arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

利用漏洞:面向机器人视觉-语言-动作模型的通用对抗攻击

Exploiting Vulnerabilities: Universal Adversarial Attacks on Vision-Language-Action Models in Robotics

Songhua Yang, Ziyu Liu, Yuanwei Liu, Xuetao Li, Xuanye Fei, He Huang, Zheng Wang, Miao Li

arXiv 2609.39178首次发表:更新:

发表机构

Wuhan University(武汉大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出一种通用对抗物体(带优化纹理的球体),通过多层级攻击框架破坏VLA模型的轨迹规划、任务执行和动作控制,使Pi0和RDT模型在模拟及真实环境中平均任务成功率降低31.2%-39.9%。

AI 中文摘要

近年来,视觉-语言-动作(VLA)模型通过端到端学习框架无缝整合视觉感知、语言理解和动作生成,彻底革新了机器人操作。然而,由于这些模型被设计为直接与物理世界和人类交互,其安全性至关重要,即使是微小的漏洞也可能导致灾难性故障。在本工作中,我们提出了通用对抗物体(Universal Adversarial Object),即一个具有优化表面纹理的球体,当它被放置在机器人的视野内时,能显著降低任务成功率。具体而言,我们的方法引入了一个多层级攻击框架,该框架联合破坏轨迹规划、任务执行和动作控制。我们在模拟和真实机器人环境中均验证了我们的方法。实验结果表明,对于两个具有代表性的VLA模型(Pi0和RDT),该对抗物体将平均任务成功率降低了31.2%-39.9%,在复杂场景中成功率甚至降至接近零。索引术语——视觉-语言-动作模型、对抗攻击、机器人安全、通用对抗物体。

英文摘要

Recently, Vision-Language-Action (VLA) models have revolutionized robotic manipulation by seamlessly integrating visual perception, language understanding, and action generation in an end-to-end learning framework. However, since these models are designed to interact directly with the physical world and humans, their security is critical, and even small vulnerabilities can lead to catastrophic failures. In this work, we propose the Universal Adversarial Object, a sphere with optimized surface texture that significantly degrades task success rates when placed within the robot's field of view. Specifically, our approach introduces a multi-level attack framework that jointly disrupts trajectory planning, task execution, and action control. We validate our method in both simulated and real-world robotic settings. Experimental results demonstrate that the adversarial object reduces the average task success rates by 31.2%-39.9% for two representative VLA models (Pi0 and RDT), with success rates dropping to near zero in complex scenarios. Index Terms--Vision-Language-Action models, adversarial attack, robotic security, universal adversarial object

CommentsAccepted to the 2026 IEEE International Conference on Robotics and Automation (ICRA 2026), Vienna, Austria. 8 pages. (c) 2026 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