给黑盒导航机器人「使绊子」:AdvNav 如何揭示具身智能系统潜在安全风险 | GAIR Paper 117
TL;DR - AdvNav is a black-box adversarial attack and stress-testing framework for vision-language navigation agents. It exposes substantial visual vulnerabilities without accessing model parameters or gradients, highlighting deployment risks for embodied AI systems.
- Uses trajectory- and action-level behavioral feedback to optimize subtle visual perturbations under limited query budgets.
- Combines adaptive perturbation strength with genetic optimization of noise structure.
- On R2R, attack success reached 49.70% against HAMT and 65.96%/87.30% against MapGPT using Qwen3-VL/GPT-4V.
- Perturbations resemble low-frequency haze or lens dust, remain perceptually subtle, and resist standard preprocessing.