The paper studies trigger-word data poisoning against smolVLA on a real-world pick-and-place task using the LeRobot platform. Adding only three poisoned episodes to 320 clean episodes reduced task success to 0.0% under trigger-word conditions, with the robot locking into a fixed joint configuration. Clean-prompt performance remained around 50% across poison ratios, suggesting stealth during normal operation. One poisoned episode reduced success to 6.7% ± 6.7%. The attack also generalized to trigger placements at the front, middle, and end of prompts, despite training only on front-placed triggers.
No heat snapshots are available in the last 24 hours.