Skip to content
InfoResearchPeer-reviewedLLM-specific

Empirical Analysis of Goal Hijacking in Large Vision-Language Models via Visual Prompt Injection

Published
Record updated
View JSON

Summary

Researchers study visual prompt injection (VPI), where instructions embedded in input images are followed by large vision-language models (LVLMs). They propose "goal hijacking via visual prompt injection" (GHVPI), which redirects an LVLM from its original task to an attacker-specified one. Their quantitative analysis reports an attack success rate of 15.8% against GPT-4V, and they find GHVPI success depends on the character recognition and instruction-following capabilities of LVLMs.