arXiv Machine Learning

Median Temporal Ensembling: Training-Free Robust Aggregation for Action-Chunked Visuomotor Policies

The paper introduces Median Temporal Ensembling, a training‑free aggregation method for action‑chunked visuomotor policies that replaces the standard exponential weighted mean with a coordinate‑wise median. This approach remains robust against adversarial corruption, maintaining a high recovery rate even as attack strength increases, and performs at least as well as the mean across numerous configurations while improving in many cases. It also handles non‑adversarial failures such as blank camera frames and shows limited impact on clean data, though it cannot counteract uniform shifts applied to all predictions.

arXiv Machine Learning
Sep 23

Margin-Drop Coordinates for Cross-Budget Robustness Evaluation

arXiv:2609.26081v1 Announce Type: new Abstract: Fixed-budget robustness evaluation can select the wrong frozen vision encoder. An encoder that survives a shallow attack may lose most of that robustne...

By Yanliang Huang, Zhen Zhang, Peng Xie, Wenyuan Wu, Sitong Zhu, Zhuoqi Zeng, Amr Alanwar
arXiv Machine Learning
Sep 11

DriftNet: A Dual-Head Trajectory Transformer for Detecting and Localizing Prompt Injection in LLM Agents

DriftNet is a dual‑head trajectory Transformer designed to detect and localize prompt injection attacks in large language model agents. It processes logged tool‑call trajectories, classifying each as compromised or not while labeling every step as benign, injection point, hijacked, or failed injection. On the AgentDrift benchmark, DriftNet achieves high accuracy, with an F1 score of 0.983, 98.7% exact injection‑point recovery, and low false‑alarm rates.

By Asif Pinjari, Mithun Paul Saint-Germain
arXiv Computer Vision
Sep 22

Algebraic Consistency Alone Does Not Certify Temporal Structure in Latent Action Models

The paper examines latent action models that encode transitions between video frames using algebraic constraints such as additive composition and antisymmetric reversal. It demonstrates that these algebraic consistency conditions do not reliably certify temporal structure, as unconstrained models can achieve similar error reductions and constrained models still outperform unconstrained ones even after temporal pairings are destroyed. The authors find that preserving temporal pairing offers no consistent advantage on downstream tasks and that a direct repair objective yields only marginal improvement, recommending a more rigorous validation protocol.

By Di Wen, Ruodi Zhang, Kailun Yang, Kunyu Peng
arXiv Machine Learning
Aug 10

Corrupting Attention: Evasion-Based Adversarial Attacks on Encoder Attention in Detection Transformers

arXiv:2608. 06674v1 Announce Type: cross Abstract: Adversarial vulnerabilities remain a major concern for the safe deployment of neural networks, particularly in object detection, a core task embedded in many safety-critical systems.

By Ridma Jayasundara, Shaheer Mohamed, Tharindu Fernando, Harshala Gammulle, Basura Fernando, Sanka Rasnayake, A V Subramanyam, Sridha Sridharan, Clinton Fookes
Hugging Face Trending Papers
Sep 17

Beyond Patch Removal: Persistent Adversarial Effects in Vision-Language-Action Policies

The paper investigates how adversarial patches affect Vision‑Language‑Action (VLA) policies, revealing that such patches can cause immediate action corruption and persistent state effects that linger after the patch is removed. A state‑restoration protocol is introduced to isolate these effects by removing the patch at action‑chunk boundaries and measuring recoverability within the remaining step budget. Experiments on OpenVLA-OFT with EDPA attacks show that only 36.2% of episodes recover after five chunks, whereas controls recover at 89.9% and 87.0%. A recovery adapter trained on attack‑induced states improves recovery from 7.7% to 47.4% at one‑chunk latency, but its effectiveness drops sharply with delayed intervention, underscoring the importance of timely recovery.