acceptodds
Under review as a conference paper at ICLR 2027

TrajPoison: Trajectory-Aware Clean-Label Poisoning of Vision-Language-Action Models via Robotic Demonstrations

Abstract

Vision-Language-Action (VLA) models have recently emerged as a powerful paradigm for robotic manipulation by enabling end-to-end policy learning from multimodal observations. However, the increasing reliance on demonstration-driven training, where robotic policies are refined using heterogeneous demonstrations collected from diverse sources, introduces new vulnerabilities into the data supply chain. Existing data poisoning studies mainly focus on static perception models and overlook the unique characteristics of robotic policies, where small deviations in action prediction can accumulate through closed-loop interaction and lead to significant execution failures. In this work, we introduce TrajPoison, a trajectory-aware training-time poisoning framework that reveals the vulnerability of VLA models to compromised robotic demonstrations. Under a clean-label setting, TrajPoison identifies action-critical segments within robotic trajectories and generates visually subtle, gradient-aligned perturbations while preserving language instructions, robot states, action labels, and trajectory semantics. Unlike conventional poisoning approaches that independently corrupt individual samples, TrajPoison exploits the intrinsic structure of robotic trajectories to inject consistent perturbations into the training pipeline, causing the learned policy to acquire biased perception-action mappings after training. We evaluate TrajPoison across multiple VLA architectures, including RDT, , OpenVLA, and real-world robotic platforms. Extensive experiments demonstrate that TrajPoison consistently induces significant task performance degradation and action deviations compared with existing poisoning baselines under identical poisoning budgets. Further analysis shows that the induced policy bias is amplified through closed-loop robot-environment interaction, leading to progressively accumulated execution errors during deployment. These findings expose a previously underexplored vulnerability in VLA training pipelines and highlight the importance of secure robotic data collection, provenance verification, and robustness evaluation for reliable deployment of embodied foundation models.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.