Risks of Multimodal AI Systems
Visual prompt injection, privacy, context leakage and tool manipulation when a multimodal system can observe and act.
Links containing ?t= open the video at a specific second.
Video summary
The ideas to retain
1. Visual prompt injection
Prompt injection is an attack in which an attacker places instructions for the model inside content that the model processes as data.
2. System leakage and tool manipulation
When a multimodal system has access to tools—API calls, database access, the ability to send messages—visual prompt injection can be used not only to alter the system's response but also…
3. Privacy: images, documents and metadata
Multimodal systems that process images and documents have access to categories of personal information that text-only systems generally do not handle, and the risk comes not only from…


