光照攻击让机器人视觉模型失明,新方法保色抗干扰
Lights, Camera, Malfunction: When Illumination Robustness Leaves VLA Models Blind to Color

- 用定向灯光攻击暴露视觉模型对光照敏感的缺陷
- 传统增强训练反而让模型丢弃颜色信息,任务成功率降至47.5%
- 提出保色对抗训练法,真实机器人实验成功率超90%
视觉-语言-动作(VLA)模型在通用机器人操作中表现强大,但在真实环境中易受微小环境扰动影响。我们提出FLARE——一种无需访问模型内部的物理聚光灯攻击框架,通过针对性照明将基准任务成功率降至零。尽管对抗训练是常见防御手段,我们发现其存在关键缺陷:简单数据增强会错误引导模型将颜色视为噪声,导致视觉感知退化为仅依赖形状的处理器。通过灰度诊断评估,经训练的模型在灰度输入上仍保持高成功率,但在正常彩色真实任务上的成功率下降至最多47.5%,低于未防御基线。为此,我们提出ChromaGuard——一种保留色彩信息的对抗训练方法。在物理6-DoF机器人平台上,ChromaGuard在无攻击和受攻击的彩色任务中分别实现97.5%和92.5%的成功率。
原文摘要 · Abstract (English)
Vision-Language-Action (VLA) models have emerged as a powerful paradigm for general-purpose robot manipulation; however, their transition to real-world environments reveals vulnerabilities to minor environmental perturbations. We propose FLARE, an optimized physical spotlight attack framework that exploits these vulnerabilities via targeted illuminations, dropping baseline task success rates to zero without any access to model internals. While adversarial training is the standard countermeasure, we identify a critical and previously underestimated defensive pitfall: naive data augmentations incorrectly condition VLA models to discard color as noise, collapsing their visual perception into a purely shape-biased processor. We expose this degradation through a diagnostic grayscale evaluation, in which the defended model maintains high success rates on grayscale inputs, while its success rate on benign, color-dependent real-world tasks drops to at most 47.5%, well below the undefended baseline. To address this, we propose ChromaGuard, a chroma-preserving adversarial training method. On a physical 6-DoF robotic platform, we demonstrate that ChromaGuard achieves 97.5% and 92.5% success rates in benign and attacked color-dependent tasks, respectively.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。