Exploiting Vulnerabilities: Universal Adversarial Attacks on Vision-Language-Action Models in Robotics
A textured adversarial sphere cuts Pi0 and RDT robot task success by 31.2% to 39.9% in view.
Researchers introduce a Universal Adversarial Object, a sphere with an optimized surface texture, that degrades Vision-Language-Action robot policies when placed in view. A multi-level attack jointly disrupts trajectory planning, task execution, and action control. On Pi0 and RDT, average task success falls by 31.2% to 39.9% in simulation and real robots, and near zero in complex tasks.
- A textured sphere in view is the universal adversarial object.
- The attack disrupts planning, execution, and action control together.
- Pi0 and RDT average success falls 31.2% to 39.9%.
- Complex tasks drop near zero in simulation and on real robots.
Full article152 words · extracted from arxiv.org · click to collapse
Recently, Vision-Language-Action (VLA) models have revolutionized robotic manipulation by seamlessly integrating visual perception, language understanding, and action generation in an end-to-end learning framework. However, since these models are designed to interact directly with the physical world and humans, their security is critical, and even small vulnerabilities can lead to catastrophic failures. In this work, we propose the Universal Adversarial Object, a sphere with optimized surface texture that significantly degrades task success rates when placed within the robot's field of view. Specifically, our approach introduces a multi-level attack framework that jointly disrupts trajectory planning, task execution, and action control. We validate our method in both simulated and real-world robotic settings. Experimental results demonstrate that the adversarial object reduces the average task success rates by 31.2%-39.9% for two representative VLA models (Pi0 and RDT), with success rates dropping to near zero in complex scenarios. Index Terms--Vision-Language-Action models, adversarial attack, robotic security, universal adversarial object
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.39178