July 2026Unreviewed
TYPO: Instruction-Dense Visual Jailbreaks against Commercial Closed-Source Image-Generation Models
Meng Xie, Li Zeng, Hangtao Zhang, Xianlong Wang, Ziqi Zhou, Pengpeng Qiao, Zhetao Li
Abstract
Recent commercial image-generation models can generate high-quality images with readable text (e.g., posters, infographics, and manuals), attracting considerable attention. Yet we first show that this same capability also introduces a previously unreported safety vulnerability: these systems may refuse to generate harmful text directly, yet permit the same content when rendered as text within generated images, i.e., safety alignment does not reliably transfer from textual outputs to text embedde
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{xie2026typo,
title = {{TYPO: Instruction-Dense Visual Jailbreaks against Commercial Closed-Source Image-Generation Models}},
author = {Meng Xie and Li Zeng and Hangtao Zhang and Xianlong Wang and Ziqi Zhou and Pengpeng Qiao and Zhetao Li},
year = {2026},
month = jul,
eprint = {2607.24897},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.24897}
}