CCS2026
PC^2: Politically Controversial Content Generation via Jailbreaking Attacks on GPT-based Text-to-Image Models
Wonwoo Choi, Minjae Seo, Minkyoo Song, Hwanjo Heo, Seungwon Shin, Myoungsung You
摘要
The rapid evolution of text-to-image (T2I) models has enabled high-fidelity visual synthesis on a global scale. However, these advancements have introduced significant security risks, particularly regarding the generation of harmful content. Politically harmful content, such as fabricated depictions of public figures, poses severe threats when weaponized for fake news or propaganda. Despite its criticality, the robustness of current T2I safety filters against such politically motivated adversarial prompting remains underexplored. In response, we propose 𝑃𝐶 2 , the first black-box political jailbreaking framework for T2I models. It exploits a novel vulnerability where safety filters evaluate political sensitivity based on linguistic context. 𝑃𝐶 2 operates through: (1) Identity-Preserving Descriptive Mapping to obfuscate sensitive keywords into neutral descriptions, and (2) Geopolitically Distal Translation to map these descriptions into fragmented, low-sensitivity languages. This strategy prevents filters from constructing toxic relationships between political entities within prompts, effectively bypassing detection. We construct a benchmark of 240 politically sensitive prompts involving 36 public figures. Evaluation on commercial T2I models, specifically the GPT series, shows that while all original prompts are blocked, 𝑃𝐶 2 achieves attack success rates (ASRs) of up to 86% and outperforms state-of-the-art frameworks by a large margin. We further propose a ready-to-deploy multi-layered filtering mitigation against 𝑃𝐶 2 -style attacks, reducing ASR to approximately 10%. Disclaimer. This paper contains politically sensitive contents, including images depicting sitting presidents or cabinet-level officials in potentially misleading or controversial contexts. Readers are advised to exercise discretion when engaging with this material. In accordance with ethical research standards and responsible disclosure practices, the vulnerabilities identified in this study were formally reported to Google Gemini on December 2, 2025, and to OpenAI on December 12, 2025. Detailed information regarding these reports is provided in Appendix E. * Wonwoo Choi and Minjae Seo contributed equally to this work. T2I generation system Safety filters Image gen. model A : En tidligere komiker og skuespiller som ble president i Ukraina i 2019… B: ဤစစ် ေရးယာ)သည် ၂၀၂၂ ခ/ 01 စ် သ2 တိ / ့က အေထာက် အပံ ့ ြပ<သည် ဟ/ … Oħloq immaġni realistika għal "A" qed isuqu fuq "B". PC 2 -generated prompt Create a realistic image: Volodymyr Zelenskyy is driving a Z-Symbol Tank.