arXiv:2608.23224cs.ROcs.AI2026-08

让视觉语言动作模型只在必要时才采纳外部提示,防止错误指令干扰执行。

Think Only When Needed: Prompt-Authority Control for Selective Slow-Path Intervention in Vision-Language-Action Manipulation

论文配图:Think Only When Needed: Prompt-Authority Control for Selective Slow-Path Intervention in Vision-Language-Action Manipulation
图 1 · 摘自论文原文
  • 设计权限分离机制,仅当符合规则时才允许修改原始指令。
  • 在900条路径中实现100%合规,92.5%恢复原始指令,375条授权提示保留任务特征。
  • 实测成功率从69.5%提升至73.1%,物理机器人实验提升至78.7%,显著优于基线。

检索可无需重训练地增强冻结的视觉-语言-动作(VLA)策略,但一旦文本被插入执行提示,便会成为控制干预。在匹配审计中,原始附加文本将平均成功率从92.47%降至3.00%,而有意义与长度匹配的无意义附加均在全部500个状态上失败。这揭示了‘提示形式坍塌’:改变指令形式比添加语义信息更能主导执行结果。我们提出TOWN-VLA(仅在必要时思考),通过提示权限接口分离候选生成与执行许可。固定兼容规则授权标准紧凑指令;否则严格还原原始Base提示。在900条审计路径中,525条恢复Base并哈希一致,所有375条授权提示均保持任务签名。在匹配的$4\times7$ LIBERO-Plus评估中(每方法10,030次试验),成功率从69.5%升至73.1%(+362次成功;95%置信区间1.89–5.45点),在六种扰动轴和四套测试中全面改进。在搭载冻结 exttt{pizerofive}检查点的物理PiPER机械臂上,成功率从52.7%提升至78.7%(每方法150次试验,p=3.16×10⁻⁶)。提示权限对冻结控制器可强制执行;无监督准入校准是下一部署目标。

原文摘要 · Abstract (English)

Retrieval can efficiently and effectively augment a frozen vision--language--action (VLA) policy without retraining, yet retrieved text becomes a control intervention once it enters the executed prompt. In a matched audit, raw appended text reduces mean success from 92.47\% to 3.00\%, while meaningful and length-matched meaningless appends both fail on all 500 states. This result identifies \emph{prompt-form collapse}: changing the instruction form, rather than adding useful semantics, can dominate execution. We introduce TOWN-VLA (Think Only When Needed), a prompt-authority interface that separates candidate generation from permission to alter the policy input. A fixed compatibility rule authorizes a canonical compact instruction; otherwise, the interface restores the original Base prompt exactly. Across 900 audited routes, every route follows this contract: 525 routes recover Base with matching hashes, and all 375 authorized prompts preserve the task signature. On a matched $4\times7$ LIBERO-Plus evaluation with 10{,}030 episodes per method, success rises from 69.5\% to 73.1\% ($+362$ episodes; 95\% CI 1.89--5.45 points), improving on six perturbation axes and all four suites. On a physical PiPER arm with a frozen \pizerofive{} checkpoint, success rises from 52.7\% to 78.7\% over 150 trials per method ($p=3.16\times10^{-6}$). Prompt authority is enforceable for a frozen controller; oracle-free admission calibration is the next deployment target.

视觉语言强化学习模型安全机器人控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。