{"id":"https://openalex.org/W4404649934","doi":"https://doi.org/10.1109/iccv51701.2025.00653","title":"Exploring the Adversarial Vulnerabilities of Vision-Language-Action Models in Robotics","display_name":"Exploring the Adversarial Vulnerabilities of Vision-Language-Action Models in Robotics","publication_year":2025,"publication_date":"2025-10-19","ids":{"openalex":"https://openalex.org/W4404649934","doi":"https://doi.org/10.1109/iccv51701.2025.00653"},"language":"en","primary_location":{"id":"doi:10.1109/iccv51701.2025.00653","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccv51701.2025.00653","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF International Conference on Computer Vision (ICCV)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2411.13587","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5004291226","display_name":"Taowen Wang","orcid":"https://orcid.org/0000-0002-1377-895X"},"institutions":[{"id":"https://openalex.org/I155173764","display_name":"Rochester Institute of Technology","ror":"https://ror.org/00v4yb702","country_code":"US","type":"education","lineage":["https://openalex.org/I155173764"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Taowen Wang","raw_affiliation_strings":["Rochester Institute of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Rochester Institute of Technology","institution_ids":["https://openalex.org/I155173764"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100325126","display_name":"Cheng Han","orcid":"https://orcid.org/0000-0002-8145-3436"},"institutions":[{"id":"https://openalex.org/I75421653","display_name":"University of Missouri\u2013Kansas City","ror":"https://ror.org/01w0d5g70","country_code":"US","type":"education","lineage":["https://openalex.org/I75421653"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Cheng Han","raw_affiliation_strings":["University of Missouri - Kansas City"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Missouri - Kansas City","institution_ids":["https://openalex.org/I75421653"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108252559","display_name":"Jung-Chin Liang","orcid":null},"institutions":[{"id":"https://openalex.org/I1288214837","display_name":"United States Naval Research Laboratory","ror":"https://ror.org/04d23a975","country_code":"US","type":"facility","lineage":["https://openalex.org/I1288214837","https://openalex.org/I1330347796","https://openalex.org/I175003984","https://openalex.org/I3130687028"]},{"id":"https://openalex.org/I4399598358","display_name":"United States Navy","ror":"https://ror.org/03cs53d16","country_code":"US","type":"government","lineage":["https://openalex.org/I1330347796","https://openalex.org/I3130687028","https://openalex.org/I4399598358"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"James Liang","raw_affiliation_strings":["U.S. Naval Research Laboratory"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"U.S. Naval Research Laboratory","institution_ids":["https://openalex.org/I1288214837","https://openalex.org/I4399598358"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103088456","display_name":"Wenhao Yang","orcid":"https://orcid.org/0009-0008-5103-4928"},"institutions":[{"id":"https://openalex.org/I177898655","display_name":"Lamar University","ror":"https://ror.org/008ms5s18","country_code":"US","type":"education","lineage":["https://openalex.org/I177898655"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Wenhao Yang","raw_affiliation_strings":["Lamar University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Lamar University","institution_ids":["https://openalex.org/I177898655"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101979291","display_name":"Dongfang Liu","orcid":"https://orcid.org/0000-0002-7295-8088"},"institutions":[{"id":"https://openalex.org/I155173764","display_name":"Rochester Institute of Technology","ror":"https://ror.org/00v4yb702","country_code":"US","type":"education","lineage":["https://openalex.org/I155173764"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dongfang Liu","raw_affiliation_strings":["Rochester Institute of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Rochester Institute of Technology","institution_ids":["https://openalex.org/I155173764"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Luna Xinyu Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I155173764","display_name":"Rochester Institute of Technology","ror":"https://ror.org/00v4yb702","country_code":"US","type":"education","lineage":["https://openalex.org/I155173764"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Luna Xinyu Zhang","raw_affiliation_strings":["Rochester Institute of Technology"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Rochester Institute of Technology","institution_ids":["https://openalex.org/I155173764"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101774659","display_name":"Qifan Wang","orcid":"https://orcid.org/0000-0002-7570-5756"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qifan Wang","raw_affiliation_strings":["Meta AI"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Meta AI","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055469774","display_name":"Jiebo Luo","orcid":"https://orcid.org/0000-0002-4516-9729"},"institutions":[{"id":"https://openalex.org/I5388228","display_name":"University of Rochester","ror":"https://ror.org/022kthw22","country_code":"US","type":"education","lineage":["https://openalex.org/I5388228"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jiebo Luo","raw_affiliation_strings":["University of Rochester"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Rochester","institution_ids":["https://openalex.org/I5388228"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101660251","display_name":"Ruixiang Tang","orcid":"https://orcid.org/0000-0001-6476-2336"},"institutions":[{"id":"https://openalex.org/I4210096112","display_name":"Rutgers Sexual and Reproductive Health and Rights","ror":"https://ror.org/00rcvgx40","country_code":"NL","type":"other","lineage":["https://openalex.org/I4210096112"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Ruixiang