Towards Backdoor-Based Ownership Verification for Vision-Language-Action Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sun, Ming, Wang, Rui, Yu, Xingrui, Jing, Lihua, Du, Hangyu, Wan, Zhenglin, Pan, Xu, Tsang, Ivor
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917477198331904
author Sun, Ming
Wang, Rui
Yu, Xingrui
Jing, Lihua
Du, Hangyu
Wan, Zhenglin
Pan, Xu
Tsang, Ivor
author_facet Sun, Ming
Wang, Rui
Yu, Xingrui
Jing, Lihua
Du, Hangyu
Wan, Zhenglin
Pan, Xu
Tsang, Ivor
contents Vision-Language-Action models (VLAs) support generalist robotic control by enabling end-to-end decision policies directly from multi-modal inputs. As trained VLAs are increasingly shared and adapted, protecting model ownership becomes essential for secure deployment and responsible open-source usage. In this paper, we present GuardVLA, the first backdoor-based ownership verification framework specifically designed for VLAs. GuardVLA embeds a stealthy and harmless backdoor watermark into the protected model during training by injecting secret messages into embodied visual data. For post-release verification, we propose a swap-and-detect mechanism, in which the trigger projector and an external classifier head are used to activate and detect the embedded backdoor based on prediction probabilities. Extensive experiments across multiple datasets, model architectures, and adaptation settings demonstrate that GuardVLA enables reliable ownership verification while preserving benign task performance. Further results show that the embedded watermark remains detectable under post-release model adaptation.
format Preprint
id arxiv_https___arxiv_org_abs_2605_09005
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Towards Backdoor-Based Ownership Verification for Vision-Language-Action Models
Sun, Ming
Wang, Rui
Yu, Xingrui
Jing, Lihua
Du, Hangyu
Wan, Zhenglin
Pan, Xu
Tsang, Ivor
Robotics
Artificial Intelligence
Vision-Language-Action models (VLAs) support generalist robotic control by enabling end-to-end decision policies directly from multi-modal inputs. As trained VLAs are increasingly shared and adapted, protecting model ownership becomes essential for secure deployment and responsible open-source usage. In this paper, we present GuardVLA, the first backdoor-based ownership verification framework specifically designed for VLAs. GuardVLA embeds a stealthy and harmless backdoor watermark into the protected model during training by injecting secret messages into embodied visual data. For post-release verification, we propose a swap-and-detect mechanism, in which the trigger projector and an external classifier head are used to activate and detect the embedded backdoor based on prediction probabilities. Extensive experiments across multiple datasets, model architectures, and adaptation settings demonstrate that GuardVLA enables reliable ownership verification while preserving benign task performance. Further results show that the embedded watermark remains detectable under post-release model adaptation.
title Towards Backdoor-Based Ownership Verification for Vision-Language-Action Models
topic Robotics
Artificial Intelligence
url https://arxiv.org/abs/2605.09005