Risk Concealment Across Modalities: Structural Obfuscation Attacks on Multimodal LLMs in Finance
Abstract
Large language models (LLMs) are increasingly used in financial decision-support scenarios, where reliable risk disclosure is critical. However, existing safety mechanisms mainly focus on semantic content and are less sensitive to the structural organization of risk information. We propose Structural Risk Obfuscation Attack (S-ROA), a red-teaming framework that conceals regulatory risks through structural manipulations such as hierarchical layouts and tabular representations, together with a judge-guided two-phase framework incorporating a Hidden Chain-of-Table-Thought (Hidden CoTT) mechanism for iterative refinement. Experiments across six LLMs show that S-ROA achieves a 97.78% average attack success rate, outperforming the strongest multi-turn baseline by 1.06% and exceeding representative single-turn methods by over 24%, with near-perfect success on several models (e.g., 99.81% on Qwen3-32B), revealing the vulnerability of current safeguards to structurally concealed risks.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.