arXiv:2605.28083cs.CV2026-05被引 1

通过劫持视觉自定位,用一张贴纸让机器人误认自己在别处,实现跨模型攻击。

VLA-Hijack: A Transferable Patch Attack against Vision-Language-Action Models via Visual Proprioception Hijacking

论文配图:VLA-Hijack: A Transferable Patch Attack against Vision-Language-Action Models via Visual Proprioception Hijacking
图 1 · 摘自论文原文
  • 利用机器人自我定位时的视觉漏洞,同时抑制真实手臂特征并注入虚假姿态。
  • 在多个模型上实现90%以上成功率,跨架构攻击效果超越现有方法。
  • 适合研究安全防御或对抗样本的开发者,尤其关注机器人系统可靠性者。

尽管视觉-语言-动作(VLA)模型已成为强大的通用策略,但其对对抗性贴纸的严重脆弱性显著阻碍了其在安全关键领域的部署。现有贴纸攻击主要集中在白盒设置下,过度拟合目标模型的具体动作输出空间,导致跨架构迁移能力差。为克服这一局限,我们提出VLA-Hijack,一种统一的对抗框架,通过利用本研究发现的根本性漏洞:在规划任何运动前,VLA模型必须先使用视觉信息定位自身机械臂在环境中的位置。针对这一共享的视觉自我定位过程,我们的方法同时优化注意力引导的本体感知抑制以抑制真实机械臂特征,并进行多模态本体感知注入,使贴纸成为替代的“幻影身体”。通过在语义概念锚定与视觉原型投影间交替,VLA-Hijack有效切断了智能体真实本体与其控制策略之间的语义关联。在OpenVLA、UniVLA和CronusVLA等多种架构上的广泛实验表明,VLA-Hijack在白盒设置中实现更优优化效率,并在跨架构与跨领域黑盒迁移性方面创下新SOTA。

原文摘要 · Abstract (English)

While Vision-Language-Action (VLA) models have emerged as powerful generalist policies, their severe vulnerability to adversarial patches significantly hinders their deployment in safety-critical domains. Moreover, existing patch attacks primarily focus on white-box settings, heavily overfitting to the specific action output space of the target model, which results in poor cross-architecture transferability. To overcome this limitation, we propose VLA-Hijack, a unified adversarial framework that breaks the transferability bottleneck by exploiting a fundamental vulnerability identified in this work: before planning any motion, a VLA model must first use visual information to locate its own robotic arm within the environment. Targeting this shared visual self-localization process, our approach concurrently optimizes Attention-Guided Proprioceptive Suppression to inhibit the real robotic arm's features, and Multimodal Proprioceptive Injection to establish the patch as a surrogate "phantom embodiment". By alternating between semantic concept anchoring and visual prototype projection, VLA-Hijack effectively severs the semantic relationship between the agent's true embodiment and its control policy. Extensive experiments across diverse architectures (OpenVLA, UniVLA, and CronusVLA) demonstrate that VLA-Hijack achieves superior optimization efficiency in white-box settings and sets a new SOTA for cross-architecture and cross-domain black-box transferability.

对抗攻击机器人安全视觉定位跨模型迁移

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。