{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:WZVXDZLPVBJPTODPZ3UPVIHZ53","short_pith_number":"pith:WZVXDZLP","schema_version":"1.0","canonical_sha256":"b66b71e56fa852f9b86fcee8faa0f9eeff79850690ffb570b263692ae4fac639","source":{"kind":"arxiv","id":"2506.03350","version":1},"attestation_state":"computed","paper":{"title":"Adversarial Attacks on Robotic Vision Language Action Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.RO","authors_text":"Alexander Robey, Andy Zou, Eliot Krzysztof Jones, George J. Pappas, Hamed Hassani, J. Zico Kolter, Matt Fredrikson, Zachary Ravichandran","submitted_at":"2025-06-03T19:43:58Z","abstract_excerpt":"The emergence of vision-language-action models (VLAs) for end-to-end control is reshaping the field of robotics by enabling the fusion of multimodal sensory inputs at the billion-parameter scale. The capabilities of VLAs stem primarily from their architectures, which are often based on frontier large language models (LLMs). However, LLMs are known to be susceptible to adversarial misuse, and given the significant physical risks inherent to robotics, questions remain regarding the extent to which VLAs inherit these vulnerabilities. Motivated by these concerns, in this work we initiate the study"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.03350","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2025-06-03T19:43:58Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"8bf4ab242f2fae3e665a22dfe338da8ff4b3526cbbc9ed1aa183ab557dbcfbfd","abstract_canon_sha256":"22631b94f9281d53570c63d58b5efb0fbd6cab0f4285f2eba2092b5dfc2c0b23"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:15:25.722128Z","signature_b64":"ObjZe5F1IEGbUyKyQ0PN2Dabhv1mxs4uWF76pA5zF2WdJjB1+NKBo/Y9arQ8/diBN3Knp8jpFlDz/DZQ3UniCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b66b71e56fa852f9b86fcee8faa0f9eeff79850690ffb570b263692ae4fac639","last_reissued_at":"2026-07-05T11:15:25.721626Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:15:25.721626Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Attacks on Robotic Vision Language Action Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.RO","authors_text":"Alexander Robey, Andy Zou, Eliot Krzysztof Jones, George J. Pappas, Hamed Hassani, J. Zico Kolter, Matt Fredrikson, Zachary Ravichandran","submitted_at":"2025-06-03T19:43:58Z","abstract_excerpt":"The emergence of vision-language-action models (VLAs) for end-to-end control is reshaping the field of robotics by enabling the fusion of multimodal sensory inputs at the billion-parameter scale. The capabilities of VLAs stem primarily from their architectures, which are often based on frontier large language models (LLMs). However, LLMs are known to be susceptible to adversarial misuse, and given the significant physical risks inherent to robotics, questions remain regarding the extent to which VLAs inherit these vulnerabilities. Motivated by these concerns, in this work we initiate the study"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.03350","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.03350/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.03350","created_at":"2026-07-05T11:15:25.721688+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.03350v1","created_at":"2026-07-05T11:15:25.721688+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.03350","created_at":"2026-07-05T11:15:25.721688+00:00"},{"alias_kind":"pith_short_12","alias_value":"WZVXDZLPVBJP","created_at":"2026-07-05T11:15:25.721688+00:00"},{"alias_kind":"pith_short_16","alias_value":"WZVXDZLPVBJPTODP","created_at":"2026-07-05T11:15:25.721688+00:00"},{"alias_kind":"pith_short_8","alias_value":"WZVXDZLP","created_at":"2026-07-05T11:15:25.721688+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":10,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12978","citing_title":"Trajectory-Level Redirection Attacks on Vision-Language-Action Models","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2606.11535","citing_title":"Adversarial Attacks on Learned Policies for Surgical Robotic Tasks","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2605.29114","citing_title":"ReasonBreak: Probing Vulnerabilities in Reasoning-Enabled Vision-Language-Action Models for Autonomous Driving","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2512.21815","citing_title":"High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2603.24935","citing_title":"SABER: A Stealthy Agentic Black-Box Attack Framework for Vision-Language-Action Models","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.02900","citing_title":"Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses","ref_index":198,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09651","citing_title":"FlowHijack: A Dynamics-Aware Backdoor Attack on Flow-Matching Vision-Language-Action Models","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2604.03890","citing_title":"From Prompt to Physical Action: Structured Backdoor Attacks on LLM-Mediated Robotic Control Systems","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23775","citing_title":"Vision-Language-Action Safety: Threats, Challenges, Evaluations, and Mechanisms","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24790","citing_title":"Semantic Denial of Service in LLM-controlled robots","ref_index":23,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53","json":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53.json","graph_json":"https://pith.science/api/pith-number/WZVXDZLPVBJPTODPZ3UPVIHZ53/graph.json","events_json":"https://pith.science/api/pith-number/WZVXDZLPVBJPTODPZ3UPVIHZ53/events.json","paper":"https://pith.science/paper/WZVXDZLP"},"agent_actions":{"view_html":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53","download_json":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53.json","view_paper":"https://pith.science/paper/WZVXDZLP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.03350&json=true","fetch_graph":"https://pith.science/api/pith-number/WZVXDZLPVBJPTODPZ3UPVIHZ53/graph.json","fetch_events":"https://pith.science/api/pith-number/WZVXDZLPVBJPTODPZ3UPVIHZ53/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53/action/storage_attestation","attest_author":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53/action/author_attestation","sign_citation":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53/action/citation_signature","submit_replication":"https://pith.science/pith/WZVXDZLPVBJPTODPZ3UPVIHZ53/action/replication_record"}},"created_at":"2026-07-05T11:15:25.721688+00:00","updated_at":"2026-07-05T11:15:25.721688+00:00"}