🤖 AI Summary
This study addresses the safety vulnerabilities of Vision-Language-Action (VLA) models during physical interactions by proposing a universal adversarial object attack. By optimizing textures to disrupt visual perception, the method compromises trajectory planning and execution. To our knowledge, this work introduces the first multi-level joint attack framework that integrates adversarial example generation, end-to-end learning, and simulation-to-reality validation to achieve cross-scenario universality. Experimental results demonstrate that the proposed attack reduces the task success rates of the Pi0 and RDT models by 31.2% to 39.9%, driving performance to near zero in complex scenarios. These findings reveal severe security threats confronting current VLA models and underscore the urgent need for more robust defenses in embodied AI systems.
📝 Abstract
Recently, Vision-Language-Action (VLA) models have revolutionized robotic manipulation by seamlessly integrating visual perception, language understanding, and action generation in an end-to-end learning framework. However, since these models are designed to interact directly with the physical world and humans, their security is critical, and even small vulnerabilities can lead to catastrophic failures. In this work, we propose the Universal Adversarial Object, a sphere with optimized surface texture that significantly degrades task success rates when placed within the robot's field of view. Specifically, our approach introduces a multi-level attack framework that jointly disrupts trajectory planning, task execution, and action control. We validate our method in both simulated and real-world robotic settings. Experimental results demonstrate that the adversarial object reduces the average task success rates by 31.2%-39.9% for two representative VLA models (Pi0 and RDT), with success rates dropping to near zero in complex scenarios. Index Terms--Vision-Language-Action models, adversarial attack, robotic security, universal adversarial object