English

Transfer Attack for Bad and Good: Explain and Boost Adversarial Transferability across Multimodal Large Language Models

Computer Vision and Pattern Recognition 2025-07-22 v5

Abstract

Multimodal Large Language Models (MLLMs) demonstrate exceptional performance in cross-modality interaction, yet they also suffer adversarial vulnerabilities. In particular, the transferability of adversarial examples remains an ongoing challenge. In this paper, we specifically analyze the manifestation of adversarial transferability among MLLMs and identify the key factors that influence this characteristic. We discover that the transferability of MLLMs exists in cross-LLM scenarios with the same vision encoder and indicate \underline{\textit{two key Factors}} that may influence transferability. We provide two semantic-level data augmentation methods, Adding Image Patch (AIP) and Typography Augment Transferability Method (TATM), which boost the transferability of adversarial examples across MLLMs. To explore the potential impact in the real world, we utilize two tasks that can have both negative and positive societal impacts: \ding{182} Harmful Content Insertion and \ding{183} Information Protection.

Keywords

Cite

@article{arxiv.2405.20090,
  title  = {Transfer Attack for Bad and Good: Explain and Boost Adversarial Transferability across Multimodal Large Language Models},
  author = {Hao Cheng and Erjia Xiao and Jiayan Yang and Jinhao Duan and Yichi Wang and Jiahang Cao and Qiang Zhang and Le Yang and Kaidi Xu and Jindong Gu and Renjing Xu},
  journal= {arXiv preprint arXiv:2405.20090},
  year   = {2025}
}

Comments

This paper is accepted by ACM MM 2025

R2 v1 2026-06-28T16:47:14.830Z