利用动作分块漏洞,实现隐蔽的机器人视觉-语言-动作模型后门攻击
SilentDrift: Exploiting Action Chunking for Stealthy Backdoor Attacks on Vision-Language-Action Models

- 通过动作分块与位姿增量表示的漏洞,使扰动在执行中累积
- 在LIBERO数据集上实现93.2%攻击成功率,污染率低于2%
- 仅在关键阶段注入扰动,攻击痕迹几乎不可见,适合安全评估
视觉-语言-动作(VLA)模型正被广泛应用于安全关键型机器人任务,但其安全漏洞尚未充分研究。我们发现现代VLA系统存在根本性安全缺陷:动作分块与位姿增量表示的结合导致了块内视觉开环机制,迫使机器人执行K步动作序列,使每步扰动通过积分持续累积。为此,我们提出SILENTDRIFT,一种利用该漏洞的隐蔽黑盒后门攻击方法。该方法采用Smootherstep函数构建具有保证C2连续性的扰动,确保轨迹边界处速度与加速度为零,满足严格的运动学一致性约束。此外,关键帧攻击策略仅对关键接近阶段进行污染,最大化攻击效果同时最小化触发暴露。中毒轨迹在视觉上与成功示范无法区分。在LIBERO数据集上的评估显示,该攻击实现了93.2%的攻击成功率,污染率低于2%,同时保持95.3%的正常任务成功率。
原文摘要 · Abstract (English)
Vision-Language-Action (VLA) models are increasingly deployed in safety-critical robotic applications, yet their security vulnerabilities remain underexplored. We identify a fundamental security flaw in modern VLA systems: the combination of action chunking and delta pose representations creates an intra-chunk visual open-loop. This mechanism forces the robot to execute K-step action sequences, allowing per-step perturbations to accumulate through integration. We propose SILENTDRIFT, a stealthy black-box backdoor attack exploiting this vulnerability. Our method employs the Smootherstep function to construct perturbations with guaranteed C2 continuity, ensuring zero velocity and acceleration at trajectory boundaries to satisfy strict kinematic consistency constraints. Furthermore, our keyframe attack strategy selectively poisons only the critical approach phase, maximizing impact while minimizing trigger exposure. The resulting poisoned trajectories are visually indistinguishable from successful demonstrations. Evaluated on the LIBERO, SILENTDRIFT achieves a 93.2% Attack Success Rate with a poisoning rate under 2%, while maintaining a 95.3% Clean Task Success Rate.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。