Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Li, Changyue, Li, Jiaying, Yuan, Youliang, He, Jiaming, Huang, Zhicong, He, Pinjia
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866912858919403520
author Li, Changyue
Li, Jiaying
Yuan, Youliang
He, Jiaming
Huang, Zhicong
He, Pinjia
author_facet Li, Changyue
Li, Jiaying
Yuan, Youliang
He, Jiaming
Huang, Zhicong
He, Pinjia
contents Multimodal Large Language Models (MLLMs) are increasingly deployed in stateless systems, such as autonomous driving and robotics. This paper investigates a novel threat: Semantic-Aware Hijacking. We explore the feasibility of hijacking multiple stateless decisions simultaneously using a single universal perturbation. We introduce the Semantic-Aware Universal Perturbation (SAUP), which acts as a semantic router, "actively" perceiving input semantics and routing them to distinct, attacker-defined targets. To achieve this, we conduct theoretical and empirical analysis on the geometric properties in the latent space. Guided by these insights, we propose the Semantic-Oriented (SORT) optimization strategy and annotate a new dataset with fine-grained semantics to evaluate performance. Extensive experiments on three representative MLLMs demonstrate the fundamental feasibility of this attack, achieving a 66% attack success rate over five targets using a single frame against Qwen.
format Preprint
id arxiv_https___arxiv_org_abs_2511_20002
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation
Li, Changyue
Li, Jiaying
Yuan, Youliang
He, Jiaming
Huang, Zhicong
He, Pinjia
Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
Multimodal Large Language Models (MLLMs) are increasingly deployed in stateless systems, such as autonomous driving and robotics. This paper investigates a novel threat: Semantic-Aware Hijacking. We explore the feasibility of hijacking multiple stateless decisions simultaneously using a single universal perturbation. We introduce the Semantic-Aware Universal Perturbation (SAUP), which acts as a semantic router, "actively" perceiving input semantics and routing them to distinct, attacker-defined targets. To achieve this, we conduct theoretical and empirical analysis on the geometric properties in the latent space. Guided by these insights, we propose the Semantic-Oriented (SORT) optimization strategy and annotate a new dataset with fine-grained semantics to evaluate performance. Extensive experiments on three representative MLLMs demonstrate the fundamental feasibility of this attack, achieving a 66% attack success rate over five targets using a single frame against Qwen.
title Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2511.20002