用视觉干扰让导航机器人无视指令,随意乱走。
Hijacking Vision-and-Language Navigation Agents with Adversarial Environmental Attacks
- 在3D环境中放置特殊外观物体,诱导预训练导航模型偏离原路径。
- 攻击可使机器人忽略指令并提前终止任务,或按攻击者设定路线移动。
- 无需修改模型,仅通过环境伪装就能实现劫持,适用于多种场景。
能够接收自然语言指令并在开放世界环境中执行任务的辅助式具身智能体,有望在制造或家庭护理等领域带来重大影响。然而,本文研究了这种优势可能被环境局部外观修改所滥用。以主流的视觉-语言导航(VLN)任务为例,我们提出一种白盒对抗攻击方法,通过优化3D攻击物体的外观,诱导观察到该物体的预训练VLN智能体执行预定行为。实验表明,该攻击可使智能体在遇到攻击物体后忽略原有指令,执行替代动作——即使这些指令和路径未在攻击优化时被考虑。攻击可引发智能体提前终止任务,或引导其沿攻击者定义的多步路径移动。在两种情况下,环境攻击均显著降低智能体正确遵循用户指令的能力。
原文摘要 · Abstract (English)
Assistive embodied agents that can be instructed in natural language to perform tasks in open-world environments have the potential to significantly impact labor tasks like manufacturing or in-home care -- benefiting the lives of those who come to depend on them. In this work, we consider how this benefit might be hijacked by local modifications in the appearance of the agent's operating environment. Specifically, we take the popular Vision-and-Language Navigation (VLN) task as a representative setting and develop a whitebox adversarial attack that optimizes a 3D attack object's appearance to induce desired behaviors in pretrained VLN agents that observe it in the environment. We demonstrate that the proposed attack can cause VLN agents to ignore their instructions and execute alternative actions after encountering the attack object -- even for instructions and agent paths not considered when optimizing the attack. For these novel settings, we find our attacks can induce early-termination behaviors or divert an agent along an attacker-defined multi-step trajectory. Under both conditions, environmental attacks significantly reduce agent capabilities to successfully follow user instructions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。