FreezeVLA: Action-Freezing Attacks against Vision-Language-Action Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Xin, Li, Jie, Weng, Zejia, Wang, Yixu, Gao, Yifeng, Pang, Tianyu, Du, Chao, Teng, Yan, Wang, Yingchun, Wu, Zuxuan, Ma, Xingjun, Jiang, Yu-Gang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918147173384192
author Wang, Xin
Li, Jie
Weng, Zejia
Wang, Yixu
Gao, Yifeng
Pang, Tianyu
Du, Chao
Teng, Yan
Wang, Yingchun
Wu, Zuxuan
Ma, Xingjun
Jiang, Yu-Gang
author_facet Wang, Xin
Li, Jie
Weng, Zejia
Wang, Yixu
Gao, Yifeng
Pang, Tianyu
Du, Chao
Teng, Yan
Wang, Yingchun
Wu, Zuxuan
Ma, Xingjun
Jiang, Yu-Gang
contents Vision-Language-Action (VLA) models are driving rapid progress in robotics by enabling agents to interpret multimodal inputs and execute complex, long-horizon tasks. However, their safety and robustness against adversarial attacks remain largely underexplored. In this work, we identify and formalize a critical adversarial vulnerability in which adversarial images can "freeze" VLA models and cause them to ignore subsequent instructions. This threat effectively disconnects the robot's digital mind from its physical actions, potentially inducing inaction during critical interventions. To systematically study this vulnerability, we propose FreezeVLA, a novel attack framework that generates and evaluates action-freezing attacks via min-max bi-level optimization. Experiments on three state-of-the-art VLA models and four robotic benchmarks show that FreezeVLA attains an average attack success rate of 76.2%, significantly outperforming existing methods. Moreover, adversarial images generated by FreezeVLA exhibit strong transferability, with a single image reliably inducing paralysis across diverse language prompts. Our findings expose a critical safety risk in VLA models and highlight the urgent need for robust defense mechanisms.
format Preprint
id arxiv_https___arxiv_org_abs_2509_19870
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle FreezeVLA: Action-Freezing Attacks against Vision-Language-Action Models
Wang, Xin
Li, Jie
Weng, Zejia
Wang, Yixu
Gao, Yifeng
Pang, Tianyu
Du, Chao
Teng, Yan
Wang, Yingchun
Wu, Zuxuan
Ma, Xingjun
Jiang, Yu-Gang
Computer Vision and Pattern Recognition
Vision-Language-Action (VLA) models are driving rapid progress in robotics by enabling agents to interpret multimodal inputs and execute complex, long-horizon tasks. However, their safety and robustness against adversarial attacks remain largely underexplored. In this work, we identify and formalize a critical adversarial vulnerability in which adversarial images can "freeze" VLA models and cause them to ignore subsequent instructions. This threat effectively disconnects the robot's digital mind from its physical actions, potentially inducing inaction during critical interventions. To systematically study this vulnerability, we propose FreezeVLA, a novel attack framework that generates and evaluates action-freezing attacks via min-max bi-level optimization. Experiments on three state-of-the-art VLA models and four robotic benchmarks show that FreezeVLA attains an average attack success rate of 76.2%, significantly outperforming existing methods. Moreover, adversarial images generated by FreezeVLA exhibit strong transferability, with a single image reliably inducing paralysis across diverse language prompts. Our findings expose a critical safety risk in VLA models and highlight the urgent need for robust defense mechanisms.
title FreezeVLA: Action-Freezing Attacks against Vision-Language-Action Models
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2509.19870