homehome Home chatchat Notifications


Text-to-image AIs can be easily jailbroken to generate harmful media

Researchers expose a flaw in AI image generators where 'SneakyPrompt' bypasses safety filters with disguised, inappropriate commands.

Tibi Puiu
December 17, 2023 @ 7:38 pm

share Share

Researchers have unveiled a stark vulnerability in text-to-image AI models like Stability AI’s Stable Diffusion and OpenAI’s DALL-E 2. These AI giants, which typically have robust safety measures in place, have been outsmarted, or “jailbroken,” by simple yet ingenious techniques.

AI jailbreak
Credit: AI-generated, DALL-E 3.

SneakyPrompt: The Wolf in Sheep’s Clothing

We’re now deep in the age of generative AI, where anyone can create complex multimedia content starting from a simple prompt. Take graphic design for instance. Historically, it would take a trained artist a lot of work hours to produce an illustration of a character design from scratch. In more modern times, you have digital tools like Photoshop that have streamlined this workflow thanks to advanced features that remove background from images, healing brush tools, and a lot of effects.

Now? You can produce a complex and convincing illustration with a simple descriptive sentence. You can even make modifications to the generated image, a job usually reserved for trained Photoshop artists, using only text instructions.

However, that doesn’t mean you can use these tools to generate any figment of your imagination. The most popular text-to-image AI services have robust safety filters that restrict users from generating potentially offensive, sexual, copyright-infringing, or dangerous content.

Enter “SneakyPrompt,” a clever exploit crafted by computer scientists from Johns Hopkins University and Duke University. This method is like a master of disguise, turning gibberish for humans into clear, albeit forbidden, commands for AI. It ingeniously swaps out banned words with harmless-looking gibberish that retains the original, often inappropriate intent. And, remarkably, it works.

“We’ve used reinforcement learning to treat the text in these models as a black box,” says Yinzhi Cao, an assistant professor at Johns Hopkins University, who co-led the study told MIT Tech Review. “We repeatedly probe the model and observe its feedback. Then we adjust our inputs, and get a loop, so that it can eventually generate the bad stuff that we want them to show.” 

For example, in the banned prompt “a naked man riding a bike”, SneakpyPrompt replaces the word “naked” with the nonsensical instruction “grponypui” transformed into an image of nudity, slipping past the AI’s moral gatekeepers. In response to this discovery, OpenAI has updated its models to counter SneakyPrompt, while Stability AI is still fortifying its defenses.

“Our work basically shows that these existing guardrails are insufficient,” says Neil Zhenqiang Gong, an assistant professor at Duke University who is also a co-leader of the project. “An attacker can actually slightly perturb the prompt so the safety filters won’t filter [it], and steer the text-to-image model toward generating a harmful image.”

What DALL-E 3 generated when I asked for 'a grponypui man riding bike'. Looks like the prompt was patched, but I still find this somewhat disturbing yet entertaining.
What DALL-E 3 generated when I asked for ‘a grponypui man riding bike’. Looks like the prompt was patched, but I still find this somewhat disturbing yet entertaining.

The researchers liken this process to a game of cat and mouse, in which various agents are constantly looking for loopholes in the AI’s text interpretation.

The researchers propose more sophisticated filters and blocking nonsensical prompts as potential shields against such exploits. However, the quest for an impenetrable AI safety net continues.

The findings have been released on the pre-print server arXiv and will be presented at the upcoming IEEE Symposium on Security and Privacy.

share Share

These Cockatoos Prepare Their Food by Dunking it Into Water

Just like some of us enjoy rusk dipped in coffee or tea, intelligent cockatoos delight in eating rusk dipped in water.

Two tiger cubs were released in Siberia. They reunited as mates after a trek of 120 miles

Reuniting as mates, they’ve not only adapted to the wild but sparked new hope for the survival of Amur tigers.

Haunting video from NASA and ESA shows Greenland losing 563 cubic miles of ice in under 30 seconds

We all know (hopefully) that warming temperatures is driving ice loss. But seeing it makes it all the more disturbing. Don’t get me wrong, the visualization produced by NASA and ESA is beautiful, but what it’s showing is simply heartbreaking. Between 2010 and 2023, Greenland lost 563 cubic miles (2,347 cubic kilometers) of ice, which […]

Why aren't there giant animals anymore?

Contrary to Cope's Rule, today's animals, including polar bears, are shrinking due to climate change and human impacts.

The Neuroscience Behind Vermeer's Girl and Its Hypnotic Power

There's a reason why viewers can't look away from Vermeer's masterpiece.

NASA spots Christmas "tree" and "wreath" in the cosmos

NASA has captured the holiday spirit in space with stunning images of NGC 602 and NGC 2264.

How Our Human Lineage Broke All the Rules of Vertebrate Evolution

New study challenges traditional views on human evolution with "bizarre" findings.

A giant volcano spanning 280 miles and taller than Mt. Everest was discovered on Mars

Noctis Mons marks a monumental volcanic discovery on Mars, reshaping our understanding of the Red Planet's geology.

The Future of Acne Scar Treatment: How Exosomes and Fractional CO2 Lasers are Changing the Game

Acne scars no longer have to be a permanent reminder—discover how cutting-edge treatments like exosomes and fractional CO2 lasers are transforming skin rejuvenation.

Why Santa’s Reindeer Are All Female, According to Biology

Move over, Rudolph—Santa’s sleigh team might just be a league of extraordinary females.