An image generated by HADES needs to be resized when it is sent into the image processor of the victim MLLM. Do you think that resizing the adversarial noise part will reduce the jailbreak ability of the image? If so, is it better to let the image size consistent with the default image size of the image processor when adding adversarial noise to it? Since the final image doesn't have to be resized when sent into the victim MLLM in this way.
An image generated by HADES needs to be resized when it is sent into the image processor of the victim MLLM. Do you think that resizing the adversarial noise part will reduce the jailbreak ability of the image? If so, is it better to let the image size consistent with the default image size of the image processor when adding adversarial noise to it? Since the final image doesn't have to be resized when sent into the victim MLLM in this way.