Back to papers
March 19, 2026cs.LGAdvanced

On Optimizing Multimodal Jailbreaks for Spoken Language Models

AI-Generated Summary

This paper demonstrates that Spoken Language Models (which process both speech and text) can be effectively attacked by simultaneously manipulating both audio and text inputs together, rather than just one modality alone. The researchers developed JAMA, a technique that optimizes adversarial perturbations across both modalities at the same time, and showed it achieves 1.5 to 10 times higher attack success rates than previous single-modality attacks. The findings highlight that protecting these AI systems requires considering both input types together, not separately.

Difficulty
Advanced
Categories

cs.LG

AI Tags
adversarial attacksjailbreakingmultimodal learningspoken language modelsgradient-based optimizationAI safetyaudio processing