paper-with-me

홈 › Papers

BadVLA: Towards Backdoor Attacks on Vision-Language-Action Models via Objective-Decoupled Optimization

2025-05-22 · Xueyang Zhou, Guiyao Tie, Guowen Zhang, Hechang Wang, Pan Zhou, Lichao Sun

Vision-Language-Action (VLA) models have advanced robotic control by enabling end-to-end decision-making directly from multimodal inputs. However, their tightly coupled architectures expose novel security vulnerabilities. Unlike traditional adversarial perturbations, backdoor attacks represent a stealthier, persistent, and practically significant threat-particularly under the emerging Training-as-a-Service paradigm-but remain largely unexplored in the context of VLA models. To address this gap, we propose BadVLA, a backdoor attack method based on Objective-Decoupled Optimization, which for the first time exposes the backdoor vulnerabilities of VLA models. Specifically, it consists of a two-stage process: (1) explicit feature-space separation to isolate trigger representations from benign inputs, and (2) conditional control deviations that activate only in the presence of the trigger, while preserving clean-task performance. Empirical results on multiple VLA benchmarks demonstrate that BadVLA consistently achieves near-100% attack success rates with minimal impact on clean task accuracy. Further analyses confirm its robustness against common input perturbations, task transfers, and model fine-tuning, underscoring critical security vulnerabilities in current VLA deployments. Our work offers the first systematic investigation of backdoor vulnerabilities in VLA models, highlighting an urgent need for secure and trustworthy embodied model design practices. We have released the project page at https://badvla-project.github.io/.

📄 PDF Abstract BibTeX arXiv:2505.16640

Code (0)

등록된 구현이 없습니다.

Tasks

Backdoor AttackVision-Language-Action

Similar Papers 제목 키워드 기반

Inject Once Survive Later: Backdooring Vision-Language-Action Models to Persist Through Downstream Fine-tuning

2026-01-31 · Jianyi Zhou, Yujie Wei, Ruichen Zhen, Bo Zhao 외 arxiv

Vision-Language-Action (VLA) models have become foundational to modern embodied AI systems. By integrating visual perception, language understanding, and action planning, they enable general-purpose task execution across…

TrustVLA: Mechanism-Guided Inference-Time Defense Against Vision-Language-Action Backdoors

2026-07-14 · Pinhan Fu, Xianda Guo, Xuetao Li, Wenke Huang 외 arxiv

Vision-Language-Action (VLA) models are deployed through pipelines that end users cannot audit, and a poisoned VLA can behave normally on clean observations while a small visual trigger redirects a long-horizon robot pol…

AttackVLA: Benchmarking Adversarial and Backdoor Attacks on Vision-Language-Action Models

2025-11-15 · Jiayu Li, Yunhan Zhao, Xiang Zheng, Zonghuan Xu 외 arxiv

Vision-Language-Action (VLA) models enable robots to interpret natural-language instructions and perform diverse tasks, yet their integration of perception, language, and control introduces new safety vulnerabilities. De…

Revisiting Backdoor Attacks against Large Vision-Language Models from Domain Shift

2024-06-27 · CVPR 2025 1 · Siyuan Liang, Jiawei Liang, Tianyu Pang, Chao Du 외

Instruction tuning enhances large vision-language models (LVLMs) but increases their vulnerability to backdoor attacks due to their open design. Unlike prior studies in static settings, this paper explores backdoor attac…

Backdoor AttackDomain Generalization

DropVLA: An Action-Level Backdoor Attack on Vision-Language-Action Models

2025-10-13 · Zonghuan Xu, Jiayu Li, Yunhan Zhao, Xiang Zheng 외 arxiv

Vision-Language-Action (VLA) models map multimodal perception and language instructions to executable robot actions, making them particularly vulnerable to behavioral backdoor manipulation: a hidden trigger introduced du…