拿一个贴了纹理的物体就能让 OpenVLA 和 π0.5 的成功率从 90% 掉到 48%,还能跨模型生效,搞机器人安全的可以看看。
UniTexture 是一种针对视觉-语言-动作(VLA)模型的对抗纹理攻击方法,通过单个带纹理的 3D 物体诱导多任务动作预测偏离。该方法利用可微渲染器将策略动作输出的梯度回传到表面纹理参数,跨任务联合优化共享纹理。在 OpenVLA 和 π0.5 上的多任务评估中,UniTexture 将平均任务成功率从良性条件下的 90.0% 降至攻击下的 48.4%。攻击还表现出跨套件和跨模型迁移能力,无需重新优化即可生效。研究揭示了多任务 VLA 中共存的跨任务安全漏洞。
UniTexture: Cross-Task Universal Adversarial Textures for Vision-Language-Action Models
Vision-Language-Action (VLA) models have emerged as generalist robotic policies capable of following diverse language instructions and performing a wide range of manipulation tasks. However, their direct control over embodied agents also exposes them to adversarial interference that may cause unsafe physical behaviors. Existing attacks on robotic policies are typically optimized for a single task or instruction, leaving the cross-task vulnerabilities of multitask VLAs largely unexplored. We introduce UniTexture, a cross-task universal adversarial texture attack that uses a single textured 3D object to induce targeted deviations in VLA action predictions across multiple tasks. UniTexture backpropagates gradients from the policy's action outputs to surface texture parameters through a differentiable renderer. It jointly optimizes the shared texture over a distribution of tasks, instructions, states, and viewpoints using a targeted action-space objective, steering predicted actions toward attacker-defined targets without optimizing a separate texture for each task. We evaluate UniTexture on OpenVLA and $π_{0.5}$ across diverse manipulation tasks and multiple evaluation settings. UniTexture reduces the mean task success rate from 90.0% under benign conditions to 48.4% under attack, induces target-aligned action shifts, and further exhibits cross-suite and cross-model transfer without re-optimization. Together, these findings reveal shared cross-task vulnerabilities in multitask VLAs that can be systematically exploited through a single adversarial surface texture.