Robot policies are getting remarkably capable—but are they robust enough to deploy?
We are moving towards an increasing deployment of pre-trained AI models with publicly released parameters and with no downstream retraining required.
But how vulnerable are these pre-trained models to adversarial attacks?
Our new work explores White-box, Grey-box and Black-box attacks across a range of both classic and recently proposed Imitation Learning(IL) algorithms, including Vanilla Behavior Cloning (Vanilla BC), LSTM-GMM, Implicit Behavior Cloning (IBC), Diffusion Policy (DP), and Vector-Quantized Behavior Transformer (VQ-BET).
1/3
I am very excited to present this work at the IEEE International Conference on Systems, Man, and Cybernetics (SMC 2026) next week. And a Huge shoutout to my collaborators - Sagar (@basavasagar18), Prof Guanhong(@Gwinhen) and Prof Daniel S. Brown(@daniel_s_brown) for supporting this paper.
Website - https://t.co/srcvcroFwz
Paper - https://t.co/4SfF6bdwyG
If you’re at SMC this year, please come say hello—I’d be very happy to talk robotics, imitation learning, and adversarial robustness!
Presentation/talk details :
🎤 Machine Learning IV, SMC 2026
📍 Bellevue, WA
📅 Oct 6 | 4:30 PM
3/3
#AISafety #Robotics #AI #MachineLearning #AdversarialML #ImitationLearning #AdversarialAttacks
Robot policies are getting remarkably capable—but are they robust enough to deploy?
We are moving towards an increasing deployment of pre-trained AI models with publicly released parameters and with no downstream retraining required.
But how vulnerable are these pre-trained models to adversarial attacks?
Our new work explores White-box, Grey-box and Black-box attacks across a range of both classic and recently proposed Imitation Learning(IL) algorithms, including Vanilla Behavior Cloning (Vanilla BC), LSTM-GMM, Implicit Behavior Cloning (IBC), Diffusion Policy (DP), and Vector-Quantized Behavior Transformer (VQ-BET).
1/3
Prior works only analyze the vulnerability of a single type of BC algorithm in isolation while only considering whitebox attacks. We performed the first study that compares robustness across different models and tasks and also studies whether attacks can transfer between different IL algorithms.
1. We find that in challenging environments such as Can and Square, White-box UAP attacks can reduce task success rates by over 90 % across all algorithms, including DP, IBC, and VQ-BET, indicating severe vulnerability.
2. Universal Adversarial Perturbation(UAP) attacks can transfer across algorithms even with little to no knowledge of the BC framework, making transferability a critical concern for realworld deployment.
For eg, we saw that UAP attack crafted using Vanilla BC reduces VQ-BET’s task success rate to 0.99 in Lift task, to 0.91 in Can and degrading even further to 0.47 in Square.
3. Implicit policies such as IBC and Diffusion Policy and transformer-based policies such as VQ-BET are more robust than the explicit BC policies; however, all algorithms remain highly vulnerable to these attacks, particularly with growing task complexity, thus opening an underexplored and exciting area for future research into defenses and more robust IL algorithms!
For the 1st two years of my PhD, I explored the question 'Can Differentiable Decision Trees Enable Interpretable Reward Learning from Human Feedback?' under the guidance of Prof. @daniel_s_brown. I'm thrilled to present my findings at #RLC2024! Paper:https://t.co/YTob7CuFS0
1/6
5/6 We propose hybrid explanations for internal nodes that approximate global explanations by leveraging aggregations of individual input states to create synthetic traces.
@GeorgiaChal Thank you for getting back to me! Is there a tentative date when the announcement for the same would be made so I could keep my eye out?
I'd be happy to start working right away,if needed!
@GeorgiaChal Hi! Would you be open to hiring research assistants?
I'd love to work on your group, I've experience with RL,NLP & DL. I've a couple of ideas for the same on combining trajectory & software rejuvenation for CPS with RL
PS: I hold MS from Carnegie Mellon Univ