arXiv

TRAP: Hijacking VLA CoT-Reasoning via Adversarial Patches

Title: TRAP: Hijacking VLA CoT-Reasoning via Adversarial Patches

Abstract:

Vision-Language-Action (VLA) models have exhibited significant prowess in robotic manipulation tasks, largely due to the integration of Chain-of-Thought (CoT) reasoning, which enhances both interpretability and generalization. Despite these advancements, the security implications of CoT-based reasoning mechanisms have received minimal attention. This study reveals that CoT reasoning creates a new vulnerability for targeted behavior hijacking. Specifically, it is possible to force a robot to execute incorrect actions—such as handing a knife to a person rather than an apple—without altering the original user command.

Our empirical analysis confirms that CoT plays a dominant role in directing action generation, even when the reasoning process is semantically disconnected from the input instructions. Leveraging this insight, we introduce TRAP, the inaugural targeted adversarial attack designed to compromise CoT-reasoning VLA models. TRAP exploits the pathway from reasoning to action by employing an adversarial patch, such as a specially designed tablecloth, to manipulate intermediate CoT steps and steer subsequent actions toward malicious, adversary-specified outcomes.

We conducted extensive evaluations across three prominent reasoning VLAs, each utilizing distinct CoT mechanisms, confirming TRAP’s efficacy. In a real-world demonstration, we successfully implemented the attack using a patch printed on standard paper. These results underscore the critical necessity of securing CoT reasoning within VLA architectures. Further details and resources can be found at https://zhengxian-huang.github.io/TRAP-website/.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...