English

Unaligning Everything: Or Aligning Any Text to Any Image in Multimodal Models

Computer Vision and Pattern Recognition 2024-07-02 v1 Artificial Intelligence Computation and Language Machine Learning

Abstract

Utilizing a shared embedding space, emerging multimodal models exhibit unprecedented zero-shot capabilities. However, the shared embedding space could lead to new vulnerabilities if different modalities can be misaligned. In this paper, we extend and utilize a recently developed effective gradient-based procedure that allows us to match the embedding of a given text by minimally modifying an image. Using the procedure, we show that we can align the embeddings of distinguishable texts to any image through unnoticeable adversarial attacks in joint image-text models, revealing that semantically unrelated images can have embeddings of identical texts and at the same time visually indistinguishable images can be matched to the embeddings of very different texts. Our technique achieves 100\% success rate when it is applied to text datasets and images from multiple sources. Without overcoming the vulnerability, multimodal models cannot robustly align inputs from different modalities in a semantically meaningful way. \textbf{Warning: the text data used in this paper are toxic in nature and may be offensive to some readers.}

Keywords

Cite

@article{arxiv.2407.01157,
  title  = {Unaligning Everything: Or Aligning Any Text to Any Image in Multimodal Models},
  author = {Shaeke Salman and Md Montasir Bin Shams and Xiuwen Liu},
  journal= {arXiv preprint arXiv:2407.01157},
  year   = {2024}
}

Comments

14 pages, 14 figures. arXiv admin note: substantial text overlap with arXiv:2401.15568, arXiv:2402.08473

R2 v1 2026-06-28T17:24:45.855Z