← Search

Zhijin Ge

3 accepted papers

2026

Sparse Tokens Suffice: Jailbreaking Audio Language Models via Token-Aware Gradient Optimization

ICML 2026poster

Jailbreak attacks on audio language models (ALMs) optimize audio perturbations to elicit unsafe generations, and they typically update the entire waveform densely throughout optimization. In this work, we investigate the necessity of such dense optimization by analyzing the structure of token-aligne…

Cited by 0SourceScholar
2025

Attention! Your Vision Language Model Could Be Maliciously Manipulated

NeurIPS 2025poster

Large Vision-Language Models (VLMs) have achieved remarkable success in understanding complex real-world scenarios and supporting data-driven decision-making processes. However, VLMs exhibit significant vulnerability against adversarial examples, either text or image, which can lead to various adver…

Cited by 0SourcecodeScholar
2023

Boosting Adversarial Transferability by Achieving Flat Local Maxima

NeurIPS 2023poster

Transfer-based attack adopts the adversarial examples generated on the surrogate model to attack various models, making it applicable in the physical world and attracting increasing interest. Recently, various adversarial attacks have emerged to boost adversarial transferability from different persp…