{"id":"https://openalex.org/W7156621071","doi":"https://doi.org/10.48550/arxiv.2604.23775","title":"Vision-Language-Action Safety: Threats, Challenges, Evaluations, and Mechanisms","display_name":"Vision-Language-Action Safety: Threats, Challenges, Evaluations, and Mechanisms","publication_year":2026,"publication_date":"2026-04-26","ids":{"openalex":"https://openalex.org/W7156621071","doi":"https://doi.org/10.48550/arxiv.2604.23775"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.23775","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23775","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.23775","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5134766513","display_name":"Qi Li","orcid":"https://orcid.org/0009-0000-1094-8995"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Qi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124951309","display_name":"Bo Yin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yin, Bo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134820622","display_name":"Weiqi Huang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Huang, Weiqi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5132766988","display_name":"Ruhao Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Ruhao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134808857","display_name":"Bojun Zou","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zou, Bojun","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134793944","display_name":"Runpeng Yu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yu, Runpeng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134760167","display_name":"Jingwen Ye","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ye, Jingwen","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134804420","display_name":"Weihao Yu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yu, Weihao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5134790294","display_name":"Xinchao Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Xinchao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":9,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9553999900817871,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9553999900817871,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.00800000037997961,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.007000000216066837,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6586999893188477},{"id":"https://openalex.org/keywords/embodied-cognition","display_name":"Embodied cognition","score":0.6315000057220459},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.5922999978065491},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5123999714851379},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.492000013589859},{"id":"https://openalex.org/keywords/scope","display_name":"Scope (computer science)","score":0.4749999940395355},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.39340001344680786}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.675000011920929},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6586999893188477},{"id":"https://openalex.org/C100609095","wikidata":"https://www.wikidata.org/wiki/Q1335050","display_name":"Embodied cognition","level":2,"score":0.6315000057220459},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.5922999978065491},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5123999714851379},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.492000013589859},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4830000102519989},{"id":"https://openalex.org/C2778012447","wikidata":"https://www.wikidata.org/wiki/Q1034415","display_name":"Scope (computer science)","level":2,"score":0.4749999940395355},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.39340001344680786},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.36500000953674316},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.36149999499320984},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.3273000121116638},{"id":"https://openalex.org/C46304622","wikidata":"https://www.wikidata.org/wiki/Q374814","display_name":"Certification","level":2,"score":0.3116999864578247},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.3012999892234802},{"id":"https://openalex.org/C90509273","wikidata":"https://www.wikidata.org/wiki/Q11012","display_name":"Robot","level":2,"score":0.2980000078678131},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.28610000014305115},{"id":"https://openalex.org/C105002631","wikidata":"https://www.wikidata.org/wiki/Q4833645","display_name":"Subject-matter expert","level":3,"score":0.27559998631477356}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.23775","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23775","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.23775","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.23775","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.5007146000862122}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-Language-Action":[0,87],"(VLA)":[1],"models":[2],"are":[3],"emerging":[4],"as":[5,173,178,180],"a":[6,15,33,79],"unified":[7,80,229],"substrate":[8],"for":[9,221],"embodied":[10,24,222],"intelligence.":[11],"This":[12,76],"shift":[13],"raises":[14],"new":[16],"class":[17,111],"of":[18,26,84,112,128,145],"safety":[19,85,136,206,231],"challenges,":[20],"stemming":[21],"from":[22,133],"the":[23,55,60,91,115,126,143,158],"nature":[25],"VLA":[27,129,146],"systems,":[28],"including":[29,148,183,218],"irreversible":[30],"physical":[31],"consequences,":[32],"multimodal":[34],"attack":[35,98],"surface":[36],"across":[37,64,208],"vision,":[38],"language,":[39],"and":[40,52,72,81,103,137,141,152,166,176,190,196,202,204,233],"state,":[41],"real-time":[42],"latency":[43],"constraints":[44],"on":[45],"defense,":[46],"error":[47],"propagation":[48],"over":[49],"long-horizon":[50],"trajectories,":[51,223],"vulnerabilities":[53],"in":[54,86],"data":[56,174],"supply":[57],"chain.":[58],"Yet":[59],"literature":[61,159],"remains":[62],"fragmented":[63],"robotic":[65,139],"learning,":[66,69],"adversarial":[67,184],"machine":[68],"AI":[70],"alignment,":[71],"autonomous":[73],"systems":[74],"safety.":[75],"survey":[77,169],"provides":[78],"up-to-date":[82],"overview":[83],"models.":[88],"We":[89,123,155,168,193],"organize":[90],"field":[92],"along":[93],"two":[94],"parallel":[95],"timing":[96,99,105],"axes,":[97],"(training-time":[100,106],"vs.":[101,107],"inference-time":[102,181],"defense":[104],"inference-time,":[108],"linking":[109],"each":[110],"threat":[113],"to":[114],"stage":[116],"at":[117],"which":[118],"it":[119,132],"can":[120],"be":[121],"mitigated.":[122],"first":[124],"define":[125],"scope":[127],"safety,":[130,140],"distinguishing":[131],"text-only":[134],"LLM":[135],"classical":[138],"review":[142,194],"foundations":[144],"models,":[147],"architectures,":[149,232],"training":[150],"paradigms,":[151],"inference":[153],"mechanisms.":[154],"then":[156],"examine":[157],"through":[160],"four":[161],"lenses:":[162],"Attacks,":[163],"Defenses,":[164],"Evaluation,":[165],"Deployment.":[167],"training-time":[170,195],"threats":[171],"such":[172],"poisoning":[175],"backdoors,":[177],"well":[179],"attacks":[182],"patches,":[185],"cross-modal":[186],"perturbations,":[187],"semantic":[188],"jailbreaks,":[189],"freezing":[191],"attacks.":[192],"runtime":[197,230],"defenses,":[198,226],"analyze":[199],"existing":[200],"benchmarks":[201],"metrics,":[203],"discuss":[205],"challenges":[207],"six":[209],"deployment":[210],"domains.":[211],"Finally,":[212],"we":[213],"highlight":[214],"key":[215],"open":[216],"problems,":[217],"certified":[219],"robustness":[220],"physically":[224],"realizable":[225],"safety-aware":[227],"training,":[228],"standardized":[234],"evaluation.":[235]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-29T00:00:00"}
