cs.CLJan 19, 2026

ChartAttack: Testing the Vulnerability of LLMs to Malicious Prompting in Chart Generation

Authors: Jesus-German Ortiz-BarajasJonathan TongletVivek GuptaIryna Gurevych

Organizations: INSAIT · KU Leuven · Arizona State University · Ubiquitous Knowledge Processing Lab (UKP Lab), Department of Computer Science, TU Darmstadt and National Research Center for Applied Cybersecurity ATHENE · Sofia University “St. Kliment Ohridski”

Abstract

Multimodal large language models (MLLMs) are increasingly used to automate chart generation from data tables, improving efficiency but introducing new misuse risks. We present ChartAttack, a framework for evaluating how MLLMs use design misleaders to generate charts that induce incorrect interpretations. We also introduce AttackViz, a chart question-answering (QA) dataset labeled with effective misleaders and their induced incorrect answers. ChartAttack reduces MLLM QA accuracy by 17.2 points in-domain and 11.9 points cross-domain. Conditional deception rates show targeted effects: correct answers shift to attacker-intended answers 11.2% of the time in-domain and 11.7-14.9% cross-domain, while originally incorrect answers rarely change. A controlled human study shows that ChartAttack-generated charts also reduce human QA performance. Finally, fine-tuning on AttackViz improves in-domain MLLM robustness to misleading charts. Our findings highlight the need for secure, robust MLLM chart generation. Code and data are publicly available on the project website.

Explore similar work

CardsList
  1. Generating Statistical Charts with Validation-Driven LLM Workflows

    May 1, 2026Pavlin G. Poličar, Andraž Pevcin, Blaž ZupanChartReasoning Graphs