学習ベース産業用ロボットアーム操作におけるバックドア:実証的セキュリティ研究
Backdoors in Learning-Based Industrial Robotic Arm Manipulation: An Empirical Security Study
FANUCとxArmの実機で学習ベースロボット操作へのバックドア攻撃を検証し、実行時検知・無効化するオンライン防御を開発して遅延・負荷も評価した。
詳しい要約
1. どんなもの?
2. 先行研究と比べてどこがすごい?
3. 技術・手法の肝は?
4. どうやって有効だと検証した?
5. 議論はある?
6. 次に読むべき論文は?
※ AIが要旨から生成した要約です。正確性は原文をご確認ください。
著者: Zijian Zhang, Zhen Zeng, Zhongshu Gu, Sandeep Pisharody
分類: cs.RO
原文アブストラクト
Learning-based models (e.g., visuomotor and Vision-Language-Action (VLA)) are increasingly explored for industrial robotic manipulation, where model predictions are directly translated into physical actions. This tight coupling between model behavior and physical execution makes hidden security vulnerabilities particularly consequential. While backdoor attacks have been widely studied in conventional AI models, their effects on deployed learning-based robotic arm manipulation systems remain less understood: a backdoored robot can behave normally during benign operation while inducing attacker-specified behaviors only when specific triggers are present, posing potentially serious risks in physical environments. In this work, we present a preliminary empirical security study of backdoor attacks and defenses in learning-based robotic manipulation on two real commercial industrial robotic arms (FANUC and xArm). We investigate whether a backdoor can reliably induce semantically incorrect manipulation behaviors while remaining stealthy under nominal task execution. We then develop an online defense pipeline that detects and neutralizes triggers at runtime, and compare its effectiveness against an offline fine-tuning defense. Beyond defense effectiveness, we further evaluate the computational latency and execution overhead introduced by the defense pipeline to assess its suitability for high-throughput industrial operation.
関連論文
- プロンプトから物理動作へ:LLM搭載ロボットシステムの包括的脅威モデリングロボットセキュリティ
- EU AI法遵守のためのロボティクス・自律システムのサイバーセキュリティ対策ロボットセキュリティ