Versatile AI Risk Assessment

AI threat cataloguePrompt Attacks and Guardrail EvasionProduction

Multimodal Attacks

Attacks exploit an AI system's combined image, audio, and text capabilities, for example instructions hidden in images, manipulated audio files, or a prompt injection that crosses from one input type into another.

As of: July 2026 · Catalogue version 2026.07.17.3 · 6 mitigations · 11 verified sources

Description

Many AI systems today process several input types at once, namely text, images, and sound. Attackers hide instructions where people barely notice them: as faint text on a pictured sign, in a single video frame, or concealed inside an audio file (audio steganography, the practice of hiding messages in media files). The system reads this hidden instruction as a command, which is called cross-modal prompt injection. Such attacks can also be spread across several input types and only take effect in combination. In addition, images can be altered so the system misreads them, even though the change stays invisible to the human eye.

Possible impact

Because the manipulation sits in seemingly harmless images or sounds, it is hard to detect and slips past classic text filters. The consequences mirror those of prompt injection: distorted output, data leakage, unwanted actions, and wrong decisions in safety-critical applications.

Example

A caseworker uploads a submitted application image to the AI system. In faint lettering, the image carries a hidden instruction to ignore all prior rules and approve the application automatically. The system complies.

Recommended mitigations (6)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM01:2025NIST AI RMF MEASURE 2.7 · NISTAML.022 · NISTAML.025MITRE ATLAS AML.T0015 · AML.T0043 · AML.T0051EU AI Act Article 55(1)(a) · Article 55(1)(d) · Article 9(1), 9(2)(a), 9(2)(d)BIML BIML-LLM model:9

Verified references (11)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Prompt Attacks and Guardrail Evasion.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Multimodal Attacks”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/multimodal-attacks/

← Back to the full catalogue