{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T20:17:29Z","timestamp":1783455449466,"version":"3.55.0"},"reference-count":78,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3107100"],"award-info":[{"award-number":["2023YFB3107100"]}]},{"name":"Key \u201cPioneer\u201d R&D Projects of Zhejiang Province","award":["2023C01120"],"award-info":[{"award-number":["2023C01120"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22A2032"],"award-info":[{"award-number":["U22A2032"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072400"],"award-info":[{"award-number":["62072400"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Collaborative Innovation Center of Artificial Intelligence by MOE and Zhejiang Provincial Government"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Visual. Comput. Graphics"],"published-print":{"date-parts":[[2025,1]]},"DOI":"10.1109\/tvcg.2024.3456150","type":"journal-article","created":{"date-parts":[[2024,9,16]],"date-time":"2024-09-16T13:53:18Z","timestamp":1726494798000},"page":"492-502","source":"Crossref","is-referenced-by-count":12,"title":["AdversaFlow: Visual Red Teaming for Large Language Models with Multi-Level Adversarial Flow"],"prefix":"10.1109","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9057-8353","authenticated-orcid":false,"given":"Dazhen","family":"Deng","sequence":"first","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chuhan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huawei","family":"Zheng","sequence":"additional","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2311-4943","authenticated-orcid":false,"given":"Yuwen","family":"Pu","sequence":"additional","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1119-3237","authenticated-orcid":false,"given":"Yingcai","family":"Wu","sequence":"additional","affiliation":[{"name":"Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2019.2934262"},{"key":"ref2","first-page":"23716","article-title":"Flamingo: a Visual Language Model for Few-Shot Learning","volume":"35","author":"Alayrac","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/vast47406.2019.8986948"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2020.2969185"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1111\/cgf.14034"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2023.3326588"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2020.2973258"},{"key":"ref8","article-title":"Alpagasus: Training a Better Alpaca Model with Fewer Data","volume-title":"Proceedings of The Twelfth International Conference on Learning Representations","author":"Chen"},{"issue":"3","key":"ref9","first-page":"469","volume-title":"Journal of Visualization","volume":"27","author":"Chen","year":"2024"},{"issue":"240","key":"ref10","first-page":"1","article-title":"Palm: Scaling Language Modeling with Pathways","volume":"24","author":"Chowdhery","year":"2023","journal-title":"Journal of Machine Learning Research"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/vis47514.2020.00061"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2022.3213565"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1461"},{"key":"ref14","author":"Ganguli","year":"2022","journal-title":"Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned"},{"key":"ref15","author":"Ge","year":"2023","journal-title":"MART: Improving LLM Safety with Multi-round Automatic Red-Teaming"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.visinf.2024.04.005"},{"key":"ref17","volume-title":"Perspective API","year":"2023"},{"key":"ref18","author":"He","year":"2021","journal-title":"DeBERTa: Decoding-enhanced BERT with Disentangled Attention"},{"key":"ref19","article-title":"Measuring Massive Multitask Language Understanding","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Hendrycks"},{"key":"ref20","volume-title":"AutoTrain Documentation","year":"2023"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2021.3114793"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2017.2744718"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2018.2864500"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.visinf.2023.05.001"},{"key":"ref25","author":"Lapid","year":"2023","journal-title":"Open Sesame! Universal Black Box Jailbreaking of Large Language Models"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2024.3370654"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2019.2934667"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-emnlp.311"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2016.2598831"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s12650-024-00955-5"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2020.3028888"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2019.2934631"},{"key":"ref33","author":"Mehrabi","year":"2023","journal-title":"FLIRT: Feedback Loop In-context Red Teaming"},{"key":"ref34","year":"2023","journal-title":"Llama 2: Open Foundation and Fine-Tuned Chat Models"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2019.2934267"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.visinf.2024.04.004"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2009.111"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1201\/b17511"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2020.3030354"},{"key":"ref40","year":"2024","journal-title":"GPT-4 Technical Report"},{"key":"ref41","volume-title":"Reward Model: DeBERTa v3 Large v2","year":"2023"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.225"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.442"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2023.3243676"},{"key":"ref45","author":"Shayegani","year":"2023","journal-title":"Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks"},{"key":"ref46","article-title":"Do Anything Now","author":"Shen","year":"2023","journal-title":"Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.346"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2019.2934629"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2018.2865044"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2017.2744158"},{"key":"ref51","author":"Sun","year":"2024","journal-title":"TrustLLM: Trustwor-thiness in Large Language Models"},{"key":"ref52","volume-title":"Alpaca Dataset","year":"2023"},{"key":"ref53","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"International Conference on Learning Representations","author":"Tram\u00e8r","year":"2018"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/tvcg.2022.3225114"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2018.2864504"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2018.2816223"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2021.3076749"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2020.3030471"},{"key":"ref59","first-page":"896","article-title":"Do-Not-Answer: A Dataset for Evaluating Safeguards in LLMs","author":"Wang","year":"2024","journal-title":"Findings of the Association for Computational Linguistics: The European Chapter of the Association for Computational Linguistics"},{"key":"ref60","article-title":"Aligning Large Language Models with Human: A Survey","author":"Wang","year":"2023","journal-title":"arXiv preprint"},{"key":"ref61","first-page":"80079","article-title":"Jailbroken: How Does LLM Safety Training Fail","volume-title":"Proceedings of Advances in Neural Information Processing Systems","volume":"36","author":"Wei"},{"key":"ref62","author":"Weidinger","year":"2021","journal-title":"Ethical and social risks of harm from Language Models"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533088"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.3389\/frai.2021.550030"},{"key":"ref65","article-title":"Adversarial Attacks on LLMs","author":"Weng","year":"2023","journal-title":"lilianweng.github.io"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/s12650-023-00936-0"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.235"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2023.3345340"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2022.3182488"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2023.3327163"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3613904.3642237"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1007\/s41095-020-0191-7"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2018.2864475"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1016\/j.visinf.2023.06.008"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1016\/j.visinf.2024.04.001"},{"key":"ref76","first-page":"1097","article-title":"Texy-gen: A Benchmarking Platform for Text Generation Models","volume-title":"Proceedings of The 41 st International ACM SIGIR Conference on Research & Development in Information Retrieval","author":"Zhu"},{"key":"ref77","first-page":"9274","article-title":"Adversarial training for high-stakes reliability","volume":"35","author":"Ziegler","year":"2022","journal-title":"Proceedings of Advances in Neural Information Processing Systems"},{"key":"ref78","author":"Zou","year":"2023","journal-title":"Universal and Transferable Adversarial Attacks on Aligned Language Models"}],"container-title":["IEEE Transactions on Visualization and Computer Graphics"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/2945\/10766346\/10681029.pdf?arnumber=10681029","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T19:44:17Z","timestamp":1783453457000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10681029\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1]]},"references-count":78,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tvcg.2024.3456150","relation":{},"ISSN":["1077-2626","1941-0506","2160-9306"],"issn-type":[{"value":"1077-2626","type":"print"},{"value":"1941-0506","type":"electronic"},{"value":"2160-9306","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1]]}}}