日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
VLAarXiv:2609.19669

パッチ除去後も持続する視覚言語行動ポリシーへの敵対的影響

Beyond Patch Removal: Persistent Adversarial Effects in Vision-Language-Action Policies

シェア:XThreadsFacebookLINEはてブBluesky

VLAポリシーへの敵対的パッチが除去後も持続する状態効果を引き起こすことを示し、状態復元プロトコルで即時影響と持続影響を分離して評価した。

詳しい要約

1. どんなもの?

- Vision-Language-Action (VLA) policies に対する adversarial patch の効果を、patch 除去後も持続する状態効果と即時の行動汚染に分離して評価する研究。 - state-restoration protocol を導入し、action-chunk 境界で patch を除去し、同じ残り step 予算で recoverability を測定。 - OpenVLA-OFT と LIBERO-Long で EDPA attacks を用い、持続効果を確認。 - autoregressive OpenVLA でも同様の持続効果を観察。 - recovery adapter の有効性と介入遅延の影響も評価。

2. 先行研究と比べてどこがすごい?

- 既存評価は主に連続攻撃に焦点を当て、即時行動汚染と持続状態効果を分離していなかった。 - 本研究は state-restoration protocol により patch 除去後の recoverability を測定し、両効果を分離。 - Clean, random-patch, deviation-matched, fixed-direction controls を導入し、occlusion, action-error magnitude, directional persistence と adversarial effects を区別。 - これにより adversarial patch の持続的影響を定量的に示した点が新しい。

3. 技術・手法の肝は?

- state-restoration protocol: action-chunk 境界で patch を除去し、同じ残り step 予算で recoverability を測定。 - 4つの control 条件: Clean, random-patch, deviation-matched, fixed-direction を比較。 - EDPA attacks を OpenVLA-OFT と LIBERO-Long に適用。 - autoregressive OpenVLA でも同様の評価を実施。 - recovery adapter を attack-induced states で訓練し、介入遅延を制御して評価。

4. どうやって有効だと検証した?

- OpenVLA-OFT with EDPA attacks で、5 chunks 後の LIBERO-Long エピソードの recoverable 率を測定。 - 結果: adversarial 36.2% vs deviation-matched 89.9% vs fixed-direction 87.0%。 - autoregressive OpenVLA でも同様の持続効果を確認。 - recovery adapter は one-chunk latency で recovery を 7.7% から 47.4% に改善。 - 介入遅延が大きくなると benefit が大幅に減少することを示した。

5. 議論はある?

- adversarial effects は patch 除去後も持続し得ることを示唆。 - 回復には timely intervention が critical であると議論。 - recovery adapter の benefit は遅延介入で減少するため、介入タイミングの重要性を強調。 - 限界や今後の課題は要旨からは不明。

6. 次に読むべき論文は?

- EDPA attacks (要旨で参照) - OpenVLA-OFT (要旨で参照) - OpenVLA (要旨で参照) - LIBERO-Long (要旨で参照) - Vision-Language-Action (VLA) policies の adversarial robustness に関する研究 - action-chunk 境界や state-restoration を用いた評価手法

※ AIが要旨から生成した要約です。正確性は原文をご確認ください。

著者: Enhao Wu, Fusen Guo, Yuxin Cao, Ziyang Lyu, Lin Li, Wei Song

分類: cs.CV, cs.RO

原文アブストラクト

Adversarial patches to Vision-Language-Action (VLA) policies can cause both immediate action corruption and persistent state effects that remain after the patch is removed. Existing evaluations largely focus on continuous attacks and do not separate these two effects. We introduce a state-restoration protocol that removes the patch at matched action-chunk boundaries and measures subsequent recoverability under the same remaining step budget. Clean, random-patch, deviation-matched, and fixed-direction controls distinguish adversarial effects from occlusion, action-error magnitude, and directional persistence. We also evaluate a recovery adapter trained on attack-induced states under controlled intervention latency. On OpenVLA-OFT with EDPA attacks, only 36.2% of LIBERO-Long episodes remain recoverable after five chunks, compared with 89.9% and 87.0% for the deviation-matched and fixed-direction controls. Similar persistent effects are observed on autoregressive OpenVLA. The recovery adapter improves recovery from 7.7% to 47.4% at one-chunk latency, but its benefit decreases substantially with delayed intervention. These results show that adversarial effects can persist after patch removal and that timely intervention is critical for recovery.

関連論文

PR本紙発行元 EmplifAI