arXiv:2604.09651cs.CVcs.LG2026-04中稿 · CVPR被引 1

首个针对连续动作生成模型的隐蔽后门攻击,可伪装成正常行为。

FlowHijack: A Dynamics-Aware Backdoor Attack on Flow-Matching Vision-Language-Action Models

论文配图:FlowHijack: A Dynamics-Aware Backdoor Attack on Flow-Matching Vision-Language-Action Models
图 1 · 摘自论文原文
  • 通过控制动作生成起始阶段,植入隐蔽后门。
  • 攻击成功率高,且不降低正常任务表现。
  • 适合关注机器人安全与模型内核漏洞的研究者。

视觉-语言-动作(VLA)模型正成为机器人领域的核心,基于流匹配的策略(如 $π_0$)在生成平滑连续动作方面展现出巨大潜力。随着模型发展,其独特的动作生成机制——向量场动力学,暴露出一个关键但未被探索的安全漏洞,尤其是后门攻击风险。现有针对自回归离散化VLA的后门攻击无法直接应用于这一类连续动态模型。我们提出FlowHijack,首个系统性针对流匹配VLA底层向量场动力学的后门攻击框架。该方法结合一种新颖的 $τ$-条件注入策略,操控动作生成的初始阶段,并引入动力学模仿正则项。实验表明,FlowHijack在先前方法失败的隐蔽、上下文感知触发条件下仍能实现高攻击成功率。关键的是,它保持了良性任务性能,并通过强制运动学相似性,使恶意动作在行为上与正常动作无法区分。研究揭示了连续具身模型中的重大安全隐患,凸显了针对模型内部生成动力学防御的紧迫性。

原文摘要 · Abstract (English)

Vision-Language-Action (VLA) models are emerging as a cornerstone for robotics, with flow-matching policies like $π_0$ showing great promise in generating smooth, continuous actions. As these models advance, their unique action generation mechanism - the vector field dynamics - presents a critical yet unexplored security vulnerability, particularly backdoor vulnerabilities. Existing backdoor attacks designed for autoregressive discretization VLAs cannot be directly applied to this new continuous dynamics. We introduce FlowHijack, the first backdoor attack framework to systematically target the underlying vector-field dynamics of flow-matching VLAs. Our method combines a novel $τ$-conditioned injection strategy, which manipulates the initial phase of the action generation, with a dynamics mimicry regularizer. Experiments demonstrate that FlowHijack achieves high attack success rates using stealthy, context-aware triggers where prior works failed. Crucially, it preserves benign task performance and, by enforcing kinematic similarity, generates malicious actions that are behaviorally indistinguishable from normal actions. Our findings reveal a significant vulnerability in continuous embodied models, highlighting the urgent need for defenses targeting the model's internal generative dynamics.

后门攻击机器人安全流匹配动态模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。