ReCast is a plug‑in framework that protects private inputs for fixed‑interface multimodal reasoning by locally converting them into a shared textual evidence‑query record, rewriting entities and topics with a distilled model, and mapping numerical values through an invertible, role‑aware map. A reconstruction agent then generates the required media from this protected record, allowing a remote solver to return a program whose operands are restored locally before execution. On 4,000 held‑out ChartQA and NMSQA examples, ReCast achieves 75.10% accuracy, retaining 92.43% of the unprotected remote accuracy, and flags source‑content leakage in 7.95% of solver‑bound requests, outperforming all evaluated local baselines.
By Bingchen Pei, Lichong Chen, Bingxi Zhao, Ziang Wu, Sirui Wang, Min Zhang, Yanhao Chen, Qingxu Liu, Qiang Gao, Chang-Tien Lu, Bo Gao
arXiv:2606. 24623v1 Announce Type: cross Abstract: Retrieval-Augmented Generation enhances large language models by incorporating external knowledge, but deploying it in sensitive scenarios risks privacy leakage via malicious prompts.
By Yuanhe Zhao, Tianyu Zhang, Huafei Xing, Derek F. Wong, Jianbin Li, Tao Fang
Multimodal agents for visual question answering increasingly operate as multi-step trajectories that interleave perception, retrieval, and reasoning, yet evaluation still largely reduces to final-answer accuracy. This aggregate signal cannot tell whether a correct answer was reached through grounded evidence, language priors, or accidental error cancellation.
arXiv:2607. 28374v1 Announce Type: new Abstract: Multimodal agents for visual question answering increasingly operate as multi-step trajectories that interleave perception, retrieval, and reasoning, yet evaluation still largely reduces to final-answer accuracy.
By Enjun Du, Hange Zhou, Chenxu Du, Siyi Liu, Zirong Chen, Ziyu Zheng, Yongqi Zhang
arXiv:2610. 01871v1 Announce Type: cross Abstract: Multimodal Retrieval-Augmented Generation (MRAG) has emerged as a reliable and cost-effective technique of grounding the generative capabilities of Multimodal Large Language Models (MLLMs) into relevant, up-to-date, external knowledge.
By Maria Carmen Jica, Ali Satvaty, Suzan Verberne, Fatih Turkmen
arXiv:2606. 04067v1 Announce Type: cross Abstract: As LLMs become increasingly woven into everyday workflows, user queries sent to cloud hosted LLMs routinely mix task-essential content with task non-essential sensitive disclosures, yet type based PII redaction is context agnostic and may raise two issues: over disclosing untyped sensitive context and over removing answer bearing spans.
By Xinyue Huang, Xiaochun Cao, Wenyuan Yang
arXiv:2607.28225v2 Announce Type: replace
Abstract: Agentic vision-language models (VLMs), which interleave textual reasoning with explicit tool calls such as cropping and code-based image manipulati...
By Haoqing Wang, Xingrun Xing, Ziheng Li, Jianyuan Guo, Yehui Tang
arXiv:2608. 11691v1 Announce Type: new Abstract: Reinforcement-learning (RL) post-training equips multimodal large reasoning models (MLRMs) with exploratory chains of thought (CoT), substantially improving visual reasoning.
By Xinhao Zhong, Yuxia Qiao, Junhao Li, Hao Fang, Yi Sun, Bin Chen
arXiv:2606. 18996v1 Announce Type: cross Abstract: Agents are increasingly deployed in document-intensive workflows where sensitive private information is not an edge case but a routine input, e.
By Moon Ye-Bin, Nam Hyeon-Woo, Baek Seong-Eun, Yejin Yeo, Tae-Hyun Oh
ReFrame is a training‑free framework that enhances safety alignment for multimodal large language models at test time. It uses two lightweight agents: one generates risk and utility evidence, and the other rewrites prompts and routes images to create a safe proxy before invoking the deployed MLLM. Experiments show that ReFrame improves jailbreak defense, safety awareness, and reduces over‑sensitivity while maintaining multimodal utility.
By Wenzheng Jiang, Xuankun Rong, Yuanzhao Zhai, Dawei Feng, Huaimin Wang
UnifiedAttack introduces a benchmark for testing the safety of large multimodal models (LMMs) in tasks that combine text and image to produce harmful content. The benchmark focuses on the additional harm that arises from cross‑modal synergy and includes filtered multimodal samples and synthesized disinformation queries. A synergistic hijacking framework—comprising In‑Context Reskinning (ICR) and Cognitive Planning Injection (CPI)—is proposed to expose vulnerabilities, and extensive evaluations show that UnifiedAttack consistently bypasses current alignment defenses in state‑of‑the‑art architectures.
By Bingjun Luo, Jialin Guo, Tony Wang, Siqi Li
arXiv:2607. 16716v1 Announce Type: new Abstract: Large language models and LLM-based agents are widely used as personal chat assistants, enterprise copilots, and autonomous workflow agents.
By Mihir Shriniwas Arya