评估视觉语言动作模型在物理威胁下的脆弱性,发现其易受干扰攻击。
Manipulation Facing Threats: Evaluating Physical Vulnerabilities in End-to-End Vision Language Action Models
- 提出PVEP评估框架,整合分布外、文字提示和对抗补丁等物理威胁
- 实验显示模型在攻击下性能显著下降,响应不稳定
- 为机器人安全提供可复用的评估方法,适合研究鲁棒性学者
近年来,随着多模态大语言模型(MLLMs)的发展,视觉语言动作模型(VLAMs)被提出以在开放词汇场景下提升机器人操作任务的表现。由于操作任务涉及与物理世界的直接交互,确保执行过程中的鲁棒性与安全性始终是关键问题。本文结合当前MLLMs的安全研究成果及操作任务的实际物理场景,系统评估了VLAMs面对潜在物理威胁的表现。具体地,我们提出了物理脆弱性评估流程(PVEP),可集成多种视觉模态的物理威胁,用于评估VLAMs的物理鲁棒性。这些威胁包括分布外样本、基于文字的视觉提示以及对抗补丁攻击。通过对比模型在攻击前后的性能波动,我们提供了关于VLAMs对不同物理威胁响应的通用性分析。
原文摘要 · Abstract (English)
Recently, driven by advancements in Multimodal Large Language Models (MLLMs), Vision Language Action Models (VLAMs) are being proposed to achieve better performance in open-vocabulary scenarios for robotic manipulation tasks. Since manipulation tasks involve direct interaction with the physical world, ensuring robustness and safety during the execution of this task is always a very critical issue. In this paper, by synthesizing current safety research on MLLMs and the specific application scenarios of the manipulation task in the physical world, we comprehensively evaluate VLAMs in the face of potential physical threats. Specifically, we propose the Physical Vulnerability Evaluating Pipeline (PVEP) that can incorporate as many visual modal physical threats as possible for evaluating the physical robustness of VLAMs. The physical threats in PVEP specifically include Out-of-Distribution, Typography-based Visual Prompt, and Adversarial Patch Attacks. By comparing the performance fluctuations of VLAMs before and after being attacked, we provide generalizable \textbf{\textit{Analyses}} of how VLAMs respond to different physical threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。