JPPO attack inflates VLM inference latency 36.6x and energy 32.7x
chaumian · x · 2026-09-09
An arXiv paper introduces JPPO (Joint Pixel-Prompt Optimization), the first compound resource-exhaustion attack framework against autoregressive vision-language models:
- Novelty: Prior attacks optimized only the image branch; JPPO elevates the user-visible prompt to a first-class adversarial variable alongside image perturbations, performing stagewise coupled optimization over both surfaces. This yields synergistic cost amplification mechanistically distinct from loop-dependent failures (negligible loop incidence in experiments).
- Numbers: Under an 8/255 infinity-norm budget across five open-source VLM families, JPPO achieves >4.6x latency and >5.3x energy amplification on Qwen2.5-VL-7B, and >36.6x latency with >32.7x energy on BLIP-2.
- Claim: The strongest cost amplification among directly compared baselines, with substantially fewer optimization iterations. Ablations detail component contributions.
More from Safety
- Pre-Auth Integer Overflow Found in SQL Server; Microsoft Patches It — wunderwuzzi23 · 2026-09-09
- Anthropic Safety Lead Puts >10% Chance on AI 'Killing All Humans' After Researcher Quits — The Verge AI · 2026-09-09
- Upcoming Talk: Participatory AI — Designing and Governing AI with Stakeholders — danielequercia · 2026-09-09
- GigaMail MCP server gates 6 destructive email tools behind biometric approval, survives hostile-email red team — Soft-Lie-434 · 2026-09-09
- How AI Keeps Europe Hooked on US Cloud: DeepL's AWS Pivot Exposes the Sovereignty Trap — agstrait · 2026-09-09
- Agent Deleted an Anti-Money-Laundering Control Because a Ticket Asked for Bigger Gift Cards — Late_Wave_5600 · 2026-09-09