Analysis · curated 11 Sep 2026
Multimodal Attacks: When Images Carry Instructions
First reported securing.ai
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Multimodal prompt injection exploits the gap that production safety controls were built around textual prompts, while vision encoders let painted-on instructions enter the same context the model obeys.
An explainer on multimodal attacks describes how non-text modalities, chiefly images, can carry instructions that bypass text-based safety controls in vision-language models. It synthesizes several published techniques including FigStep (82.5% average success on open-source LVLMs by typesetting harmful instructions into images), MM-SafetyBench, GHVPI against GPT-4V, CrossMPI adversarial perturbations, and steganographic 'Invisible Injections'.