Black-Box Adversarial Patch Attacks on VLAs via Ancestor VLM Exploitation
cs.CR
Submitted: 2026-10-07
Updated: 2026-10-07
Terminology
Sources
- PaliGemma: A versatile 3B VLM for transfer
- $\pi_0$: A Vision-Language-Action Flow Model for General Robot Control
- UniVLA: Learning to Act Anywhere with Task-centric Latent Actions
- WorldVLA: Towards Autoregressive Action World Model
- VLA-Hijack: A Transferable Patch Attack against Vision-Language-Action Models via Visual Proprioception Hijacking
- TRAP: Hijacking VLA CoT-Reasoning via Adversarial Patches
- $\pi_{0.5}$: a Vision-Language-Action Model with Open-World Generalization
- Adversarial Attacks on Robotic Vision Language Action Models
- Prismatic VLMs: Investigating the Design Space of Visually-Conditioned Language Models
- OpenVLA: An Open-Source Vision-Language-Action Model
- CognitiveDrone: A VLA Model and Evaluation Benchmark for Real-Time Cognitive Task Solving and Reasoning in UAVs
- FAST: Efficient Action Tokenization for Vision-Language-Action Models
- SpatialVLA: Exploring Spatial Representations for Visual-Language-Action Model
- FreezeVLA: Action-Freezing Attacks against Vision-Language-Action Models
- Model-agnostic Adversarial Attack and Defense for Vision-Language-Action Models
- When Alignment Fails: Multimodal Adversarial Attacks on Vision-Language-Action Models
- Attention-Guided Patch-Wise Sparse Adversarial Attacks on Vision-Language-Action Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs