arXiv:2606.15165cs.CRcs.RO2026-06被引 1

首次揭示视觉语言动作模型的隐私漏洞,可高效识别训练数据成员身份。

VLALeaks: Membership Inference Attacks against Vision-Language-Action Models

论文配图:VLALeaks: Membership Inference Attacks against Vision-Language-Action Models
图 1 · 摘自论文原文
  • 基于注意力差异设计两阶段攻击,挖掘VLA模型中的成员信息。
  • 在多个VLA基准上实现最优攻击性能,AUC与1%误报率下真阳性率领先。
  • 为机器人学习模型隐私安全提供关键警示,适合关注AI安全的研究者。

视觉语言动作(VLA)模型实现了端到端机器人控制,受到广泛关注。然而,VLA模型对训练数据的固有记忆特性,结合机器人数据采集的高昂成本,引发了严重的数据隐私泄露和知识产权侵权担忧。成员推断攻击(MIAs)旨在判断某样本是否属于训练集。尽管构成重大隐私威胁,该攻击在VLA模型领域仍鲜被研究。为此,我们提出VLALeaks,基于VLA模型中的注意力差异,首次揭示了其隐私脆弱性。该方法包含两个阶段:(1) 成员特征提取,(2) 攻击模型构建。在多个VLA基准上的实验表明,VLALeaks能有效暴露成员信息,取得最优攻击AUC及1%误报率下的真阳性率,凸显当前VLA模型部署中的隐私风险。本工作是首个系统性研究VLA模型成员推断攻击的工作,旨在为构建安全可信的VLA模型提供洞见。

原文摘要 · Abstract (English)

Vision-Language-Action (VLA) models enable end-to-end robot control and have garnered widespread attention. However, the memorization of training data inherent to VLA, coupled with the high cost of robotic data acquisition, raises serious concerns regarding data privacy leakage and intellectual property infringement. Membership inference attacks (MIAs) aim to determine whether a given sample belongs to the training set. While representing a significant privacy threat, this attack remains underexplored in the context of VLA models. To bridge this gap, we propose VLALeaks, which is based on attention discrepancies in VLA models. We reveal, for the first time, the privacy vulnerabilities of VLA models. Specifically, it comprises a two-stage process: (1) membership feature extraction, and (2) attack model construction. Experimental results across multiple VLA benchmarks demonstrate that VLALeaks readily reveals membership information and achieves optimal attack AUC and TPR@1\%FPR, highlighting the privacy vulnerabilities in current VLA model deployments. Our work is the first systematic study of MIAs on VLA models, aiming to provide insights for secure and trustworthy VLA models.

隐私安全成员推断VLA模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。