TRAP: Hijacking VLA CoT-Reasoning via Adversarial Patches
Fuente:
arXiv
Saved in:
| Main Authors: | Huang, Zhengxian, Zhu, Wenjun, Qiu, Haoxuan, Ji, Xiaoyu, Xu, Wenyuan |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
TPatch: A Triggered Physical Adversarial Patch
by: Zhu, Wenjun, et al.
Published: (2023)
by: Zhu, Wenjun, et al.
Published: (2023)
SLIP: Soft Label Mechanism and Key-Extraction-Guided CoT-based Defense Against Instruction Backdoor in APIs
by: Wu, Zhengxian, et al.
Published: (2025)
by: Wu, Zhengxian, et al.
Published: (2025)
SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band Vulnerabilities
by: Xiao, Shilin, et al.
Published: (2025)
by: Xiao, Shilin, et al.
Published: (2025)
ShadowCoT: Cognitive Hijacking for Stealthy Reasoning Backdoors in LLMs
by: Zhao, Gejian, et al.
Published: (2025)
by: Zhao, Gejian, et al.
Published: (2025)
R-CoT: A Reasoning-Layer Watermark via Redundant Chain-of-Thought in Large Language Models
by: Zhang, Ziming, et al.
Published: (2026)
by: Zhang, Ziming, et al.
Published: (2026)
Reasoning Hijacking: The Fragility of Reasoning Alignment in Large Language Models
by: Liu, Yuansen, et al.
Published: (2026)
by: Liu, Yuansen, et al.
Published: (2026)
CamPro: Camera-based Anti-Facial Recognition
by: Zhu, Wenjun, et al.
Published: (2023)
by: Zhu, Wenjun, et al.
Published: (2023)
Hijacking Large Language Models via Adversarial In-Context Learning
by: Zhou, Xiangyu, et al.
Published: (2023)
by: Zhou, Xiangyu, et al.
Published: (2023)
CoTDeceptor:Adversarial Code Obfuscation Against CoT-Enhanced LLM Code Agents
by: Li, Haoyang, et al.
Published: (2025)
by: Li, Haoyang, et al.
Published: (2025)
AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning Models
by: Liang, Jiacheng, et al.
Published: (2025)
by: Liang, Jiacheng, et al.
Published: (2025)
Unreal Thinking: Chain-of-Thought Hijacking via Two-stage Backdoor
by: Chang, Wenhan, et al.
Published: (2026)
by: Chang, Wenhan, et al.
Published: (2026)
Differentially Private and Communication Efficient Large Language Model Split Inference via Stochastic Quantization and Soft Prompt
by: Gu, Yujie, et al.
Published: (2026)
by: Gu, Yujie, et al.
Published: (2026)
SwitchPatch: Physical Adversarial Attack Strategy with Switchable Adversarial Objectives
by: Jiang, Hanrui, et al.
Published: (2025)
by: Jiang, Hanrui, et al.
Published: (2025)
BeDKD: Backdoor Defense Based on Directional Mapping Module and Adversarial Knowledge Distillation
by: Wu, Zhengxian, et al.
Published: (2025)
by: Wu, Zhengxian, et al.
Published: (2025)
MIP against Agent: Malicious Image Patches Hijacking Multimodal OS Agents
by: Aichberger, Lukas, et al.
Published: (2025)
by: Aichberger, Lukas, et al.
Published: (2025)
ReThink: Reveal the Threat of Electromagnetic Interference on Power Inverters
by: Yang, Fengchen, et al.
Published: (2024)
by: Yang, Fengchen, et al.
Published: (2024)
Moshi Moshi? A Model Selection Hijacking Adversarial Attack
by: Petrucci, Riccardo, et al.
Published: (2025)
by: Petrucci, Riccardo, et al.
Published: (2025)
CAMH: Advancing Model Hijacking Attack in Machine Learning
by: He, Xing, et al.
Published: (2024)
by: He, Xing, et al.
Published: (2024)
Visual CoT Makes VLMs Smarter but More Fragile
by: Xu, Chunxue, et al.
Published: (2025)
by: Xu, Chunxue, et al.
Published: (2025)
CoT-Guard: Small Models for Strong Monitoring
by: Diwan, Nirav, et al.
Published: (2026)
by: Diwan, Nirav, et al.
Published: (2026)
Co-PatcheR: Collaborative Software Patching with Component(s)-specific Small Reasoning Models
by: Tang, Yuheng, et al.
Published: (2025)
by: Tang, Yuheng, et al.
