Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation
Fuente:
arXiv
Guardado en:
| Autores principales: | , , , , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866912858919403520 |
|---|---|
| author | Li, Changyue Li, Jiaying Yuan, Youliang He, Jiaming Huang, Zhicong He, Pinjia |
| author_facet | Li, Changyue Li, Jiaying Yuan, Youliang He, Jiaming Huang, Zhicong He, Pinjia |
| contents | Multimodal Large Language Models (MLLMs) are increasingly deployed in stateless systems, such as autonomous driving and robotics.
This paper investigates a novel threat: Semantic-Aware Hijacking. We explore the feasibility of hijacking multiple stateless decisions simultaneously using a single universal perturbation.
We introduce the Semantic-Aware Universal Perturbation (SAUP), which acts as a semantic router, "actively" perceiving input semantics and routing them to distinct, attacker-defined targets.
To achieve this, we conduct theoretical and empirical analysis on the geometric properties in the latent space. Guided by these insights, we propose the Semantic-Oriented (SORT) optimization strategy and annotate a new dataset with fine-grained semantics to evaluate performance. Extensive experiments on three representative MLLMs demonstrate the fundamental feasibility of this attack, achieving a 66% attack success rate over five targets using a single frame against Qwen. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2511_20002 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation Li, Changyue Li, Jiaying Yuan, Youliang He, Jiaming Huang, Zhicong He, Pinjia Computer Vision and Pattern Recognition Artificial Intelligence Cryptography and Security Multimodal Large Language Models (MLLMs) are increasingly deployed in stateless systems, such as autonomous driving and robotics. This paper investigates a novel threat: Semantic-Aware Hijacking. We explore the feasibility of hijacking multiple stateless decisions simultaneously using a single universal perturbation. We introduce the Semantic-Aware Universal Perturbation (SAUP), which acts as a semantic router, "actively" perceiving input semantics and routing them to distinct, attacker-defined targets. To achieve this, we conduct theoretical and empirical analysis on the geometric properties in the latent space. Guided by these insights, we propose the Semantic-Oriented (SORT) optimization strategy and annotate a new dataset with fine-grained semantics to evaluate performance. Extensive experiments on three representative MLLMs demonstrate the fundamental feasibility of this attack, achieving a 66% attack success rate over five targets using a single frame against Qwen. |
| title | Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation |
| topic | Computer Vision and Pattern Recognition Artificial Intelligence Cryptography and Security |
| url | https://arxiv.org/abs/2511.20002 |