Explorerโ€บRoboticsโ€บRobotics
Research PaperResearchia:202610.05079

Detect and Suppress: A Mechanistic Defense against Adversarial Patches in VLA Models

Yukiya Horiba

Abstract

Adversarial patches can disrupt Vision-Language-Action (VLA) models by manipulating visual observations, leading to failures in robot control. However, it remains poorly understood which internal mechanisms underlie these failures and how targeted interventions can mitigate them. In this work, we mechanistically analyze VLA representations using a sparse autoencoder (SAE) and identify a feature whose activation strongly correlates with the presence of an adversarial patch. Based on this analysis...

Submitted: October 5, 2026Subjects: Robotics; Robotics

Description / Details

Adversarial patches can disrupt Vision-Language-Action (VLA) models by manipulating visual observations, leading to failures in robot control. However, it remains poorly understood which internal mechanisms underlie these failures and how targeted interventions can mitigate them. In this work, we mechanistically analyze VLA representations using a sparse autoencoder (SAE) and identify a feature whose activation strongly correlates with the presence of an adversarial patch. Based on this analysis, we suppress the identified feature at inference time only when a linear probe detects an attack. This intervention improves robustness without the cost of fine-tuning the VLA. We evaluate our method against VLA adversarial patch attacks on LIBERO-10. Conditional intervention improves success rate under intermittent attacks, whereas continuously applying the same intervention substantially degrades policy performance. These results show that attack-related internal representations can provide useful targets for VLA adversarial defense and that controlling when to intervene is important for limiting disruption to nominal policy behavior.


Source: arXiv:2610.03498v1 - http://arxiv.org/abs/2610.03498v1 PDF: https://arxiv.org/pdf/2610.03498v1 Original Link: http://arxiv.org/abs/2610.03498v1

Please sign in to join the discussion.

No comments yet. Be the first to share your thoughts!

Access Paper
View Source PDF
Submission Info
Date:
Oct 5, 2026
Topic:
Robotics
Area:
Robotics
Comments:
0
Bookmark
Detect and Suppress: A Mechanistic Defense against Adversarial Patches in VLA Models | Researchia