Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation
语义路由器:通过单一对抗扰动劫持多模态大语言模型的可行性研究
机构 * The Chinese University of Hong Kong, Shenzhen, China(香港中文大学(深圳)) ; School of Data Science, School of Artificial Intelligence, The Chinese University of Hong Kong, Shenzhen, China(数据科学学院、人工智能学院、香港中文大学(深圳))
专题命中 幻觉与鲁棒性 :multimodal large language model(abstract);MLLM(abstract_cn);分类 cs.CV、cs.AI
AI总结 提出语义感知通用扰动(SAUP),作为语义路由器同时劫持多个无状态决策,通过理论分析和SORT优化策略实现,在Qwen上对五个目标达到66%攻击成功率。
Comments Accepted to ICML 2026