🤖 AI Summary
This work addresses the scarcity of resources for detecting jailbreak attacks against vision-language models (VLMs) in the financial domain, where the integration of textual and visual modalities expands the attack surface. To bridge this gap, we introduce FENCE, the first bilingual (Chinese–English), finance-oriented multimodal jailbreak detection dataset. FENCE comprises adversarial samples generated from real-world financial image–text pairs, explicitly designed to contain harmful content and enable joint image–text threat modeling. Baseline detectors trained on FENCE achieve 99% accuracy on in-distribution data and demonstrate strong generalization on external benchmarks, underscoring the dataset’s effectiveness and practical utility in enhancing the security of financial AI systems.
📝 Abstract
Jailbreaking poses a significant risk to the deployment of Large Language Models (LLMs) and Vision Language Models (VLMs). VLMs are particularly vulnerable because they process both text and images, creating broader attack surfaces. However, available resources for jailbreak detection are scarce, particularly in finance. To address this gap, we present FENCE, a bilingual (Korean-English) multimodal dataset for training and evaluating jailbreak detectors in financial applications. FENCE emphasizes domain realism through finance-relevant queries paired with image-grounded threats. Experiments with commercial and open-source VLMs reveal consistent vulnerabilities, with GPT-4o showing measurable attack success rates and open-source models displaying greater exposure. A baseline detector trained on FENCE achieves 99 percent in-distribution accuracy and maintains strong performance on external benchmarks, underscoring the dataset's robustness for training reliable detection models. FENCE provides a focused resource for advancing multimodal jailbreak detection in finance and for supporting safer, more reliable AI systems in sensitive domains. Warning: This paper includes example data that may be offensive.