Multimodal Prompt Decoupling Attack on the Safety Filters in Text-to-Image Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Peng, Xingkai, Jiang, Jun, Tong, Meng, Li, Shuai, Zhang, Weiming, Yu, Nenghai, Chen, Kejiang
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909806563950592
author Peng, Xingkai
Jiang, Jun
Tong, Meng
Li, Shuai
Zhang, Weiming
Yu, Nenghai
Chen, Kejiang
author_facet Peng, Xingkai
Jiang, Jun
Tong, Meng
Li, Shuai
Zhang, Weiming
Yu, Nenghai
Chen, Kejiang
contents Text-to-image (T2I) models have been widely applied in generating high-fidelity images across various domains. However, these models may also be abused to produce Not-Safe-for-Work (NSFW) content via jailbreak attacks. Existing jailbreak methods primarily manipulate the textual prompt, leaving potential vulnerabilities in image-based inputs largely unexplored. Moreover, text-based methods face challenges in bypassing the model's safety filters. In response to these limitations, we propose the Multimodal Prompt Decoupling Attack (MPDA), which utilizes image modality to separate the harmful semantic components of the original unsafe prompt. MPDA follows three core steps: firstly, a large language model (LLM) decouples unsafe prompts into pseudo-safe prompts and harmful prompts. The former are seemingly harmless sub-prompts that can bypass filters, while the latter are sub-prompts with unsafe semantics that trigger filters. Subsequently, the LLM rewrites the harmful prompts into natural adversarial prompts to bypass safety filters, which guide the T2I model to modify the base image into an NSFW output. Finally, to ensure semantic consistency between the generated NSFW images and the original unsafe prompts, the visual language model generates image captions, providing a new pathway to guide the LLM in iterative rewriting and refining the generated content.
format Preprint
id arxiv_https___arxiv_org_abs_2509_21360
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Multimodal Prompt Decoupling Attack on the Safety Filters in Text-to-Image Models
Peng, Xingkai
Jiang, Jun
Tong, Meng
Li, Shuai
Zhang, Weiming
Yu, Nenghai
Chen, Kejiang
Computer Vision and Pattern Recognition
Artificial Intelligence
Text-to-image (T2I) models have been widely applied in generating high-fidelity images across various domains. However, these models may also be abused to produce Not-Safe-for-Work (NSFW) content via jailbreak attacks. Existing jailbreak methods primarily manipulate the textual prompt, leaving potential vulnerabilities in image-based inputs largely unexplored. Moreover, text-based methods face challenges in bypassing the model's safety filters. In response to these limitations, we propose the Multimodal Prompt Decoupling Attack (MPDA), which utilizes image modality to separate the harmful semantic components of the original unsafe prompt. MPDA follows three core steps: firstly, a large language model (LLM) decouples unsafe prompts into pseudo-safe prompts and harmful prompts. The former are seemingly harmless sub-prompts that can bypass filters, while the latter are sub-prompts with unsafe semantics that trigger filters. Subsequently, the LLM rewrites the harmful prompts into natural adversarial prompts to bypass safety filters, which guide the T2I model to modify the base image into an NSFW output. Finally, to ensure semantic consistency between the generated NSFW images and the original unsafe prompts, the visual language model generates image captions, providing a new pathway to guide the LLM in iterative rewriting and refining the generated content.
title Multimodal Prompt Decoupling Attack on the Safety Filters in Text-to-Image Models
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2509.21360