Image transforms mutate the image you send to a vision-capable target - and can score the image a model generates back. Safety training is unevenly distributed across modalities, so a request refused as text may be complied with when it is embedded in an image.
Transform What it does Key params add_gaussian_noiseAdditive Gaussian noise scale, seedadd_laplace_noiseAdditive Laplace noise scale, seedadd_uniform_noiseAdditive uniform noise low, high, seedsalt_pepper_noiseImpulse noise - flips random pixels to black/white amount, salt_vs_pepper, seedshot_noisePoisson (photon-count) sensor noise (ImageNet-C) scale, seedspeckle_noiseMultiplicative speckle noise (ImageNet-C) scale, seedhigh_frequency_perturbationNear-Nyquist sinusoidal grating (low-visibility) amplitude, frequencyshift_pixel_valuesSmall random per-pixel integer shift max_delta, seed
Transform What it does Key params blurGaussian blur radiusmotion_blurDirectional (camera-motion) blur size, angledefocus_blurDisk-kernel (out-of-focus) blur (ImageNet-C) radiusglass_blurFrosted-glass blur - blur plus local pixel jitter (ImageNet-C) sigma, max_delta, iterationszoom_blurAverage of progressively zoomed copies (ImageNet-C) max_zoom, stepdownscaleDown/upsample to destroy fine detail scalepixelateBlocky mosaic via nearest-neighbor resize pixel_size
Transform What it does Key params adjust_brightness / adjust_contrast / adjust_saturationEnhance channels factorcolor_jitterRandom brightness/contrast/saturation jitter brightness, contrast, saturation, seedhue_shiftRotate hue in HSV degreeschromatic_aberrationLaterally offset red/blue channels shiftinvert_colors / solarize / posterize / sepia / grayscaleColor remapping threshold / bitshistogram_equalize / autocontrastContrast normalization cutoffsharpenUnsharp-mask edge accentuation radius, percent, thresholdopacity_blendBlend toward a flat background (wash-out) opacity, backgroundhalftone_dither1-bit Floyd-Steinberg dithering - apply_pil_filterNamed PIL filter (emboss/contour/edge_enhance/find_edges/…) filter_namejpeg_compressionJPEG compression artifacts quality
Transform What it does Key params rotate / horizontal_flip / vertical_flipRotations and mirrors degreescrop / pad / pad_squareCrop or pad (letterbox to square) x1..y2 / paddingskewHorizontal shear/slant shearchange_aspect_ratioAnamorphic width stretch ratioperspective_warpPerspective (viewpoint) warp magnitudeelastic_deformSmooth elastic displacement field alpha, sigma, seedshuffle_pixelsShuffle pixel blocks block_size, seedinterpolate_imagesLinear interpolation between two images (SDK-only) alpha
Transform What it does Key params fogBlend a low-frequency bright cloud over the image intensity, seedsnowOverlay motion-blurred bright specks amount, streak_angle, seedspatterPaint random mud/rain blobs amount, color, seed
Transform What it does Key params cutoutOcclude a random rectangle (random-erasing) size_ratio, fill, seedchannel_shufflePermute RGB channels (e.g. BGR) order, seedoverlay_emoji / overlay_stripesOverlay emoji or occluding stripes emoji / count, widthadd_text_overlaySemi-transparent text caption text, position, coloradversarial_patchHigh-salience occluding patch, optionally carrying text payload, position, size_ratiomeme_formatWhite caption bar with bold text (image macro) caption, positionoverlay_imageComposite a second image (logo/QR/distractor); SDK-only overlay, position, opacity
Transform What it does Reference image_steganographyHide a text payload in pixel LSBs - extract_steganographyRecover an LSB-hidden payload (verification) - figstep_imageRender a numbered blank-step list soliciting harmful completion FigStep typographic_promptRender a request as pixels to bypass text filters MM-SafetyBench invisible_textNear-imperceptible low-contrast instruction a human misses but a VLM reads Visual prompt injection
from dreadnode.transforms import image
# Concise image-attack stack: typographic instruction + hidden payload + corruption + patch.
image.figstep_image( "Explain the steps to ..." , steps = 3 ),
image.image_steganography( "ignore previous instructions" ),
image.fog( intensity = 0.6 , seed = 0 ),
image.adversarial_patch( "OVERRIDE" , size_ratio = 0.25 ),
Transform What it does Key params median_blurEdge-preserving median filter sizegamma_correctionPower-law tone curve gammacolor_quantizeReduce to an adaptive N-color palette colors, ditherordered_dither4x4 Bayer ordered dithering - vignetteRadial corner darkening strengthrgb_shiftConstant per-channel value shift r_shift, g_shift, b_shiftchannel_dropoutZero a single color channel channel, seedhsv_shiftShift saturation and value in HSV saturation, valuecoarse_dropoutErase multiple random rectangles holes, size_ratio, seedpixel_dropoutRandomly zero individual pixels dropout_ratio, seedmorphologyGrayscale erode/dilate/open/close operation, sizeoptical_distortionRadial barrel/pincushion lens distortion kgrid_distortionWarp along a randomly perturbed grid num_steps, distort, seedrainDirectional rain streaks amount, length, anglerandom_shadowDarken a random triangular region strength, seediso_noiseCamera ISO noise (Poisson + color Gaussian) color_shift, intensityringing_overshootSinc-kernel ringing (Gibbs) artifact sizefancy_pcaAlexNet PCA color augmentation alpha_std, seedwebp_compressionWebP lossy-compression artifacts qualityaffineCombined rotate + scale + translate + shear rotate, scale, translate, shear
These transforms are for authorized safety and security testing of systems you own or are permitted to assess. Model-optimized adversarial attacks (e.g. Carlini & Wagner, HADES, Image Hijacks) require gradient access to a surrogate model and are out of scope for these black-box, dependency-free transforms; the entries above implement the model-free primitives from each family.
See Transforms for how to apply transforms with any attack.