← Back to search
paper llmsec-2026-00129

VisInject: Disruption != Injection -- A Dual-Dimension Evaluation of Universal Adversarial Attacks on Vision-Language Models

Pang Liu, Yingjie Lao

2026-05

Abstract

Universal adversarial attacks on aligned multimodal large language models are increasingly reported with attack success rates in the 60-80% range, suggesting the visual modality is highly vulnerable to imperceptible perturbations as a prompt-injection channel. We argue that this number conflates two distinct events: (i) the model's output was perturbed (Influence), and (ii) the attacker's chosen target concept was actually emitted (Precise Injection). We compose two existing techniques -- Univer

Cite This Resource

@article{llmsec202600129,
  title = {VisInject: Disruption != Injection -- A Dual-Dimension Evaluation of Universal Adversarial Attacks on Vision-Language Models},
  author = {Pang Liu and Yingjie Lao},
  year = {2026},
  url = {https://arxiv.org/abs/2605.01449},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.01449