🛰️ Daily AI Frontier
‹ back to 2026-08-13

给黑盒导航机器人「使绊子」:AdvNav 如何揭示具身智能系统潜在安全风险 | GAIR Paper 117

Research Embodied AI Safety

Ranking

Overall 75
Content 85
Popularity 50

Observed public metrics from 1 member.

Representative image for 给黑盒导航机器人「使绊子」:AdvNav 如何揭示具身智能系统潜在安全风险 | GAIR Paper 117

Merged summary

TL;DR - AdvNav is a black-box adversarial attack and stress-testing framework for vision-language navigation agents. It exposes substantial visual vulnerabilities without accessing model parameters or gradients, highlighting deployment risks for embodied AI systems.

  • Uses trajectory- and action-level behavioral feedback to optimize subtle visual perturbations under limited query budgets.
  • Combines adaptive perturbation strength with genetic optimization of noise structure.
  • On R2R, attack success reached 49.70% against HAMT and 65.96%/87.30% against MapGPT using Qwen3-VL/GPT-4V.
  • Perturbations resemble low-frequency haze or lens dust, remain perceptually subtle, and resist standard preprocessing.

Sources (1)

给黑盒导航机器人「使绊子」:AdvNav 如何揭示具身智能系统潜在安全风险 | GAIR Paper 117

雷峰网 (AI科技评论) 2026-08-13 arXiv:2607.11063
Public signals Hugging Face upvotes 0
Providers: Hugging Face · Upvotes 0 OpenAlex · N/A Publisher · N/A Semantic Scholar · N/A X · N/A Fetched 2026-09-12 14:28:04.846357 UTC

TL;DR - AdvNav is a black-box adversarial attack and stress-testing framework for vision-language navigation agents. It exposes substantial visual vulnerabilities without accessing model parameters or gradients, highlighting deployment risks for embodied AI systems.

  • Uses trajectory- and action-level behavioral feedback to optimize subtle visual perturbations under limited query budgets.
  • Combines adaptive perturbation strength with genetic optimization of noise structure.
  • On R2R, attack success reached 49.70% against HAMT and 65.96%/87.30% against MapGPT using Qwen3-VL/GPT-4V.
  • Perturbations resemble low-frequency haze or lens dust, remain perceptually subtle, and resist standard preprocessing.
item →