用多样性优化生成对抗指令,暴露视觉语言机器人系统漏洞并提升鲁棒性。
Red-Teaming Vision-Language-Action Models via Quality Diversity Prompt Generation for Robust Robot Policies
- 基于质量多样性算法生成多样且自然的指令,挖掘VLA模型失败模式。
- 在多个仿真环境中发现更多元、更真实的故障场景,提升任务成功率。
- 生成指令更贴近人类表达,适合用于机器人系统安全测试与训练。
视觉-语言-动作(VLA)模型在实现通用机器人系统方面潜力巨大,但其性能对语言指令的表述极为敏感,难以预测何时会失效。本文提出将质量多样性(QD)优化作为红队测试具身模型的自然框架,设计Q-DIG(质量多样性用于多样化指令生成),通过可扩展方式识别出多样、自然且与任务相关却导致失败的语言指令。Q-DIG结合质量多样性技术与视觉语言模型(VLM),生成广泛多样的对抗性指令,揭示VLA行为中的真实漏洞。在多个仿真基准上的实验表明,相比基线方法,Q-DIG能发现更多样且有意义的失败模式,且在生成指令上微调VLA可显著提高任务成功率。用户研究显示,Q-DIG生成的提示被认为比基线更自然、更像人类表达。真实世界评估结果与仿真一致,且在生成指令上微调后,对未见过的指令成功率进一步提升。这些结果表明,Q-DIG是识别漏洞并增强VLA机器人鲁棒性的有效方法。
原文摘要 · Abstract (English)
Vision-Language-Action (VLA) models have significant potential to enable general-purpose robotic systems for a range of vision-language tasks. However, the performance of VLA-based robots is highly sensitive to the precise wording of language instructions, and it remains difficult to predict when such robots will fail. We propose Quality Diversity (QD) optimization as a natural framework for red-teaming embodied models, and present Q-DIG (Quality Diversity for Diverse Instruction Generation), which performs red-teaming by scalably identifying diverse, natural language task descriptions that induce failures while remaining task-relevant. Q-DIG integrates QD techniques with Vision-Language Models (VLMs) to generate a broad spectrum of adversarial instructions that expose meaningful vulnerabilities in VLA behavior. Our results across multiple simulation benchmarks show that Q-DIG finds more diverse and meaningful failure modes compared to baseline methods, and that fine-tuning VLAs on the generated instructions improves task success rates. Furthermore, results from a user study highlight that Q-DIG generates prompts judged to be more natural and human-like than those from baselines. Finally, real-world evaluations of Q-DIG prompts show results consistent with simulation, and fine-tuning VLAs on the generated prompts further success rates on unseen instructions. Together, these findings suggest that Q-DIG is a promising approach for identifying vulnerabilities and improving the robustness of VLA-based robots. Our anonymous project website is at qdigvla.github.io.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。