{"data":{"id":"371477f3-f2f4-4522-8cc4-1698eb5e1d17","title":"One Attack to Fool Them All: Highly Transferable Black-Box Adversarial Attacks on Frontier MLLMs","summary":"Researchers ask whether a single adversarial image can consistently mislead diverse frontier MLLMs in black-box settings. They present O-Attack, a transfer-based black-box framework that exploits cross-modally aligned semantic representations in surrogate models, and report attack success rates rising on GPT-5.4 (29.1% to 77.2%), Claude-4.6 (42.8% to 81.6%), and Gemini-3.1 (38.2% to 80.9%). Across 24 MLLMs, O-Attack outperforms six state-of-the-art methods in black-box transferability.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://arxiv.org/abs/2609.33833v1","publishedAt":"2026-09-27T18:33:38.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["model_evasion"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":["OpenAI","Anthropic","Google"],"affectedVendorsRaw":["GPT-5.4","Claude-4.6","Gemini-3.1"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-09-27T18:33:38.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","safety"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"preprint","atlasIds":null}}