Chain-of-Jailbreak Attack for Image Generation Models via Step by Step Editing

1Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Text-based image generation models, such as Stable Diffusion and DALL-E 3, hold significant potential in content creation and publishing workflows, making them the focus in recent years. Despite their remarkable capability to generate diverse and vivid images, considerable efforts are being made to prevent the generation of harmful content, such as abusive, violent, or pornographic material. To assess the safety of existing models, we introduce a novel jailbreaking method called Chain-of-Jailbreak (CoJ) attack, which compromises image generation models through a step-by-step editing process. Specifically, for malicious queries that cannot bypass the safeguards with a single prompt, we intentionally decompose the query into multiple sub-queries. The image generation models are then prompted to generate and iteratively edit images based on these sub-queries. To evaluate the effectiveness of our CoJ attack method, we constructed a comprehensive dataset, CoJ-Bench, including nine safety scenarios, three types of editing operations, and three editing elements. Experiments on four widely-used image generation services provided by GPT-4V, GPT-4o, Gemini 1.5 and Gemini 1.5 Pro, demonstrate that our CoJ attack method can successfully bypass the safeguards of models for over 60% cases, which significantly outperforms other jailbreaking methods (i.e., 14%). Further, to enhance these models' safety against our CoJ attack method, we also propose an effective prompting-based method, Think-Twice Prompting, that can successfully defend over 95% of CoJ attack. Our dataset is publicly available.

Cite

CITATION STYLE

APA

Wang, W., Gao, K., Yuan, Y., Huang, J. T., Liu, Q., Wang, S., … Tu, Z. (2025). Chain-of-Jailbreak Attack for Image Generation Models via Step by Step Editing. In Proceedings of the Annual Meeting of the Association for Computational Linguistics (pp. 10940–10957). Association for Computational Linguistics (ACL). https://doi.org/10.18653/v1/2025.findings-acl.571

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free