FORCE: Transferable Visual Jailbreaking Attacks via Feature Over-Reliance CorrEction
Runqi Lin, Alasdair Paren, Suqin Yuan, Muyang Li, Philip H.S. Torr, Adel Bibi, Tongliang Liu
Abstract
The integration of new modalities enhances the capabilities of multimodal large language models (MLLMs) but also introduces additional vulnerabilities. In particular, simple visual jailbreaking attacks can manipulate open-source MLLMs more readily than sophisticated textual attacks. However, these underdeveloped attacks exhibit extremely limited cross-model transferability, failing to reliably identify vulnerabilities in closed-source MLLMs. In this work, we analyse the loss landscape of these jailbreaking attacks and find that the generated attacks tend to reside in highsharpness regions, whose effectiveness is highly sensitive to even minor parameter changes during transfer. To further explain the high-sharpness localisations, we analyse their feature representations in both the intermediate layers and the spectral domain, revealing an improper reliance on narrow layer representations and semantically poor frequency components. Building on this, we propose a Feature Over-Reliance CorrEction (FORCE) method, which guides the attack to explore broader feasible regions across layer features and rescales the influence of frequency features according to their semantic content. By eliminating non-generalizable reliance on both layer and spectral features, our method discovers flattened feasible regions for visual jailbreaking attacks, thereby improving cross-model transferability. Extensive experiments demonstrate that our approach effectively facilitates visual red-teaming evaluations against closedsource MLLMs. Our implementation is released at https: //github.com/tmllab/2026_CVPR_FORCE. 0.0 0.2 0.4 0.6 0.8 1.0 Interpolation Rate 0.0 0.4 0.8 1.2
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c84d575e-3c3f-4d1a-9606-3cbcbcbea1a8Cited by top-tier papers5
- When Safety Collides: Resolving Multi-Category Harmful Conflicts in Text-to-Image Diffusion via Adaptive Safety GuidanceYongli Xiang, Ziming Hong, Zhaoqing Wang, Xiangyu Zhao et al.CVPR 2026 · 14 citations
- Mitigating Mismatch within Reference-based Preference OptimizationSuqin Yuan, Xingrui Yu, Jiyang Zheng, Lei Feng et al.ICLR 2026 · 4 citations
- Mobile-VTON: High-Fidelity On-Device Virtual Try-OnZhenchen Wan, Ce Chen, Runqi Lin, Jiaxin Huang et al.CVPR 2026 · 4 citations
- Dissecting the Safety Circuit: Neuronal Intervention for Transferable Adversarial Attacks on VLMsChunlong Xie, Kangjie Chen, Shangwei Guo, Shudong Zhang et al.ICML 2026
- Select Before Use: On the Importance of Reference Model Selection in Preference AlignmentMuyang Li, Runze Wu, Xiangyu Zhao, Bo Han et al.ACL 2026
Builds on32
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Visual Instruction TuningHaotian Liu, Chunyuan Li, Qingyang Wu, Yong Jae LeeNeurIPS 2023 · 11,349 citations
- Direct Preference Optimization: Your Language Model is Secretly a Reward ModelRafael Rafailov, Archit Sharma, Eric Mitchell, Christopher D. Manning et al.NeurIPS 2023 · 10,924 citations
- InstructBLIP: Towards General-purpose Vision-Language Models with Instruction TuningWenliang Dai, Junnan Li, Dongxu Li, Anthony Meng Huat Tiong et al.NeurIPS 2023 · 4,013 citations
- HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust RefusalMantas Mazeika, Long Phan, Xuwang Yin, Andy Zou et al.ICML 2024 · 1,031 citations
Related papers
- Understanding and Enhancing the Transferability of Jailbreaking AttacksRunqi Lin, Bo Han, Fengwang Li, Tongliang LiuICLR 2025
- MIDAS: Multi-Image Dispersion and Semantic Reconstruction for Jailbreaking MLLMsYilian Liu, Guoshun Nan, Jiuyang Lyu, Zhican Chen et al.ICLR 2026 · 3 citations
- Adversarial Style Optimization: Enhancing VLM Jailbreaks by GRPO-based Stylistic Triggers OptimizationBingjun Luo, Jialin Guo, Yue Yao, Xinpeng DingCVPR 2026
- Distract Large Language Models for Automatic Jailbreak AttackZeguan Xiao, Yan Yang, Guanhua Chen, Yun ChenEMNLP 2024 · 8 citations
- FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual PromptsYichen Gong, Delong Ran, Jinyuan Liu, Conglei Wang et al.AAAI 2025 · 350 citations
