This investigation reveals a novel exploit derived from PNG image file formats, specifically their alpha transparency layer, and its potential to fool multiple AI vision systems. Our method uses this alpha layer as a clandestine channel invisible to human observers but fully actionable by AI image processors. The scope tested for the vulnerability spans representative vision systems from Apple, Microsoft, Google, Salesforce, Nvidia, and Facebook, highlighting the attack's potential breadth. This vulnerability challenges the security protocols of existing and fielded vision systems, from medical imaging to autonomous driving technologies. Our experiments demonstrate that the affected systems, which rely on convolutional neural networks or the latest multimodal language models, cannot quickly mitigate these vulnerabilities through simple patches or updates. Instead, they require retraining and architectural changes, indicating a persistent hole in multimodal technologies without some future adversarial hardening against such vision-language exploits.
翻译:本研究揭示了一种源自PNG图像文件格式的新型攻击手段,特别是其Alpha透明度通道,该通道可被用于欺骗多种AI视觉系统。我们的方法利用这一Alpha通道作为隐秘载体,使其对人类观察者不可见,但对AI图像处理器完全可操作。针对该漏洞的测试范围涵盖了苹果、微软、谷歌、Salesforce、英伟达和脸谱等公司的代表性视觉系统,凸显了攻击潜在的广泛性。这一漏洞对现有及已部署的视觉系统(从医学影像到自动驾驶技术)的安全协议构成了挑战。实验表明,受影响的系统(无论是依赖卷积神经网络还是最新多模态语言模型)无法通过简单的补丁或更新快速修复这些漏洞,而需要通过重新训练和架构调整来解决。这表明,若不针对此类视觉-语言攻击进行未来的对抗性加固,多模态技术中将长期存在这一安全漏洞。