{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:11:07Z","timestamp":1777889467334,"version":"3.51.4"},"reference-count":66,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62322216,62172409,62311530686,U24B20175"],"award-info":[{"award-number":["62322216,62172409,62311530686,U24B20175"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004835","name":"Zhejiang University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004835","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00258","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"2686-2696","source":"Crossref","is-referenced-by-count":0,"title":["Heuristic-Induced Multimodal Risk Distribution Jailbreak Attack for Multimodal Large Language Models"],"prefix":"10.1109","author":[{"given":"Teng","family":"Ma","sequence":"first","affiliation":[{"name":"Shenzhen Campus of Sun Yat-Sen University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojun","family":"Jia","sequence":"additional","affiliation":[{"name":"Nanyang Technological University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ranjie","family":"Duan","sequence":"additional","affiliation":[{"name":"Alibaba Group"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinfeng","family":"Li","sequence":"additional","affiliation":[{"name":"Nanyang Technological University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yihao","family":"Huang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoshuang","family":"Jia","sequence":"additional","affiliation":[{"name":"Renmin University of China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhixuan","family":"Chu","sequence":"additional","affiliation":[{"name":"Zhejiang University,The State Key Laboratory of Blockchain and Data Security"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenqi","family":"Ren","sequence":"additional","affiliation":[{"name":"Shenzhen Campus of Sun Yat-Sen University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Gpt-4 technical report","author":"Achiam","year":"2023","journal-title":"arXiv preprint"},{"key":"ref2","article-title":"Gemini: A family of highly capable multimodal models","volume":"abs\/2312.11805","author":"Anil","year":"2023","journal-title":"CoRR"},{"key":"ref3","article-title":"Qwen technical report","author":"Bai","year":"2023","journal-title":"CoRR, abs\/2309"},{"key":"ref4","article-title":"Qwen-vl: A frontier large vision-language model with versatile abilities","volume":"abs\/2308.12966","author":"Bai","year":"2023","journal-title":"CoRR"},{"issue":"2","key":"ref5","article-title":"Qwen-vl: A versatile vision-language model for understanding, localization, text reading, and beyond","volume":"1","author":"Bai","year":"2023","journal-title":"arXiv preprint"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00034"},{"key":"ref8","article-title":"Jailbreaking black box large language models in twenty queries","author":"Chao","year":"2023","journal-title":"arXiv preprint"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-main.32"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3731715.3733349"},{"key":"ref11","article-title":"Scaling rectified flow transformers for high-resolution image synthesis","volume-title":"Forty-first International Conference on Machine Learning","author":"Esser","year":"2024"},{"key":"ref12","article-title":"Chatglm: A family of large language models from glm-130b to glm-4 all tools","author":"Team","year":"2024","journal-title":"arXiv preprint"},{"key":"ref13","article-title":"Dimensions for designing 11 m -based writing support","author":"Gmeiner","year":"2023","journal-title":"In2Writing Workshop at CHI"},{"key":"ref14","article-title":"Figstep: Jailbreaking large vision-language models via typographic visual prompts","volume":"abs\/2311.05608","author":"Gong","year":"2023","journal-title":"CoRR"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/RO-MAN60168.2024.10731381"},{"key":"ref16","article-title":"Cold-attack: Jailbreaking llms with stealthiness and controllability","author":"Guo","year":"2024","journal-title":"arXiv preprint"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51701.2025.00982"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3416030"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i25.34821"},{"key":"ref20","article-title":"Semantic-guided prompt organization for universal goal hijacking against llms","author":"Huang","year":"2024","journal-title":"arXiv preprint"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413976"},{"key":"ref22","article-title":"Global challenge for safe and secure llms track 1","author":"Jia","year":"2024","journal-title":"arXiv preprint"},{"key":"ref23","article-title":"Improved techniques for optimization-based jailbreaking on large language models","author":"Jia","year":"2024","journal-title":"arXiv preprint"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3381180"},{"key":"ref25","article-title":"A comprehensive survey on process-oriented automatic text summarization with exploration of 11 m -based methods","author":"Jin","year":"2024","journal-title":"arXiv preprint"},{"key":"ref26","article-title":"Surveying the mllm landscape: A meta-review of current surveys","author":"Li","year":"2024","journal-title":"arXiv preprint"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.198"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670295"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73464-9_11"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.401"},{"key":"ref31","article-title":"Improved