{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:18:02Z","timestamp":1777889882877,"version":"3.51.4"},"reference-count":42,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00198","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"2045-2054","source":"Crossref","is-referenced-by-count":0,"title":["Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency"],"prefix":"10.1109","author":[{"given":"Shiji","family":"Zhao","sequence":"first","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Ranjie","family":"Duan","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Fengxiang","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Chi","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Caixin","family":"Kang","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Shouwei","family":"Ruan","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Jialing","family":"Tao","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"YueFeng","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Hui","family":"Xue","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]},{"given":"Xingxing","family":"Wei","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University,State Key Laboratory of Virtual Reality Technology and Systems,Beijing,China"}]}],"member":"263","reference":[{"key":"ref1","author":"Alon","year":"2023","journal-title":"guage model attacks with perplexity"},{"key":"ref2","volume-title":"The claude 3 model family: Opus, sonnet, haiku","year":"2024"},{"key":"ref3","article-title":"Qwen-vl: A versatile vision-language model for understanding, localization, text reading, and beyond","author":"Bai","year":"2023","journal-title":"arXiv preprint"},{"key":"ref4","article-title":"Image hijacks: Adversarial images can control generative models at runtime","author":"Bailey","year":"2023","journal-title":"arXiv preprint"},{"key":"ref5","article-title":"Cross-modal safety alignment: Is textual unlearning all you need?","author":"Chakraborty","year":"2024","journal-title":"arXiv preprint"},{"key":"ref6","article-title":"Internvl: Scaling up vision foundation models and aligning for generic visual-linguistic tasks","author":"Chen","year":"2023","journal-title":"arXiv preprint"},{"key":"ref7","article-title":"Multilingual jailbreak challenges in large language models","author":"Deng","year":"2023","journal-title":"arXiv preprint"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i22.34568"},{"key":"ref9","volume-title":"Gemini","year":"2024"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-short.27"},{"key":"ref11","article-title":"Llama guard: Llm-based input-output safeguard for human-ai conversations","author":"Inan","year":"2023","journal-title":"arXiv preprint"},{"key":"ref12","article-title":"Llava-next-interleave: Tackling multi-image, video, and 3d in large multimodal models","author":"Li","year":"2024","journal-title":"arXiv preprint"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73464-9_11"},{"key":"ref14","volume-title":"Images are achilles\u2019 heel of alignment: Exploit-Detecting lanarXiv preprint arXiv preprint","author":"Li"},{"key":"ref15","article-title":"Autodan: Generating stealthy jailbreak prompts on aligned large language models","author":"Liu","year":"2023","journal-title":"arXiv preprint"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72992-8_22"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.153"},{"key":"ref18","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv preprint"},{"key":"ref19","article-title":"Jailbreaking attack against multimodal large language model","author":"Niu","year":"2024","journal-title":"arXiv preprint"},{"key":"ref20","volume-title":"Perspectiveapi","year":"2023"},{"key":"ref21","volume-title":"Chatgpt","year":"2023"},{"key":"ref22","volume-title":"Moderationapi","year":"2023"},{"key":"ref23","volume-title":"Hello gpt-4o","year":"2024"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"ref25","article-title":"Red-teaming the stable diffusion safety filter","author":"Rando","year":"2022","journal-title":"arXiv preprint"},{"key":"ref26","article-title":"Jailbreak in pieces: Compositional adversarial attacks on multimodal language models","volume-title":"The Twelfth International Conference on Learning Representations","author":"Shayegani","year":"2023"},{"key":"ref27","article-title":"\u201cdo anything now\u201d: Characterizing and evaluating in-the-wild jailbreak prompts on large language models","author":"Shen","year":"2023","journal-title":"arXiv preprint"},{"key":"ref28","article-title":"Mrj-agent: An effective jailbreak agent for multi-round dialogue","author":"Wang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.52202\/075280-3508"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i26.34983"},{"key":"ref31","article-title":"Defending jailbreak attack in vlms via cross-modality information detector","author":"Xu","year":"2024","journal-title":"arXiv preprint"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"ref33","article-title":"Unveiling the safety of gpt-4o: An empirical study using jailbreak attacks","author":"Ying","year":"2024","journal-title":"arXiv preprint"},{"key":"ref34","article-title":"When and why visionlanguage models behave like bags-of-words, and what to do about it?","author":"Yuksekgonul","year":"2022","journal-title":"arXiv preprint arXiv"},{"key":"ref35","article-title":"A mutation-based method for multi-modal jailbreaking attack detection","author":"Zhang","year":"2023","journal-title":"arXiv preprint"},{"key":"ref36","article-title":"Benchmarking trustworthiness of multimodal large language models: A comprehensive study","author":"Zhang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref37","article-title":"The first to know: How token distributions reveal hidden knowledge in large visionlanguage models?","author":"Zhao","year":"2024","journal-title":"arXiv preprint"},{"key":"ref38","article-title":"On evaluating adversarial robustness of large vision-language models","volume":"36","author":"Zhao","year":"2024","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref39","article-title":"On prompt-driven safeguarding for large language models","volume-title":"Forty-first International Conference on Machine Learning","author":"Zheng","year":"2024"},{"key":"ref40","article-title":"Minigpt-4: Enhancing vision-language understanding with advanced large language models","author":"Zhu","year":"2023","journal-title":"arXiv preprint"},{"key":"ref41","article-title":"Safety fine-tuning at (almost) no cost: A baseline for vision large language models","author":"Zong","year":"2024","journal-title":"arXiv preprint"},{"key":"ref42","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023","journal-title":"arXiv preprint"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11446016.pdf?arnumber=11446016","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:22:46Z","timestamp":1777612966000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11446016\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00198","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}