防御视觉语言动作机器人注意力劫持,提升无线传感网络中智能体鲁棒性
VLAGuard: A Framework for Evaluating and Mitigating Physical Attention Hijacking in Vision-Language-Action Robots within Wireless Sensor Networks

- 用可打印贴纸诱导机器人跨模态注意力错乱,模拟物理攻击
- 提出无推理开销的注意力保护微调,使失败率从100%降至25.9%
- 适用于部署在无线传感网中的智能机器人系统安全防护
将视觉-语言-动作(VLA)机器人作为无线传感器网络(WSNs)中的移动边缘节点部署时,需防范物理层面的对抗性威胁。本文提出VLAGuard框架,用于评估并缓解一项关键漏洞:政策关键的动作-视觉注意力劫持。我们首先引入应力测试模块——视觉运动引导语义攻击(VASA),利用可打印贴纸严重干扰机器人基于动作条件的交叉注意力。为应对该威胁,提出注意力保护微调(APFT)防御机制,通过稳定时空注意力并强制几何一致性,在零推理开销下实现防护。在仿真与真实世界的WSN辅助智能环境中的评估表明,显著提升了鲁棒性:在LIBERO仿真中,APFT将OpenVLA失败率从100.0%降至25.9%;在2000次真实世界试验中,面对严重贴纸攻击,平均成功率从23.0%提升至67.4%。这表明保护注意力路径对提升VLA驱动边缘节点在传感器网络中的可靠性至关重要。
原文摘要 · Abstract (English)
Deploying Vision-Language-Action (VLA) robots as mobile edge nodes within wireless sensor networks (WSNs) requires robust protection against physical adversarial threats. We present VLAGuard, a framework to assess and mitigate a critical vulnerability: policy-critical action-to-vision attention hijacking. We first introduce a stress-test module, Visuomotor Attention-guided Semantic Attack (VASA), using printable patches to severely distract the robot's action-conditioned cross-attention. To counter this, we propose Attention-Protective Fine-Tuning (APFT), a defense that stabilizes spatiotemporal attention and enforces geometric consistency with zero inference overhead. Evaluations across simulated and physical WSN-assisted smart environments demonstrate significant robustness gains. APFT reduces the OpenVLA failure rate from 100.0% to 25.9% in LIBERO simulations. Furthermore, across 2,000 real-world trials, APFT improves the average success rate from 23.0% to 67.4% under severe patch attacks. This highlights that protecting attention pathways is important for improving the robustness of VLA-driven edge nodes in sensor networks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。