Pith. sign in

REVIEW 4 cited by

Multilingual and Multi-Accent Jailbreaking of Audio LLMs

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2504.01094 v1 pith:LINMVPD3 submitted 2025-04-01 cs.SD cs.AIcs.CLcs.CReess.AS

classification cs.SDcs.AIcs.CLcs.CReess.AS
keywords audiomultilingualattackattacksmulti-accentsuccessacousticdataset
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Large Audio Language Models (LALMs) have significantly advanced audio understanding but introduce critical security risks, particularly through audio jailbreaks. While prior work has focused on English-centric attacks, we expose a far more severe vulnerability: adversarial multilingual and multi-accent audio jailbreaks, where linguistic and acoustic variations dramatically amplify attack success. In this paper, we introduce Multi-AudioJail, the first systematic framework to exploit these vulnerabilities through (1) a novel dataset of adversarially perturbed multilingual/multi-accent audio jailbreaking prompts, and (2) a hierarchical evaluation pipeline revealing that how acoustic perturbations (e.g., reverberation, echo, and whisper effects) interacts with cross-lingual phonetics to cause jailbreak success rates (JSRs) to surge by up to +57.25 percentage points (e.g., reverberated Kenyan-accented attack on MERaLiON). Crucially, our work further reveals that multimodal LLMs are inherently more vulnerable than unimodal systems: attackers need only exploit the weakest link (e.g., non-English audio inputs) to compromise the entire model, which we empirically show by multilingual audio-only attacks achieving 3.1x higher success rates than text-only attacks. We plan to release our dataset to spur research into cross-modal defenses, urging the community to address this expanding attack surface in multimodality as LALMs evolve.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Attacker's Noise Can Manipulate Your Audio-based LLM in the Real World

    cs.CR 2025-07 conditional novelty 6.0 of 10

    Adversarial audio noise, optimized with audio augmentations, can trigger and distort the behavior of audio-based LLMs both digitally and when played through the air.

  2. Evaluating Robustness of Large Audio Language Models to Audio Injection: An Empirical Study

    cs.CL 2025-05 conditional novelty 6.0 of 10

    Five leading audio-language models show substantial, scenario-dependent vulnerability to injected audio instructions that can override user requests and sway evaluations.

  3. Universal Acoustic Adversarial Attacks for Flexible Control of Speech-LLMs

    cs.CL 2025-05 conditional novelty 6.0 of 10

    A single learned 3.2-second audio prefix can mute or redirect speech LLMs, and can be trained to selectively mute only targeted genders or languages.

  4. A Red Teaming Roadmap Towards System-Level Safety

    cs.CR 2025-05 conditional novelty 4.0 of 10

    A position paper from Scale AI argues that red teaming research should prioritize product-level safety specifications, realistic attacker models, and system-level monitoring over abstract model-level harm benchmarks.

Pith tools