[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-attaching-any-image-makes-ai-chatbots-more-likely-to-refuse":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},8166,"attaching-any-image-makes-ai-chatbots-more-likely-to-refuse","Attaching Any Image Makes AI Chatbots More Likely to Refuse","A study finds attaching any image, even a blank one, raises AI refusal on borderline prompts by up to 51 points, regardless of content.","Attach an image to an AI chatbot prompt, even a blank square that has nothing to do with your question, and the model gets noticeably more cautious, according to a new study.\n\nResearchers tested four hosted vision-language models by pairing identical prompts with a blank, unreadable, or otherwise irrelevant image, byte-identical across every trial. For genuinely neutral requests, refusal rates barely moved, shifting by 2 percentage points or less on three of the four models. But for borderline-benign prompts touching privacy, self-harm, violence, or illegal activity, refusal rates jumped by 23 to 51 percentage points based on image attachment alone. The effect changed with the canvas's color and pixel count, flipped direction across different model checkpoints, and persisted even when the prompt explicitly told the model to ignore the image. On one model, simply asserting that an image existed, with nothing actually attached, was enough to trigger it.\n\nThis matters because the same trick does work against genuinely harmful requests, lowering attack success rates on a matched harmful-prompt set, so the underlying instinct is not baseless. The problem is the cost isn't tied to that benefit: the model with the weakest defenses in the study, completing just 2% of plain harmful requests, still charged the full benign penalty, and as models got better at refusing harmful requests, the benign cost didn't fall in step.\n\nIn short, \"an image is attached\" is being used as a proxy for risk, and it's a proxy that shifts with pixel count and model version rather than anything about what's actually being asked.","[\"ai safety\",\"vision-language models\",\"llm alignment\",\"ai research\"]","2026-09-28T04:00:00.000Z","2026-09-28T12:09:34.387Z","2026-09-28T12:09:41.692Z","published",null,[],"ai",[26,27,28,29],"ai safety","vision-language models","llm alignment","ai research",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.26174",0,{"sections":36},[37,40,44,49,54,59,63,68,73,78,83,88,92,97],{"name":38,"slug":24,"count":39,"latest_published_at":18},"AI",4798,{"name":41,"slug":42,"count":43,"latest_published_at":18},"Security","security",762,{"name":45,"slug":46,"count":47,"latest_published_at":48},"Policy","policy",399,"2026-09-27T18:39:02.000Z",{"name":50,"slug":51,"count":52,"latest_published_at":53},"Deals","deals",261,"2026-09-27T15:30:35.000Z",{"name":55,"slug":56,"count":57,"latest_published_at":58},"Hardware","hardware",188,"2026-09-27T20:46:36.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":18},"Science","science",151,{"name":64,"slug":65,"count":66,"latest_published_at":67},"Consumer Tech","consumer-tech",135,"2026-09-26T14:30:00.000Z",{"name":69,"slug":70,"count":71,"latest_published_at":72},"Software","software",91,"2026-09-25T20:55:00.000Z",{"name":74,"slug":75,"count":76,"latest_published_at":77},"Dev Tools","dev-tools",84,"2026-09-26T04:20:58.000Z",{"name":79,"slug":80,"count":81,"latest_published_at":82},"Startups","startups",76,"2026-09-25T18:33:59.000Z",{"name":84,"slug":85,"count":86,"latest_published_at":87},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":89,"slug":90,"count":86,"latest_published_at":91},"General","general","2026-09-26T17:02:42.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Reviews","reviews",30,"2026-09-24T20:07:31.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]