paper-with-me

홈 › Papers

FreezeVLA: Action-Freezing Attacks against Vision-Language-Action Models

2025-09-24 · Xin Wang, Jie Li, Zejia Weng, Yixu Wang, Yifeng Gao, Tianyu Pang, Chao Du, Yan Teng, Yingchun Wang, Zuxuan Wu, Xingjun Ma, Yu-Gang Jiang arxiv

Vision-Language-Action (VLA) models are driving rapid progress in robotics by enabling agents to interpret multimodal inputs and execute complex, long-horizon tasks. However, their safety and robustness against adversarial attacks remain largely underexplored. In this work, we identify and formalize a critical adversarial vulnerability in which adversarial images can "freeze" VLA models and cause them to ignore subsequent instructions. This threat effectively disconnects the robot's digital mind from its physical actions, potentially inducing inaction during critical interventions. To systematically study this vulnerability, we propose FreezeVLA, a novel attack framework that generates and evaluates action-freezing attacks via min-max bi-level optimization. Experiments on three state-of-the-art VLA models and four robotic benchmarks show that FreezeVLA attains an average attack success rate of 76.2%, significantly outperforming existing methods. Moreover, adversarial images generated by FreezeVLA exhibit strong transferability, with a single image reliably inducing paralysis across diverse language prompts. Our findings expose a critical safety risk in VLA models and highlight the urgent need for robust defense mechanisms.

📄 PDF Abstract BibTeX arXiv:2509.19870

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Vision-Language-Action Safety: Threats, Challenges, Evaluations, and Mechanisms

2026-04-26 · Qi Li, Bo Yin, Weiqi Huang, Ruhao Liu 외 arxiv

Vision-Language-Action (VLA) models are emerging as a unified substrate for embodied intelligence. This shift raises a new class of safety challenges, stemming from the embodied nature of VLA systems, including irreversi…

Towards Understanding the Fragility of Multilingual LLMs against Fine-Tuning Attacks

2024-10-23 · Samuele Poppi, Zheng-Xin Yong, Yifei He, Bobbie Chern 외

Recent advancements in Large Language Models (LLMs) have sparked widespread concerns about their safety. Recent work demonstrates that safety alignment of LLMs can be easily removed by fine-tuning with a few adversariall…

Instruction FollowingSafety Alignment

CertVLA: Certified Defense against Physical Visual Attacks for Vision-Language-Action Models

2026-08-21 · Hui Lu, Zhijie Peng, Yuqi Lin, Zaijia Yang 외 arxiv

Vision-Language-Action (VLA) policies are vulnerable to localized physical perturbations, yet existing certified patch defenses target discrete labels and cannot directly certify continuous, temporally correlated actions…

TransMIA: Membership Inference Attacks Using Transfer Shadow Training

2020-11-30 · Seira Hidano, Takao Murakami, Yusuke Kawamoto

Transfer learning has been widely studied and gained increasing popularity to improve the accuracy of machine learning models by transferring some knowledge acquired in different training. However, no prior work has poin…

BIG-bench Machine LearningTransfer Learning

DivQAT: Enhancing Robustness of Quantized Convolutional Neural Networks against Model Extraction Attacks

2025-12-30 · Kacem Khaled, Felipe Gohring de Magalhães, Gabriela Nicolescu arxiv

Convolutional Neural Networks (CNNs) and their quantized counterparts are vulnerable to extraction attacks, posing a significant threat of IP theft. Yet, the robustness of quantized models against these attacks is little…

Model extraction