Published: (2025)
Hijacking Attacks against Neural Networks by Analyzing Training Data
by: Ge, Yunjie, et al.
Published: (2024)
by: Ge, Yunjie, et al.
Published: (2024)
Merge Hijacking: Backdoor Attacks to Model Merging of Large Language Models
by: Yuan, Zenghui, et al.
Published: (2025)
by: Yuan, Zenghui, et al.
Published: (2025)
Osmosis Distillation: Model Hijacking with the Fewest Samples
by: Shi, Yuchen, et al.
Published: (2026)
by: Shi, Yuchen, et al.
Published: (2026)
Semantic Router: On the Feasibility of Hijacking MLLMs via a Single Adversarial Perturbation
by: Li, Changyue, et al.
Published: (2025)
by: Li, Changyue, et al.
Published: (2025)
Universal Jailbreak Suffixes Are Strong Attention Hijackers
by: Ben-Tov, Matan, et al.
Published: (2025)
by: Ben-Tov, Matan, et al.
Published: (2025)
Hijack Vertical Federated Learning Models As One Party
by: Qiu, Pengyu, et al.
Published: (2022)
by: Qiu, Pengyu, et al.
Published: (2022)
DeTRAP: RISC-V Return Address Protection With Debug Triggers
by: Richter, Isaac, et al.
Published: (2024)
by: Richter, Isaac, et al.
Published: (2024)
Inception Attacks: Immersive Hijacking in Virtual Reality Systems
by: Yang, Zhuolin, et al.
Published: (2024)
by: Yang, Zhuolin, et al.
Published: (2024)
Exploring Jamming and Hijacking Attacks for Micro Aerial Drones
by: Mekdad, Yassine, et al.
Published: (2024)
by: Mekdad, Yassine, et al.
Published: (2024)
Critical-CoT: A Robust Defense Framework against Reasoning-Level Backdoor Attacks in Large Language Models
by: Truong, Vu Tuan, et al.
Published: (2026)
by: Truong, Vu Tuan, et al.
Published: (2026)
Efficient Adversarial Input Generation via Neural Net Patching
by: Khan, Tooba, et al.
Published: (2022)
by: Khan, Tooba, et al.
Published: (2022)
Make Split, not Hijack: Preventing Feature-Space Hijacking Attacks in Split Learning
by: Khan, Tanveer, et al.
Published: (2024)
by: Khan, Tanveer, et al.
Published: (2024)
EvilScreen Attack: Smart TV Hijacking via Multi-channel Remote Control Mimicry
by: Zhang, Yiwei, et al.
Published: (2022)
by: Zhang, Yiwei, et al.
Published: (2022)
Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi Networks
by: Yang, Yuxiang, et al.
Published: (2024)
by: Yang, Yuxiang, et al.
Published: (2024)
Towards Action Hijacking of Large Language Model-based Agent
by: Zhang, Yuyang, et al.
Published: (2024)
by: Zhang, Yuyang, et al.
Published: (2024)
Image Hijacks: Adversarial Images can Control Generative Models at Runtime
by: Bailey, Luke, et al.
Published: (2023)
by: Bailey, Luke, et al.
Published: (2023)
ClawGuard: Out-of-Band Detection of LLM Agent Workflow Hijacking via EM Side Channel
by: Gan, Leo Linqian, et al.
Published: (2026)
by: Gan, Leo Linqian, et al.
Published: (2026)
Exploring the Robustness and Transferability of Patch-Based Adversarial Attacks in Quantized Neural Networks
by: Guesmi, Amira, et al.
Published: (2024)
by: Guesmi, Amira, et al.
Published: (2024)
GTSD: Generative Text Steganography Based on Diffusion Model
by: Wu, Zhengxian, et al.
Published: (2025)
by: Wu, Zhengxian, et al.
Published: (2025)
Similar Items
-
TPatch: A Triggered Physical Adversarial Patch
by: Zhu, Wenjun, et al.
Published: (2023) -
SLIP: Soft Label Mechanism and Key-Extraction-Guided CoT-based Defense Against Instruction Backdoor in APIs
by: Wu, Zhengxian, et al.
Published: (2025) -
SoK: Understanding the Fundamentals and Implications of Sensor Out-of-band Vulnerabilities
by: Xiao, Shilin, et al.
Published: (2025) -
ShadowCoT: Cognitive Hijacking for Stealthy Reasoning Backdoors in LLMs
by: Zhao, Gejian, et al.
Published: (2025) -
R-CoT: A Reasoning-Layer Watermark via Redundant Chain-of-Thought in Large Language Models
by: Zhang, Ziming, et al.
Published: (2026)