Tang","raw_affiliation_strings":["Rutgers University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Rutgers University","institution_ids":["https://openalex.org/I4210096112"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5004291226"],"corresponding_institution_ids":["https://openalex.org/I155173764"],"apc_list":null,"apc_paid":null,"fwci":2.0398,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.86280083,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"6948","last_page":"6958"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7398216724395752},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6644152998924255},{"id":"https://openalex.org/keywords/action","display_name":"Action (physics)","score":0.6425290703773499},{"id":"https://openalex.org/keywords/robotics","display_name":"Robotics","score":0.5616776347160339},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5266427993774414},{"id":"https://openalex.org/keywords/cognitive-science","display_name":"Cognitive science","score":0.38547295331954956},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.33255890011787415},{"id":"https://openalex.org/keywords/robot","display_name":"Robot","score":0.2545265555381775},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.24312156438827515}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7398216724395752},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6644152998924255},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.6425290703773499},{"id":"https://openalex.org/C34413123","wikidata":"https://www.wikidata.org/wiki/Q170978","display_name":"Robotics","level":3,"score":0.5616776347160339},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5266427993774414},{"id":"https://openalex.org/C188147891","wikidata":"https://www.wikidata.org/wiki/Q147638","display_name":"Cognitive science","level":1,"score":0.38547295331954956},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.33255890011787415},{"id":"https://openalex.org/C90509273","wikidata":"https://www.wikidata.org/wiki/Q11012","display_name":"Robot","level":2,"score":0.2545265555381775},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.24312156438827515},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/iccv51701.2025.00653","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iccv51701.2025.00653","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF International Conference on Computer Vision (ICCV)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2411.13587","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2411.13587","pdf_url":"https://arxiv.org/pdf/2411.13587","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2411.13587","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2411.13587","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2411.13587","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2411.13587","pdf_url":"https://arxiv.org/pdf/2411.13587","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1533466681","display_name":null,"funder_award_id":"2450068,2242243","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G377155036","display_name":null,"funder_award_id":"2242243","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320337345","display_name":"Office of Naval Research","ror":"https://ror.org/00rk2pe57"},{"id":"https://openalex.org/F4320337628","display_name":"U.S. Naval Research Laboratory","ror":"https://ror.org/04d23a975"}],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4404649934.pdf"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W4288019534"],"abstract_inverted_index":{"Recently":[0],"in":[1,113,125,146],"robotics,":[2],"Vision-Language-Action":[3],"(VLA)":[4],"models":[5,34],"have":[6],"emerged":[7],"as":[8],"a":[9,82,101,122,132,136],"transformative":[10],"approach,":[11],"enabling":[12],"robots":[13],"to":[14,77,131,182],"execute":[15],"complex":[16],"tasks":[17],"by":[18],"integrating":[19],"visual":[20],"and":[21,59,81,116,154,164],"linguistic":[22],"inputs":[23],"within":[24,105],"an":[25,94],"end-to-end":[26],"learning":[27],"framework.":[28],"Despite":[29],"their":[30,43],"significant":[31],"capabilities,":[32],"VLA":[33,148],"introduce":[35,68],"new":[36],"attack":[37,53,71,84,112],"surfaces.":[38],"This":[39],"paper":[40],"systematically":[41],"evaluates":[42],"robustness.":[44],"Recognizing":[45],"the":[46,56,88,106,111,162,173],"unique":[47],"demands":[48],"of":[49,62,138,166],"robotic":[50,63,79,89,140,170],"execution,":[51],"our":[52],"objectives":[54,72],"target":[55],"inherent":[57],"spatial":[58,75],"functional":[60],"characteristics":[61],"systems.":[64],"In":[65],"particular,":[66],"we":[67,92,159],"two":[69],"untargeted":[70],"that":[73,86,99],"leverage":[74],"foundations":[76],"destabilize":[78],"actions,":[80],"targeted":[83],"objective":[85],"manipulates":[87],"trajectory.":[90],"Additionally,":[91],"design":[93],"adversarial":[95],"patch":[96,104],"generation":[97],"approach":[98],"places":[100],"small,":[102],"colorful":[103],"camera's":[107],"view,":[108],"effectively":[109],"executing":[110],"both":[114,161],"digital":[115],"physical":[117],"environments.":[118],"Our":[119],"evaluation":[120,157],"reveals":[121],"marked":[123],"degradation":[124],"task":[126],"success":[127],"rates,":[128],"with":[129],"up":[130],"100\\%":[133],"reduction":[134],"across":[135],"suite":[137],"simulated":[139],"tasks,":[141],"highlighting":[142],"critical":[143],"security":[144],"gaps":[145],"current":[147],"architectures.":[149],"By":[150],"unveiling":[151],"these":[152],"vulnerabilities":[153],"proposing":[155],"actionable":[156],"metrics,":[158],"advance":[160],"understanding":[163],"enhancement":[165],"safety":[167],"for":[168,175],"VLA-based":[169],"systems,":[171],"underscoring":[172],"necessity":[174],"continuously":[176],"developing":[177],"robust":[178],"defense":[179],"strategies":[180],"prior":[181],"physical-world":[183],"deployments.":[184]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-05-06T06:03:25.996018","created_date":"2025-10-10T00:00:00"}
