TensorX
返回文献探索

Paper · arXiv 2402.13220

How Easy is It to Fool Your Multimodal LLMs? An Empirical Analysis on Deceptive Prompts

Yusu Qian, Haotian Zhang, Yinfei Yang, Zhe Gan

14 upvotesFebruary 20, 2024arXiv 预印本
AI 摘要

MAD-Bench is a benchmark designed to evaluate the susceptibility of Multimodal Large Language Models (MLLMs) to deceptive prompts, with GPT-4V performing significantly better than other models but still facing limitations.

Multimodal Large Language Models (MLLMs)MAD-BenchGPT-4VGemini-ProLLaVA-1.5CogVLMLRV-InstructionLLaVA-RLHFhallucinated responsesdeceptive prompts

Abstract

The remarkable advancements in Multimodal Large Language Models (MLLMs) have not rendered them immune to challenges, particularly in the context of handling deceptive information in prompts, thus producing hallucinated responses under such conditions. To quantitatively assess this vulnerability, we present MAD-Bench, a carefully curated benchmark that contains 850 test samples divided into 6 categories, such as non-existent objects, count of objects, spatial relationship, and visual confusion. We provide a comprehensive analysis of popular MLLMs, ranging from GPT-4V, Gemini-Pro, to open-sourced models, such as LLaVA-1.5 and CogVLM. Empirically, we observe significant performance gaps between GPT-4V and other models; and previous robust instruction-tuned models, such as LRV-Instruction and LLaVA-RLHF, are not effective on this new benchmark. While GPT-4V achieves 75.02% accuracy on MAD-Bench, the accuracy of any other model in our experiments ranges from 5% to 35%. We further propose a remedy that adds an additional paragraph to the deceptive prompts to encourage models to think twice before answering the question. Surprisingly, this simple method can even double the accuracy; however, the absolute numbers are still too low to be satisfactory. We hope MAD-Bench can serve as a valuable benchmark to stimulate further research to enhance models' resilience against deceptive prompts.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号