攻击者可实时劫持视觉驱动的机器人,远程操控其行为。
Test-time Adversarial Takeover: A Real-time Hijacking Interface against Robotic Diffusion Policies

- 用可复用的通用扰动块控制机器人视觉输入,实现实时劫持。
- 在4个任务、3种模型架构下,人类操纵者100%成功达成目标。
- 突破传统干扰攻击,直接获得对机器人的远程控制权。
基于扩散模型的动作生成已成为具身智能的核心组件,但其依赖视觉条件输入,使部署的视觉-运动策略易受对抗性攻击。现有攻击多为干扰型,通过扰动观测流降低任务成功率或引发异常行为。本文研究更强威胁——测试时对抗劫持(TAKO),攻击者可在不修改模型的前提下,实时获取对冻结机器人策略的操控接口,将其变为远程遥控工具。TAKO通过可微分扩散推断学习一组小型通用扰动块;测试时,攻击者在摄像头画面中切换这些扰动块,即可合成攻击者指定的轨迹。该方法有效是因为扰动作用于视觉条件路径,其诱导偏差能贯穿迭代生成过程。我们进一步证明,自然的靶向基线(目标策略匹配)失效,因受害者策略无法可靠监督自身在分布外目标变化下的表现。在四个任务(2D操作、模拟空中投送、模拟地面导航、真实世界地面导航)、两种视觉编码器(ResNet-18 和 EfficientNet-B0 + Transformer)以及三种生成推理方法(DDPM、DDIM、flow matching)下,人类操作员在所有设置中均实现100%劫持成功率,达成攻击者定义的目标。
原文摘要 · Abstract (English)
Diffusion-based action generation has become a foundational component of embodied AI, but its reliance on visual conditioning leaves deployed visuomotor policies vulnerable to adversarial manipulation. Most prior attacks focus on disruption: they perturb the observation stream to reduce task success or induce erratic behavior. We study a stronger threat, Test-time Adversarial Takeover (TAKO), in which an attacker obtains a real-time steering interface over a frozen robot policy and turns it into a remotely piloted instrument. TAKO learns a small vocabulary of reusable universal patches through differentiable diffusion inference; at test time, the attacker switches among these patches in the camera stream to compose attacker-chosen trajectories. This works because the perturbation acts on the visual conditioning pathway, where the induced bias can persist through iterative generative inference. We further show that the natural targeted baseline, target-policy matching, fails because the victim policy cannot reliably supervise itself on out-of-distribution target shifts. Across four tasks (2D manipulation, simulated aerial delivery, simulated ground navigation, and physical-world ground navigation), two visual encoders (ResNet-18 and EfficientNet-B0 + Transformer), and three generative inference families (DDPM, DDIM, and flow matching), human operators achieve 100\% takeover success on attacker-defined objectives in every evaluated setting. The project page is available at https://tako-attack.github.io.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。