baselines with visual instruction tuning","author":"Liu","year":"2023","journal-title":"CoRR"},{"key":"ref32","author":"Liu","year":"2024","journal-title":"Llava-next: Improved reasoning, ocr, and world knowledge"},{"key":"ref33","first-page":"4711","article-title":"Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu","year":"2024"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72992-8_22"},{"key":"ref35","article-title":"Deepseek-vl: towards real-world vision-language understanding","author":"Lu","year":"2024","journal-title":"arXiv preprint"},{"key":"ref36","article-title":"An image is worth 1000 lies: Adversarial transferability across prompts on vision-language models","volume":"abs\/2403.09766","author":"Luo","year":"2024","journal-title":"CoRR"},{"key":"ref37","article-title":"Jailbreakv-28k: A benchmark for assessing the robustness of multimodal large language models against jailbreak attacks","volume":"abs\/2404.03027","author":"Luo","year":"2024","journal-title":"CoRR"},{"key":"ref38","article-title":"Harmbench: A standardized evaluation framework for automated red teaming and robust refusal","author":"Mazeika","year":"2024","journal-title":"arXiv preprint"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.3390\/info16080688"},{"key":"ref40","article-title":"o1-mini system card","year":"2024","journal-title":"CoRR"},{"key":"ref41","article-title":"Gpt-4o system card","year":"2024","journal-title":"CoRR"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3421300"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00973"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3276392"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"ref46","article-title":"Vision-llms can fool themselves with self-generated typographic attacks","author":"Qraitem","year":"2024","journal-title":"arXiv preprint"},{"key":"ref47","first-page":"8093","article-title":"Overfitting in adversarially robust deep learning","volume-title":"International conference on machine learning","author":"Rice","year":"2020"},{"key":"ref48","article-title":"A systematic survey of prompt engineering in large language models: Techniques and applications","author":"Sahoo","year":"2024","journal-title":"arXiv preprint"},{"key":"ref49","article-title":"Jailbreak in pieces: Compositional adversarial attacks on multimodal language models","volume-title":"The Twelfth International Conference on Learning Representations","author":"Shayegani","year":"2023"},{"key":"ref50","article-title":"\u201cdo anything now\u201d: Characterizing and eval-uating in-the-wild jailbreak prompts on large language models","author":"Shen","year":"2023","journal-title":"arXiv preprint"},{"key":"ref51","article-title":"Imgtrojan: Jailbreaking vision-language models with one image","author":"Tao","year":"2024","journal-title":"arXiv preprint"},{"key":"ref52","article-title":"Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context","author":"Team","year":"2024","journal-title":"arXiv preprint"},{"key":"ref53","article-title":"Llama: Open and efficient foundation language models","author":"Touvron","year":"2023","journal-title":"arXiv preprint"},{"key":"ref54","article-title":"Llama 2: Open foundation and finetuned chat models","volume":"abs\/2307.09288","author":"Touvron","year":"2023","journal-title":"CoRR"},{"key":"ref55","article-title":"How many unicorns are in this image? A safety evaluation benchmark for vision llms","volume":"abs\/2311.16101","author":"Tu","year":"2023","journal-title":"CoRR"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681092"},{"key":"ref57","article-title":"Cross-modality safety alignment","volume":"abs\/2406.15279","author":"Wang","year":"2024","journal-title":"CoRR"},{"key":"ref58","article-title":"Sorry-bench: Systematically evaluating large language model safety refusal behaviors","author":"Xie","year":"2024","journal-title":"arXiv preprint"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1093\/nsr\/nwae403"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2025.3583249"},{"key":"ref61","article-title":"Yi: Open foundation models by 01. ai","author":"Young","year":"2024","journal-title":"arXiv preprint"},{"key":"ref62","article-title":"Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts","author":"Yu","year":"2023","journal-title":"arXiv preprint"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.773"},{"key":"ref64","article-title":"Minigpt-4: Enhancing vision-language understanding with advanced large language models","volume":"abs\/2304.10592","author":"Zhu","year":"2023","journal-title":"CoRR"},{"key":"ref65","article-title":"Autodan: Automatic and interpretable adversarial attacks on large language models","author":"Zhu","year":"2023","journal-title":"Socially Responsible Language Modelling Research"},{"key":"ref66","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023","journal-title":"arXiv preprint"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444556.pdf?arnumber=11444556","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:11:20Z","timestamp":1777612280000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444556\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":66,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00258","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}