TempQ-Jail: Query-Constrained Ranking for T2V Jailbreak

Arxiv pdf 2026-09-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Existing text-to-video (T2V) jailbreak methods primarily focus on generating more effective or stealthier attack candidates; however, in real-world guarded T2V systems, video generation and security evaluation incur high target query costs, making it difficult for attackers to exhaustively test a large number of candidates. When the number of candidates far exceeds the available query budget, the effectiveness of an attack depends not only on the existence of valid candidates but also on whether these candidates can be prioritised for access before the budget is exhausted. To this end, we further model the T2V jailbreak as a query-constrained candidate allocation and ranking problem, and propose TempQ-Jail. This method first fuses multiple attack mechanisms through heterogeneous candidate construction to expand the attack coverage of the candidate space; it then estimates the end-to-end attack value of candidates based on Tianmeng Fang is with the School of Computing and Information Systems, Master of IT in Business (MITB), Singapore Management University, Singapore 178903, Singapore. (Email: fangtianmeng@gmail.com). Jiancheng Wang is with the School of Computer Science and Technology, Anhui University, Hefei 230601, China. (Email: e24301271@stu.ahu.edu.cn). Chen Wang is with the Department of Electrical and Computer Engineering, University of Miami, Coral Gables, FL 33146, United States. (Email: chenwang9508@163.com). Liming Wang is with CSG Digital Operations Software Technology (Guangdong) Co., Ltd., Shenzhen 518000, China. (Email: 448171821@qq.com). Wei Wang and Xiaochun Cao are with the School of Cyber Science and Technology, Sun Yat-sen University, Shenzhen Campus, Shenzhen 518107, China. (Email: wangwei29@mail.sysu.edu.cn, caoxiaochun@mail.sysu.edu.cn). Jiayang Liu is with the College of Computing and Data Science, Nanyang Technological University, Singapore 639798, Singapore. (Email: ljyljy957@gmail.com). Corresponding author: Wei Wang. aspects such as security gate passage, dangerous visual generation, preservation of original intent, and temporal validity; finally, through budget-aware candidate ranking, high-value candidates are prioritised at the front of the limited query trajectory. On CogVideoX-5B, based on 70 common viable intents derived from T2VSafetyBench, we conducted a unified comparison with six representative T2V jailbreak methods. The results show that TempQ-Jail achieves TP-ASR@5 and TP-ASR@10 of 48.9% and 65.4%, representing improvements of 4.6 and 4.0 percentage points, respectively, over the strongest baselines under the corresponding budgets, whilst also achieving the highest AUC-TP (0.469) and the lowest AvgQ (6.3). Further analyses of query trajectories, candidate allocation, failure attribution and ablation studies demonstrate that TempQ-Jail is capable of more effectively identifying and prioritising candidates with full attack potential, thereby providing an effective framework for candidate allocation and ranking in T2V red teaming scenarios with query constraints.

Loading executive summary...

LINK COPIED TO CLIPBOARD