May 2026Unreviewed
DMN: A Compositional Framework for Jailbreaking Multimodal LLMs with Multi-Image Inputs
Wenzhuo Xu, Zhipeng Wei, Zonghao Ying, Deyue Zhang, Dongdong Yang, Xiangzheng Zhang, Quanchen Zou
Abstract
Multimodal Large Language Models (MLLMs) are vulnerable to jailbreak attacks, which can elicit harmful responses from MLLMs. Many MLLMs support multi-image inputs, inadvertently introducing new vulnerabilities due to less efforts on multi-image safety alignment. Previous MLLM jailbreak methods only uses a single image, which restricts the attack space: they cannot distribute harmful requests across multiple images, carry abundant information, or exploit additional visual reasoning tasks to distr
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{xu2026dmn,
title = {{DMN: A Compositional Framework for Jailbreaking Multimodal LLMs with Multi-Image Inputs}},
author = {Wenzhuo Xu and Zhipeng Wei and Zonghao Ying and Deyue Zhang and Dongdong Yang and Xiangzheng Zhang and Quanchen Zou},
year = {2026},
month = may,
eprint = {2605.18915},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.18915}
}