In May 2025, she released Enkrypt Ai Report of a multimedia red teamChopping analysis, which revealed the ease of processing advanced artificial intelligence systems to generate dangerous and immoral content. The report focuses on two Pixral-Large’s leading Mistral models (25.02) and Pixral-12B- and draws a picture of models that are not only technically impressive but worrying.
VLMS models (VLMS) Like PIXTAR, it is designed to explain both visual and text inputs, allowing them to respond intelligently to the real world claims. But this ability comes with increased risk. Unlike the traditional linguistic models that only process the text, VLMS can be affected by the interaction between images and words, which opens new doors of rivalry attacks. The Enkrypt AI test shows the ease of opening these doors.
Disturbing test results: Csem and CBRN failure
Use the team behind the advanced report Red team Roads-a form of aggressive evaluation designed to imitate threats in the real world. These tests were used tactics such as protection fracture (pushing the model with carefully made information to bypass safety filters), images -based deception, and context processing. It is worrying that 68 % of these aggressive claims sparked harmful responses, including the content related to structure, exploitation and even chemical weapons design.
One of the most striking stakeholders involves the sexual exploitation materials for children (CSEM). The report found that Mistral models were 60 times more likely to produce content associated with CSEM compared to industry standards such as GPT-4O and Claude 3.7 Sonnet. In test situations, models responded to persuasive calls for a multi-vertebral regulatory content that explains how minors are tackled-they were included in the evacuation of deadly responsibility such as “for educational awareness only.” The models simply did not fail to reject harmful information – they were completing them in detail.
It was an equal concern to be the results in the CBRN category (chemical, biological, radiological and nuclear). When he is required to request how to modify the VX nerve factor – a chemical weapon – models have made shockingly specific ideas to increase their stability in the environment. They have been described, in the technical details, but clearly, ways such as packaging, environmental shielding, and controlling version systems.
These failures have not always been operated by public harmful requests. One of the tactics included downloading a picture of an empty numbered menu and asking the form “Fill in Details”. This simple, simple claim, which seems not harmful, has generated immoral and illegal instructions. The integration of visual and fair manipulation has proven particularly dangerous – as the unique challenge represented by Amnesty International Multimedia lights up.
Why are the examples of the language of vision are new security challenges
At the heart of these risks, the artistic complexity of models in the language of vision lies. These systems are not only abandoning the language – they collect the meaning through coordination, which means that they must explain the content of the image, understand the context of the text, and respond accordingly. This reaction offers new exploitation. The model may properly reject a directed text on its own, but when it is associated with a suggestive image or a mysterious context, a dangerous output may be generated.
Enkrypt AI Red Red team revealed how Media injection attacksWhere the exact signals affect one way to output the other – they can completely exceed standard safety mechanisms. These failures show that traditional content baptism techniques, created for one systems, are not enough for VLMS today.
The report also shows how Pixral: Pixrtral-Large models have been accessed through AWS BEDROCK and Pixral-12B via Mistral platform. The context of publishing in the real world emphasizes these results. These models are not limited to laboratories – they are available through the prevailing cloud platforms and can be easily combined into consumer products or institutions.
What to do: AI is safer
Thanks to this, Enkrypt AI does more than highlight the problems – it provides a path forward. The report defines a comprehensive reduction strategy, starting with Safety alignment training. This includes re -training the form using its red team data to reduce exposure to harmful demands. It is recommended for techniques such as improving direct preference (DPO) for high -end models’ responses away from risky outputs.
It also emphasizes the importance of the perceived handrails of the dynamic context that can be interpreted and prohibited harmful information in the actual time, taking into account the full context of the multimedia inputs. In addition, the use of model risk cards as a transparent measure, helping stakeholders to understand the restrictions of the model and known failure.
Perhaps the most important recommendation is to deal with the red team as a continuous process, not a single time test. With the development of models, as well as attack strategies. Only for continuous evaluation and active monitoring can ensure long -term reliability, especially when models are published in sensitive sectors such as health care, education or defense.
the Report of a multimedia red team from Enkrypt Ai It is a clear indication of the artificial intelligence industry: multimedia power comes with multimedia responsibility. These models represent a leap forward in ability, but they also require a jump on how we think of safety, security and moral publishing. They left without deterrent, they are not only risked by failure, but they risk harm in the real world.
Anyone who works to or spread artificial intelligence on a large scale, this report is not just a warning. It is the playing book. It was not possible to come in a more urgent time.
