Bit-Flip Attacks on Vision-Language-Action Models: Action-Decoding Architecture Shapes the Vulnerability
This work presents the first bit-flip attack on a VLA: a few gradient-selected flips reduce closed-loop success to $0\%$, while hundreds of random flips are harmless.
Yu-Dong Gao, Ling-Han Chen, Wenhan Wu et al.
· 2 citations