arXiv AI By Hui Lu, Zhijie Peng, Yuqi Lin, Zaijia Yang, Jiaming He, Shuhan Ye, Yi Yu, Hanwei Zhu, Bingquan Shen, Alex Kot, Xudong Jiang

CertVLA: Certified Defense against Physical Visual Attacks for Vision-Language-Action Models

Read the original on arXiv AI →

CertVLA is a certified defense for Vision‑Language‑Action (VLA) models that protects closed‑loop control against bounded patch and texture attacks. It calibrates a region of behaviorally consistent actions and uses deterministic covering masks to guarantee at least one attack‑free prediction, normalizing action disagreement by benign variation and accepting only consistent single‑mask anchors. The method provides finite‑sample clean coverage, extends the certificate to full rollouts, and proves that certified rollouts execute only action chunks consistent with clean predictions, ensuring task success regardless of patch content or physical transformation.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

Hugging Face Trending Papers
Sep 17

Beyond Patch Removal: Persistent Adversarial Effects in Vision-Language-Action Policies

The paper investigates how adversarial patches affect Vision‑Language‑Action (VLA) policies, revealing that such patches can cause immediate action corruption and persistent state effects that linger after the patch is removed. A state‑restoration protocol is introduced to isolate these effects by removing the patch at action‑chunk boundaries and measuring recoverability within the remaining step budget. Experiments on OpenVLA-OFT with EDPA attacks show that only 36.2% of episodes recover after five chunks, whereas controls recover at 89.9% and 87.0%. A recovery adapter trained on attack‑induced states improves recovery from 7.7% to 47.4% at one‑chunk latency, but its effectiveness drops sharply with delayed intervention, underscoring the importance of timely recovery.

arXiv Computer Vision
Sep 18

Beyond Patch Removal: Persistent Adversarial Effects in Vision-Language-Action Policies

Adversarial patches applied to Vision‑Language‑Action (VLA) policies not only corrupt actions immediately but also leave lasting state effects that persist after the patch is removed. The study introduces a state‑restoration protocol that evaluates recoverability after patch removal, distinguishing true adversarial impact from occlusion or action‑error magnitude. Experiments on OpenVLA‑OFT with EDPA attacks show that only 36.2% of episodes recover after five chunks, while controls recover at much higher rates; a recovery adapter can improve recovery but its effectiveness drops with delayed intervention.

By Enhao Wu, Fusen Guo, Yuxin Cao, Ziyang Lyu, Lin Li, Wei Song
Hugging Face Trending Papers
Jun 24

VPA-Guard: Defending and Benchmarking Image-to-Video Generation Against Visual Prompt Attacks

Recent advancements in Image-to-Video (I2V) generation have transformed input images from simple appearance references into interactive control interfaces where visual cues such as arrows, sketches, and emojis orchestrate complex video dynamics with unprecedented controllability. However, these seemingly innocuous static cues can be interpreted by models as executable temporal instructions, unfolding into harmful actions in the generated videos.