Why GPT-4 is vulnerable to multimodal prompt injection image attacks