Analysis · curated 11 Sep 2026

Multimodal Attacks: When Images Carry Instructions

Coverage timeline

8 Aug 2022securing.ai

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Multimodal prompt injection exploits the gap that production safety controls were built around textual prompts, while vision encoders let painted-on instructions enter the same context the model obeys.

An explainer on multimodal attacks describes how non-text modalities, chiefly images, can carry instructions that bypass text-based safety controls in vision-language models. It synthesizes several published techniques including FigStep (82.5% average success on open-source LVLMs by typesetting harmful instructions into images), MM-SafetyBench, GHVPI against GPT-4V, CrossMPI adversarial perturbations, and steganographic 'Invisible Injections'.