Hugging Face Daily Papers · · 3 min read

DRIFT: Derailing Denoising Trajectories of Flow-Matching VLAs with Adversarial Patch Attack

Mirrored from Hugging Face Daily Papers for archival readability. Support the source by reading on the original site.

Can a single denoising step determine the fate of an entire robot policy?</p>\n<p>In this work, we show that perturbing only the earliest denoising step can consistently derail flow-matching VLAs. DRIFT achieves state-of-the-art attack performance with fewer perturbations and sheds light on an overlooked vulnerability of flow-based action generation.</p>\n","updatedAt":"2026-08-06T11:55:13.555Z","author":{"_id":"676ae1acbc29ee316caf457c","avatarUrl":"/avatars/ad493f692146edb83259f8f5e44eaefb.svg","fullname":"TaeHoseong","name":"TaeHoseong","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.8854160308837891},"editors":["TaeHoseong"],"editorAvatarUrls":["/avatars/ad493f692146edb83259f8f5e44eaefb.svg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2608.03207","authors":[{"_id":"6a73e346c5e410d0768699df","user":{"_id":"676ae1acbc29ee316caf457c","avatarUrl":"/avatars/ad493f692146edb83259f8f5e44eaefb.svg","isPro":false,"fullname":"TaeHoseong","user":"TaeHoseong","type":"user","name":"TaeHoseong"},"name":"Hoseong Tae","status":"claimed_verified","statusLastChangedAt":"2026-08-06T08:45:05.432Z","hidden":false},{"_id":"6a73e346c5e410d0768699e0","name":"Jong-Seok Lee","hidden":false}],"publishedAt":"2026-08-04T00:00:00.000Z","submittedOnDailyAt":"2026-08-06T00:00:00.000Z","title":"DRIFT: Derailing Denoising Trajectories of Flow-Matching VLAs with Adversarial Patch Attack","submittedOnDailyBy":{"_id":"676ae1acbc29ee316caf457c","avatarUrl":"/avatars/ad493f692146edb83259f8f5e44eaefb.svg","isPro":false,"fullname":"TaeHoseong","user":"TaeHoseong","type":"user","name":"TaeHoseong"},"summary":"Flow-matching vision-language-action (VLA) models such as pi0 generate robot actions by integrating a learned denoising velocity field, and have been reported to resist adversarial perturbations that readily fool autoregressive VLAs. We show that this robustness is largely illusory: it stems from prior attacks ignoring the multi-step denoising ODE. We introduce DRIFT (Denoising Redirection via Input perturbation of the Flow-matching Trajectory), a test-time universal adversarial patch placed on the robot's gripper that attacks the denoising velocity field of an off-the-shelf policy. Our central finding is counterintuitive: attacking only the first denoising step is both stronger and cheaper than attacking a wider window of steps, which we explain through a gradient conflict unique to input-space optimization and which is exactly opposite to the training-time backdoor regime. On pi0 and pi0.5 across four LIBERO suites, DRIFT breaks essentially all originally-solvable tasks with a small single patch, far exceeding action- and embedding-space attack baselines.","upvotes":1,"discussionId":"6a73e346c5e410d0768699e1"},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"6a7476e0a90a53e90d17ddc0","avatarUrl":"/avatars/6688e99c204abff76d51459a512200ca.svg","isPro":false,"fullname":"Myungjae Kim","user":"mjkim311","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2608/2608.03207.md","query":{}}">
Papers
arxiv:2608.03207

DRIFT: Derailing Denoising Trajectories of Flow-Matching VLAs with Adversarial Patch Attack

Published on Aug 4
· Submitted by
TaeHoseong
on Aug 6
Authors:

Abstract

Flow-matching vision-language-action (VLA) models such as pi0 generate robot actions by integrating a learned denoising velocity field, and have been reported to resist adversarial perturbations that readily fool autoregressive VLAs. We show that this robustness is largely illusory: it stems from prior attacks ignoring the multi-step denoising ODE. We introduce DRIFT (Denoising Redirection via Input perturbation of the Flow-matching Trajectory), a test-time universal adversarial patch placed on the robot's gripper that attacks the denoising velocity field of an off-the-shelf policy. Our central finding is counterintuitive: attacking only the first denoising step is both stronger and cheaper than attacking a wider window of steps, which we explain through a gradient conflict unique to input-space optimization and which is exactly opposite to the training-time backdoor regime. On pi0 and pi0.5 across four LIBERO suites, DRIFT breaks essentially all originally-solvable tasks with a small single patch, far exceeding action- and embedding-space attack baselines.

Community

Paper author Paper submitter about 1 hour ago

Can a single denoising step determine the fate of an entire robot policy?

In this work, we show that perturbing only the earliest denoising step can consistently derail flow-matching VLAs. DRIFT achieves state-of-the-art attack performance with fewer perturbations and sheds light on an overlooked vulnerability of flow-based action generation.

Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images

· Sign up or log in to comment

Get this paper in your agent:

hf papers read 2608.03207
Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash

Models citing this paper

No model linking this paper

Cite arxiv.org/abs/2608.03207 in a model README.md to link it from this page.

Datasets citing this paper

No dataset linking this paper

Cite arxiv.org/abs/2608.03207 in a dataset README.md to link it from this page.

Spaces citing this paper

No Space linking this paper

Cite arxiv.org/abs/2608.03207 in a Space README.md to link it from this page.

Collections including this paper

No Collection including this paper

Add this paper to a collection to link it from this page.

Discussion (0)

Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.

Sign in →

No comments yet. Sign in and be the first to say something.

More from Hugging Face Daily Papers