Explainable Multimodal LLM for Proactive Detection of Image-Borne Threats
Digital images, ubiquitous in Swedish society and industry, represent a sophisticated and evolving vector for cyberattacks. Threats include stealthy zero-click exploits and AI-assisted steganography, where malicious code is deeply embedded within image data.
Traditional defenses, often reliant on known signatures or unimodal analysis, frequently fail against these advanced attacks, posing a significant risk to Sweden’s digital infrastructure. This research posits that a fundamental leap is required, moving beyond mere detection to proactive and predictive identification of such embedded threats. We propose a groundbreaking Multimodal Large Language Model (MLLM) framework.
This MLLM is designed not only to detect malicious code embedded in images with high fidelity but also to: a) Infer the potential intent and target of these embedded malicious payloads. b) Identify novel, zero-day image-borne threats including sophisticated zero-click attack vectors through advanced unsupervised anomaly detection across diverse data modalities. c) Provide causally-informed, actionable explanations for its findings. This approach aims to provide support for Swedish entities that depend on image retrieval and matching, so that they can defend against these pervasive and damaging image-based attacks, particularly those that execute without user interaction.
About the PhD project
Proejct period
- 2025-11-03–2029-10-31
PhD student
Supervisor
Main supervisor
Co-supervisors
- Stefan Byttner, Professor, Halmstad University
- Jens Lundström, Senior Lecturer, Halmstad University
- Peyman Mashhadi, Senior Lecturer, Halmstad University
- Stefan Axelsson, Stockholm University
Cybercampus Sweden
Cybercampus Sweden is a national initiative and collaboration between universities, institutes, authorities and companies throughout Sweden, including Halmstad University. Cybercampus Sweden conducts groundbreaking and agile research, innovation and education for cyber security and defence beyond what is possible for individual organisations. The initiative aims to increase cyber security, strengthen society’s defence capabilities and Swedish competitiveness. KTH is the main partner for Cybercampus Sweden.