发现视觉语言动作模型在机器人中的对抗漏洞,可导致任务失败率达100%。
Exploring the Adversarial Vulnerabilities of Vision-Language-Action Models in Robotics
- 设计三种攻击方式:两种无目标空间扰动,一种有目标轨迹干扰
- 物理与数字环境中均通过彩色贴片实现攻击,任务成功率最高下降100%
- 为机器人VLA系统提供安全评估新标准,适合关注机器人安全的研究者
近年来,视觉-语言-动作(Vision-Language-Action, VLA)模型在机器人领域成为变革性方法,通过端到端学习整合视觉与语言输入以执行复杂任务。然而,这类模型引入了新的攻击面。本文系统评估其鲁棒性,针对机器人执行的特异性,提出三种攻击目标:利用空间特性实施两种无目标攻击以扰乱动作,以及通过操纵轨迹实现有目标攻击。此外,设计了一种对抗性贴片生成方法,在摄像头视野内放置小块彩色贴片,可在数字与物理环境中有效触发攻击。实验表明,在一系列模拟机器人任务中,任务成功率最高下降100%,揭示当前VLA架构存在重大安全隐患。本文通过揭示这些漏洞并提出可操作的评估指标,推动对VLA机器人系统安全性的理解与提升,强调在真实世界部署前必须持续构建鲁棒防御策略。
原文摘要 · Abstract (English)
Recently in robotics, Vision-Language-Action (VLA) models have emerged as a transformative approach, enabling robots to execute complex tasks by integrating visual and linguistic inputs within an end-to-end learning framework. Despite their significant capabilities, VLA models introduce new attack surfaces. This paper systematically evaluates their robustness. Recognizing the unique demands of robotic execution, our attack objectives target the inherent spatial and functional characteristics of robotic systems. In particular, we introduce two untargeted attack objectives that leverage spatial foundations to destabilize robotic actions, and a targeted attack objective that manipulates the robotic trajectory. Additionally, we design an adversarial patch generation approach that places a small, colorful patch within the camera's view, effectively executing the attack in both digital and physical environments. Our evaluation reveals a marked degradation in task success rates, with up to a 100\% reduction across a suite of simulated robotic tasks, highlighting critical security gaps in current VLA architectures. By unveiling these vulnerabilities and proposing actionable evaluation metrics, we advance both the understanding and enhancement of safety for VLA-based robotic systems, underscoring the necessity for continuously developing robust defense strategies prior to physical-world deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。