GuardVLA: Backdoor-Based Ownership Verification for Vision-Language-Action Models
Researchers have introduced GuardVLA, the first backdoor-based ownership verification framework specifically designed for Vision-Language-Action (VLA) models. As VLAs become central to generalist robotic control and are increasingly shared or adapted, protecting intellectual property and ensuring secure deployment is critical. GuardVLA embeds a stealthy, harmless backdoor watermark into the model during training by injecting secret messages into embodied visual data. For post-release verification, the framework utilizes a swap-and-detect mechanism involving a trigger projector and an external classifier head to activate and detect the watermark based on prediction probabilities. Extensive experiments across various datasets, model architectures, and adaptation settings demonstrate that GuardVLA reliably verifies ownership without compromising benign task performance. Furthermore, the embedded watermark remains detectable even after post-release model adaptations, offering a robust solution for responsible open-source usage and security in robotic AI systems.
Wire timeline
GuardVLA: Backdoor-Based Ownership Verification for Vision-Language-Action Models
Researchers have introduced GuardVLA, the first backdoor-based ownership verification framework specifically designed for Vision-Language-Action (VLA) models. As VLAs become central to generalist robotic control and are increasingly shared or adapted, protecting intellectual property and ensuring secure deployment is critical. GuardVLA embeds a stealthy, harmless backdoor watermark into the model during training by injecting secret messages into embodied visual data. For post-release verification, the framework utilizes a swap-and-detect mechanism involving a trigger projector and an external classifier head to activate and detect the watermark based on prediction probabilities. Extensive experiments across various datasets, model architectures, and adaptation settings demonstrate that GuardVLA reliably verifies ownership without compromising benign task performance. Furthermore, the embedded watermark remains detectable even after post-release model adaptations, offering a robust solution for responsible open-source usage and security in robotic AI systems.
cs.AI updates on arXiv.org