{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T23:15:34Z","timestamp":1782947734198,"version":"3.54.5"},"reference-count":44,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00830","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"8875-8884","source":"Crossref","is-referenced-by-count":2,"title":["Ideator: Jailbreaking and Benchmarking Large Vision-Language Models Using Themselves"],"prefix":"10.1109","author":[{"given":"Ruofan","family":"Wang","sequence":"first","affiliation":[{"name":"Fudan University,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Juncheng","family":"Li","sequence":"additional","affiliation":[{"name":"Fudan University,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yixu","family":"Wang","sequence":"additional","affiliation":[{"name":"Fudan University,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Wang","sequence":"additional","affiliation":[{"name":"Huawei Technologies Ltd.,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaosen","family":"Wang","sequence":"additional","affiliation":[{"name":"Huawei Technologies Ltd.,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"Teng","sequence":"additional","affiliation":[{"name":"Shanghai Artificial Intelligence Laboratory,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yingchun","family":"Wang","sequence":"additional","affiliation":[{"name":"Shanghai Artificial Intelligence Laboratory,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingjun","family":"Ma","sequence":"additional","affiliation":[{"name":"Fudan University,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu-Gang","family":"Jiang","sequence":"additional","affiliation":[{"name":"Fudan University,China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Gpt-4 technical report","author":"Achiam","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref2","volume-title":"Claude: An ai assistant","year":"2025"},{"key":"ref3","article-title":"(ab) using images and sounds for indirect instruction injection in multi-modal 11 ms","author":"Bagdasaryan","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref4","article-title":"Image hijacks: Adversarial images can control generative models at runtime","author":"Bailey","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref5","article-title":"Language models are few-shot learners","author":"Brown","year":"2020","journal-title":"arxiv preprint arxiv"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2687"},{"key":"ref7","article-title":"Jailbreaking black box large language models in twenty queries","author":"Chao","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref8","article-title":"Minigpt-v2: large language model as a unified interface for vision-language multi-task learning","author":"Chen","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref9","volume-title":"Vicuna: An open-source chatbot impressing gpt-4 with 90% chatgpt quality","author":"Chiang","year":"2023"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2142"},{"key":"ref11","volume-title":"Gemini: Flash thinking","year":"2025"},{"key":"ref12","article-title":"An image is worth 16 \u00d7 16 words: Transformers for image recognition at scale","author":"Dosovitskiy","year":"2020","journal-title":"arxiv preprint arxiv"},{"key":"ref13","article-title":"The llama 3 herd of models","author":"Dubey","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref14","article-title":"Jailbreak in pieces: Compositional adversarial attacks on multi-modal language models","author":"Shayegani","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref15","article-title":"Jailbreakv: A benchmark for assessing the robustness of multimodal large language models against jailbreak attacks","author":"Luo","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72661-3_5"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19784-0_6"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i22.34568"},{"key":"ref19","volume-title":"More than you\u2019ve asked for: A comprehensive analysis of novel prompt injection threats to application-integrated large language models","author":"Greshake","year":"2023"},{"key":"ref20","article-title":"Llava-onevision: Easy visual task transfer","author":"Li","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref21","article-title":"Privacy in large language models: Attacks, defenses and future directions","author":"Li","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2025.3592935"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52733.2024.02484"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72992-8_22"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681379"},{"key":"ref26","article-title":"Visual-roleplay: Universal jailbreak attack on multimodal large language models via role-playing image character","author":"Ma","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref27","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022","journal-title":"arxiv preprint arxiv"},{"key":"ref28","article-title":"Jailbreaking attack against multimodal large language model","author":"Niu","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"ref30","volume-title":"Learning transferable visual models from natural language supervision","author":"Radford","year":"2021"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref32","article-title":"Survey of vulnerabilities in large language models revealed by adversarial attacks","author":"Shayegani","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref33","article-title":"Chameleon: Mixed-modal early-fusion foundation models","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref34","article-title":"Gemini: a family of highly capable multimodal models","author":"Team","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref35","article-title":"Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context","author":"Team","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref36","article-title":"Llama: Open and efficient foundation language models","author":"Touvron","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref37","article-title":"Qwen2-vl: Enhancing vision-language model\u2019s perception of the world at any resolution","author":"Wang","year":"2024","journal-title":"arxiv preprint arxiv"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681092"},{"key":"ref39","volume-title":"Chain-of-thought prompting elicits reasoning in large language models","author":"Wei","year":"2022"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-025-02613-1"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3743126"},{"key":"ref42","article-title":"A mutationbased method for multi-modal jailbreaking attack detection","author":"Zhang","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref43","article-title":"Minigpt-4: Enhancing vision-language understanding with advanced large language models","author":"Zhu","year":"2023","journal-title":"arxiv preprint arxiv"},{"key":"ref44","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023","journal-title":"arxiv preprint arxiv"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11446151.pdf?arnumber=11446151","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:22:15Z","timestamp":1777612935000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11446151\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00830","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}