Understanding and Defending VLM Jailbreaks via Jailbreak-Related Representation Shift
arXiv cs.CV / 3/19/2026
💬 OpinionIdeas & Deep AnalysisModels & Research
Key Points
- VLM safety alignment weakens when the visual modality is added, with image prompts increasing jailbreak success even for harmful intents.
- Benign and harmful inputs are separable in the model's representation space, and jailbreak samples form a distinct internal state separate from refusals.
- The authors define a jailbreak direction and a jailbreak-related shift (JRS) as the component of the image-induced representation shift along that direction, unifying diverse jailbreak behaviors.
- They propose a defense method, JRS-Rem, that removes the jailbreak-related shift at inference to improve safety while preserving performance on benign tasks.
Related Articles

Hey dev.to community – sharing my journey with Prompt Builder, Insta Posts, and practical SEO
Dev.to

How to Build Passive Income with AI in 2026: A Developer's Practical Guide
Dev.to

The Research That Doesn't Exist
Dev.to

Jeff Bezos reportedly wants $100 billion to buy and transform old manufacturing firms with AI
TechCrunch

Krish Naik: AI Learning Path For 2026- Data Science, Generative and Agentic AI Roadmap
Dev.to