arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.26868cs.RO

基于学习的工业机械臂操作中的后门攻击:一项实证安全研究

Backdoors in Learning-Based Industrial Robotic Arm Manipulation: An Empirical Security Study

  • University of Wisconsin Milwaukee(威斯康星大学密尔沃基分校)
  • IBM Research(IBM研究院)
  • MIT Lincoln Laboratory(麻省理工学院林肯实验室)

机构由 AI 辅助整理,请以论文原文为准。

Zijian Zhang, Zhen Zeng, Zhongshu Gu, Sandeep Pisharody

AI总结:

本研究在真实工业机械臂上实证评估后门攻击的隐蔽性与危害,提出在线防御流程以实时检测并中和触发器,兼顾防御效果与运行开销。

AI中文摘要:

基于学习的模型(例如视觉运动模型和视觉-语言-动作(VLA)模型)正越来越多地被应用于工业机械臂操作中,其中模型预测被直接转化为物理动作。模型行为与物理执行之间的这种紧密耦合使得隐藏的安全漏洞尤为严重。尽管后门攻击已在传统AI模型中得到广泛研究,但其对已部署的基于学习的机械臂操作系统的影响仍鲜为人知:一个被植入后门的机器人可以在正常运行期间表现正常,仅在特定触发器出现时才诱导攻击者指定的行为,这在物理环境中可能构成严重风险。在本研究中,我们对基于学习的机械臂操作中的后门攻击与防御进行了初步的实证安全研究,实验在两款真实的商用工业机械臂(FANUC和xArm)上进行。我们探究后门是否能在名义任务执行期间保持隐蔽的同时,可靠地诱导语义上错误的操作行为。随后,我们开发了一种在线防御流程,能够在运行时检测并中和触发器,并将其效果与离线微调防御进行比较。除防御效果外,我们还进一步评估了防御流程引入的计算延迟和执行开销,以评估其是否适用于高吞吐量的工业操作。

英文摘要:

Learning-based models (e.g., visuomotor and Vision-Language-Action (VLA)) are increasingly explored for industrial robotic manipulation, where model predictions are directly translated into physical actions. This tight coupling between model behavior and physical execution makes hidden security vulnerabilities particularly consequential. While backdoor attacks have been widely studied in conventional AI models, their effects on deployed learning-based robotic arm manipulation systems remain less understood: a backdoored robot can behave normally during benign operation while inducing attacker-specified behaviors only when specific triggers are present, posing potentially serious risks in physical environments. In this work, we present a preliminary empirical security study of backdoor attacks and defenses in learning-based robotic manipulation on two real commercial industrial robotic arms (FANUC and xArm). We investigate whether a backdoor can reliably induce semantically incorrect manipulation behaviors while remaining stealthy under nominal task execution. We then develop an online defense pipeline that detects and neutralizes triggers at runtime, and compare its effectiveness against an offline fine-tuning defense. Beyond defense effectiveness, we further evaluate the computational latency and execution overhead introduced by the defense pipeline to assess its suitability for high-throughput industrial operation.

补充信息

↑