Author

Jiaxing Li

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

Conference Jun 2026

ROCAP: Rollout-Aware and Occlusion-Calibrated Adversarial Patches for VLA

Vision-Language-Action (VLA) models have recently emerged as a promising paradigm for embodied intelligence by unifying perception, language grounding, and action generation in an end-to-end framework. Despite their strong performance, their deployment in physical control loops introduces new security risks: small perturbations to visual inputs can propagate through sequential decision-making and ultimately lead to unsafe or task-failing robot behaviors. In this work, we investigate the vulnerability of VLA models to black-box adversarial patch attacks and propose a patch generation method that explicitly targets closed-loop policy behavior. Our approach combines a rollout-aware objective with an occlusion-calibrated scoring mechanism, enabling the attack to capture trajectory-level degradation while separating genuine adversarial effects from trivial performance drops caused by visual occlusion. We evaluate our method on OpenVLA with the LIBERO benchmark. Experimental results show that our attack consistently degrades task performance, reducing the success rate on LIBERO-Spatial from 81.0% to 74.4% and on LIBERO-Object from 70.4% to 53.0%. These findings highlight the security risks of VLA systems in embodied settings and underscore the need for robustness evaluation and defense mechanisms for safe real-world deployment.

Kaizheng Liu, Yuntao Hu, Jiaxing Li et al. · 0 citations