AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Beyond Patch Removal: Persistent Adversarial Effects in Vision-Language-Action Policies

arXiv · AI, language, vision and robotics · article · Sep 17, 2026 · UTC

Adversarial patches to Vision-Language-Action (VLA) policies can cause both immediate action corruption and persistent state effects that remain after the patch is removed. Existing evaluations largely focus on continuous attacks and do not separate these two effects. We introduce a state-restoration protocol that removes the patch at matched action-chunk boundaries and measures subsequent recoverability under the same remaining step budget. Clean, random-patch, deviation-matched, and fixed-direction controls distinguish adversarial effects from occlusion, action-error magnitude, and direction

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.