[COLM 2025] JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model
See the code
JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language ModelYi Nian*, Shenzhe Zhu*, Yuehan Qin, Shawn Li, Ziyi Wang, Chaowei Xiao, Yue Zhao†
(*Contribute equally, †Corresponding author)
❗️Content Warning: This repo contains examples of harmful language.
./data.conda env create -f environment.yml
conda activate llava
demo.ipynbMultimodal large language models (MLLMs) excel in vision-language tasks but also pose significant risks of generating harmful content, particularly through jailbreak attacks. Jailbreak attacks refer to intentional manipulations that bypass safety mechanisms in models, leading to the generation of inappropriate or unsafe content. Detecting such attacks is critical to ensuring the responsible deployment of MLLMs. Existing jailbreak detection methods face three primary challenges: (1) Many rely on model hidden states or gradients, limiting their applicability to white-box models, where the internal workings of the model are accessible; (2) They involve high computational overhead from uncertainty-based analysis, which limits real-time detection, and (3) They require fully labeled harmful datasets, which are often scarce in real-world settings. To address these issues, we introduce a test-time adaptive framework called JAILDAM . Our method leverages a memory-based approach guided by policy-driven unsafe knowledge representations, eliminating the need for explicit exposure to harmful data. By dynamically updating unsafe knowledge during test-time, our framework improves generalization to unseen jailbreak strategies while maintaining efficiency. Experiments on multiple VLM jailbreak benchmarks demonstrate that JAILDAM delivers state-of-the-art performance in harmful content detection, improving both accuracy and speed.
JAILDAM overview. (A) Training: We encode safe text and images with CLIP, computing attention scores against a policy-driven unsafe memory bank. An autoencoder learns to reconstruct these features, linking benign inputs to unsafe concepts without explicit harmful data. (B) Inference: For each new input, we compute attention scores and measure the autoencoder’s reconstruction error; high error indicates potential harm. If similarity to the memory bank is low, JAILDAM updates the least-used concept with a residual representation, adapting to new attacks over time.
Based on our attack detector, JAILDAM, we construct an end-to-end attack defense framework, denoted as JAILDAM-D (see Figure 3). This framework implements a two-stage defense approach:
We use following amazing datasets/benchmarks as data source:
This dataset includes offensive content that some may find disturbing. It is intended solely for educational and research use.
@article{nian2025jaildam,
title={JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model},
author={Nian, Yi and Zhu, Shenzhe and Qin, Yuehan and Li, Li and Wang, Ziyi and Xiao, Chaowei and Zhao, Yue},
journal={arXiv preprint arXiv:2504.03770},
year={2025}
}
Python
67.5%
Jupyter Notebook
32.5%
[COLM 2025] JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model
See the code
JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language ModelYi Nian*, Shenzhe Zhu*, Yuehan Qin, Shawn Li, Ziyi Wang, Chaowei Xiao, Yue Zhao†
(*Contribute equally, †Corresponding author)
❗️Content Warning: This repo contains examples of harmful language.
./data.conda env create -f environment.yml
conda activate llava
demo.ipynbMultimodal large language models (MLLMs) excel in vision-language tasks but also pose significant risks of generating harmful content, particularly through jailbreak attacks. Jailbreak attacks refer to intentional manipulations that bypass safety mechanisms in models, leading to the generation of inappropriate or unsafe content. Detecting such attacks is critical to ensuring the responsible deployment of MLLMs. Existing jailbreak detection methods face three primary challenges: (1) Many rely on model hidden states or gradients, limiting their applicability to white-box models, where the internal workings of the model are accessible; (2) They involve high computational overhead from uncertainty-based analysis, which limits real-time detection, and (3) They require fully labeled harmful datasets, which are often scarce in real-world settings. To address these issues, we introduce a test-time adaptive framework called JAILDAM . Our method leverages a memory-based approach guided by policy-driven unsafe knowledge representations, eliminating the need for explicit exposure to harmful data. By dynamically updating unsafe knowledge during test-time, our framework improves generalization to unseen jailbreak strategies while maintaining efficiency. Experiments on multiple VLM jailbreak benchmarks demonstrate that JAILDAM delivers state-of-the-art performance in harmful content detection, improving both accuracy and speed.
JAILDAM overview. (A) Training: We encode safe text and images with CLIP, computing attention scores against a policy-driven unsafe memory bank. An autoencoder learns to reconstruct these features, linking benign inputs to unsafe concepts without explicit harmful data. (B) Inference: For each new input, we compute attention scores and measure the autoencoder’s reconstruction error; high error indicates potential harm. If similarity to the memory bank is low, JAILDAM updates the least-used concept with a residual representation, adapting to new attacks over time.
Based on our attack detector, JAILDAM, we construct an end-to-end attack defense framework, denoted as JAILDAM-D (see Figure 3). This framework implements a two-stage defense approach:
We use following amazing datasets/benchmarks as data source:
This dataset includes offensive content that some may find disturbing. It is intended solely for educational and research use.
@article{nian2025jaildam,
title={JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model},
author={Nian, Yi and Zhu, Shenzhe and Qin, Yuehan and Li, Li and Wang, Ziyi and Xiao, Chaowei and Zhao, Yue},
journal={arXiv preprint arXiv:2504.03770},
year={2025}
}
Python
67.5%
Jupyter Notebook
32.5%