Saved in:
Bibliographic Details
Main Authors: Zhao, Shiji, Xiong, Shukun, Huang, Yao, Jin, Yan, Wu, Zhenyu, Guan, Jiyang, Duan, Ranjie, Tao, Jialing, Xue, Hui, Wei, Xingxing
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2512.05853
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915658915119104
author Zhao, Shiji
Xiong, Shukun
Huang, Yao
Jin, Yan
Wu, Zhenyu
Guan, Jiyang
Duan, Ranjie
Tao, Jialing
Xue, Hui
Wei, Xingxing
author_facet Zhao, Shiji
Xiong, Shukun
Huang, Yao
Jin, Yan
Wu, Zhenyu
Guan, Jiyang
Duan, Ranjie
Tao, Jialing
Xue, Hui
Wei, Xingxing
contents Multimodal Large Language Models (MLLMs) are widely used in various fields due to their powerful cross-modal comprehension and generation capabilities. However, more modalities bring more vulnerabilities to being utilized for jailbreak attacks, which induces MLLMs to output harmful content. Due to the strong reasoning ability of MLLMs, previous jailbreak attacks try to explore reasoning safety risk in text modal, while similar threats have been largely overlooked in the visual modal. To fully evaluate potential safety risks in the visual reasoning task, we propose Visual Reasoning Sequential Attack (VRSA), which induces MLLMs to gradually externalize and aggregate complete harmful intent by decomposing the original harmful text into several sequentially related sub-images. In particular, to enhance the rationality of the scene in the image sequence, we propose Adaptive Scene Refinement to optimize the scene most relevant to the original harmful query. To ensure the semantic continuity of the generated image, we propose Semantic Coherent Completion to iteratively rewrite each sub-text combined with contextual information in this scene. In addition, we propose Text-Image Consistency Alignment to keep the semantical consistency. A series of experiments demonstrates that the VRSA can achieve a higher attack success rate compared with the state-of-the-art jailbreak attack methods on both the open-source and closed-source MLLMs such as GPT-4o and Claude-4.5-Sonnet.
format Preprint
id arxiv_https___arxiv_org_abs_2512_05853
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle VRSA: Jailbreaking Multimodal Large Language Models through Visual Reasoning Sequential Attack
Zhao, Shiji
Xiong, Shukun
Huang, Yao
Jin, Yan
Wu, Zhenyu
Guan, Jiyang
Duan, Ranjie
Tao, Jialing
Xue, Hui
Wei, Xingxing
Computer Vision and Pattern Recognition
Multimodal Large Language Models (MLLMs) are widely used in various fields due to their powerful cross-modal comprehension and generation capabilities. However, more modalities bring more vulnerabilities to being utilized for jailbreak attacks, which induces MLLMs to output harmful content. Due to the strong reasoning ability of MLLMs, previous jailbreak attacks try to explore reasoning safety risk in text modal, while similar threats have been largely overlooked in the visual modal. To fully evaluate potential safety risks in the visual reasoning task, we propose Visual Reasoning Sequential Attack (VRSA), which induces MLLMs to gradually externalize and aggregate complete harmful intent by decomposing the original harmful text into several sequentially related sub-images. In particular, to enhance the rationality of the scene in the image sequence, we propose Adaptive Scene Refinement to optimize the scene most relevant to the original harmful query. To ensure the semantic continuity of the generated image, we propose Semantic Coherent Completion to iteratively rewrite each sub-text combined with contextual information in this scene. In addition, we propose Text-Image Consistency Alignment to keep the semantical consistency. A series of experiments demonstrates that the VRSA can achieve a higher attack success rate compared with the state-of-the-art jailbreak attack methods on both the open-source and closed-source MLLMs such as GPT-4o and Claude-4.5-Sonnet.
title VRSA: Jailbreaking Multimodal Large Language Models through Visual Reasoning Sequential Attack
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2512.05853