LLMs). With the integration of vision modalities, additional attack vectors exacerbate the risk of RCAs in large vision-language models (LVLMs). However, existing red-teaming studies have mainly overlooked visual inputs as a potential attack surface, resulting in insufficient mitigation strategies against RCAs in LVLMs. To address this gap, we propose RECITE ($\textbf{Re}$source $\textbf{C}$onsumpt$\textbf{i}$on Red-$\textbf{Te}$aming for LVLMs), the first approach for exploiting visual modalities to trigger unbounded RCAs red-teaming. First, we present $\textit{Vision Guided Optimization}$, a fine-grained pixel-level optimization to obtain \textit{Output Recall Objective} adversarial perturbations, which can induce repeating output. Then, we inject the perturbations into visual inputs, triggering unbounded generations to achieve the goal of RCAs. Empirical results demonstrate that RECITE increases service response latency by over 26 $\uparrow$, resulting in an additional 20\% increase in GPU utilization and memory consumption. Our study reveals security vulnerabilities in LVLMs and establishes a red-teaming framework that can facilitate the development of future defenses against RCAs.
title Resource Consumption Red-Teaming for Large Vision-Language Models
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2507.18053