{"id":"https://openalex.org/W7160846391","doi":"https://doi.org/10.48550/arxiv.2605.07088","title":"Membership Inference Attacks on Vision-Language-Action Models","display_name":"Membership Inference Attacks on Vision-Language-Action Models","publication_year":2026,"publication_date":"2026-05-08","ids":{"openalex":"https://openalex.org/W7160846391","doi":"https://doi.org/10.48550/arxiv.2605.07088"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.07088","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.07088","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.07088","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5135847145","display_name":"Yuefeng Peng","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Peng, Yuefeng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135892174","display_name":"Mingzhe Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Mingzhe","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5119181802","display_name":"Kejing Xia","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xia, Kejing","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135837935","display_name":"Renhao Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Renhao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5135833408","display_name":"Amir Houmansadr","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Houmansadr, Amir","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.4562999904155731,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.4562999904155731,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.3172999918460846,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.03819999843835831,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7856000065803528},{"id":"https://openalex.org/keywords/embodied-cognition","display_name":"Embodied cognition","score":0.7390999794006348},{"id":"https://openalex.org/keywords/action","display_name":"Action (physics)","score":0.7373999953269958},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.6549999713897705},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.38989999890327454},{"id":"https://openalex.org/keywords/defeasible-estate","display_name":"Defeasible estate","score":0.36469998955726624}],"concepts":[{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7856000065803528},{"id":"https://openalex.org/C100609095","wikidata":"https://www.wikidata.org/wiki/Q1335050","display_name":"Embodied cognition","level":2,"score":0.7390999794006348},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.7373999953269958},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6674000024795532},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.6549999713897705},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.45350000262260437},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4131999909877777},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.38989999890327454},{"id":"https://openalex.org/C193856179","wikidata":"https://www.wikidata.org/wiki/Q5251100","display_name":"Defeasible estate","level":2,"score":0.36469998955726624},{"id":"https://openalex.org/C81917197","wikidata":"https://www.wikidata.org/wiki/Q628760","display_name":"Selection (genetic algorithm)","level":2,"score":0.3393999934196472},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.33809998631477356},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3276999890804291},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.29649999737739563},{"id":"https://openalex.org/C2776576444","wikidata":"https://www.wikidata.org/wiki/Q303569","display_name":"Attack surface","level":2,"score":0.27799999713897705},{"id":"https://openalex.org/C166109690","wikidata":"https://www.wikidata.org/wiki/Q4677422","display_name":"Action selection","level":3,"score":0.2653999924659729},{"id":"https://openalex.org/C104114177","wikidata":"https://www.wikidata.org/wiki/Q79782","display_name":"Motion (physics)","level":2,"score":0.26010000705718994},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2547000050544739}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.07088","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.07088","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.07088","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.07088","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7499226927757263}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Membership":[0],"inference":[1,105,111,118,174],"attacks":[2,140,171,188],"(MIAs)":[3],"have":[4],"been":[5],"extensively":[6],"studied":[7],"in":[8,35,215],"large":[9],"language":[10],"models":[11,15,23,28,179],"(LLMs)":[12],"and":[13,33,54,58,69,78,116,150,158,166,217,220,228],"vision-language":[14],"(VLMs),":[16],"yet":[17],"their":[18],"implications":[19],"for":[20,43,84,107,202,224,230],"vision-language-action":[21],"(VLA)":[22],"remain":[24],"largely":[25],"unexplored.":[26],"VLA":[27,99,108,164,168,178,231],"differ":[29],"from":[30],"standard":[31],"LLMs":[32],"VLMs":[34],"several":[36],"important":[37],"ways:":[38],"they":[39],"are":[40,180],"often":[41],"fine-tuned":[42],"many":[44],"epochs":[45],"on":[46,191],"relatively":[47],"small":[48],"embodied":[49,121,204,218],"datasets,":[50],"operate":[51],"over":[52,112,119],"constrained":[53],"structured":[55],"action":[56,60,156],"spaces,":[57],"expose":[59],"outputs":[61],"that":[62,177],"can":[63],"be":[64],"observed":[65],"as":[66,147,154],"executable":[67],"behaviors":[68],"temporally":[70],"correlated":[71],"trajectories.":[72],"These":[73],"characteristics":[74],"suggest":[75],"a":[76,126,198,210],"distinct":[77],"potentially":[79],"more":[80],"informative":[81],"attack":[82,129],"surface":[83],"membership":[85,104,184],"inference.":[86,185],"In":[87],"this":[88],"work,":[89],"we":[90],"present":[91],"the":[92,222],"first":[93],"systematic":[94],"study":[95],"of":[96,128],"MIAs":[97],"against":[98],"systems.":[100,206],"We":[101,123],"formalize":[102],"two":[103],"settings":[106],"models:":[109],"sample-level":[110],"individual":[113],"transition":[114],"samples":[115],"trajectory-level":[117],"complete":[120],"demonstrations.":[122],"further":[124],"develop":[125],"suite":[127],"methods":[130],"under":[131],"multiple":[132,163],"access":[133],"regimes,":[134],"including":[135],"strict":[136],"black-box":[137,187],"access.":[138],"Our":[139,207],"exploit":[141],"both":[142],"classic":[143],"MIA":[144],"signals,":[145,152],"such":[146,153],"token":[148],"likelihood,":[149],"VLA-specific":[151],"observable":[155],"errors":[157],"temporal":[159],"motion":[160],"patterns.":[161],"Across":[162],"benchmarks":[165],"representative":[167],"models,":[169],"these":[170],"achieve":[172,194],"strong":[173,195],"performance,":[175,196],"showing":[176],"highly":[181],"vulnerable":[182],"to":[183],"Notably,":[186],"based":[189],"only":[190],"generated":[192],"actions":[193],"highlighting":[197],"practical":[199],"privacy":[200,213,226],"risk":[201,214],"deployed":[203],"AI":[205],"findings":[208],"reveal":[209],"previously":[211],"underexplored":[212],"robotic":[216],"AI,":[219],"underscore":[221],"need":[223],"dedicated":[225],"evaluation":[227],"defenses":[229],"models.":[232]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-12T00:00:00"}
