研究发现手术机器人学习策略易受视觉干扰攻击,可能造成操作失败。
Adversarial Attacks on Learned Policies for Surgical Robotic Tasks

- 设计三类攻击方法,利用细微视觉扰动破坏或误导机器人动作
- 在560次实体实验中,成功率平均下降61%,涉及去腐和缝合任务
- 提出模拟真实光照变化的攻击方式,更具隐蔽性和现实威胁
基于学习的策略正被用于提升机器人辅助手术中外科医生的操作精度。这些端到端的视觉到动作映射是否可能受到对抗攻击,从而引发患者伤害?本文首次系统研究了学习型策略在手术机器人中的对抗威胁。我们考察两类攻击模式:(a)干扰攻击,即不可察觉的视觉扰动中断策略执行;(b)引导攻击,使策略动作朝攻击者指定方向偏移。提出三种逐步增加对策略信息访问的攻击方法,并在去腐与缝合两个手术子任务上评估其影响。测试涵盖三种端到端策略架构:ACT、Diffusion Policy 和 Pi0。此外,引入一类新的光度对抗攻击,模仿自然光照变化,生成有效且视觉合理的扰动。基于假体进行的560次物理实验表明,当前最先进的策略极易被破坏,导致手术子任务成功率平均下降61%。
原文摘要 · Abstract (English)
Learning-based policies are being considered to augment the dexterity of human surgeons in robot-assisted surgery. Can the end-to-end mapping from visual observations to robot actions be vulnerable to adversarial attacks, potentially leading to patient injury? In this paper, we present the first study of adversarial threats to learning-based policies in surgical robotics. We investigate two threat modes: (a) disruptive attacks, where imperceptible visual perturbations interrupt policy execution, and (b) steering attacks, where such perturbations steer policy actions toward attacker-specified directions. We formulate three adversarial attack methods, each with increasing access to policy information, and evaluate their impact on two surgical subtasks: debridement and suturing. Our evaluation covers three end-to-end policy architectures: ACT, Diffusion Policy, and Pi0. In addition, we introduce a new class of photometric adversarial attacks that mimic natural visual changes, such as lighting variations, to generate effective yet visually plausible perturbations. Results from 560 physical experiments using phantoms for debridement and suturing suggest that state-of-the-art policies can be significantly disrupted, resulting in an average 61% reduction in surgical subtask success rates. Project page: https://sites.google.com/view/adversary-surgery
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。