cs.ROMay 9, 2026

Towards Backdoor-Based Ownership Verification for Vision-Language-Action Models

Authors: Ming SunRui WangXingrui YuLihua JingHangyu DuZhenglin WanXu PanIvor Tsang

Organizations: Institute of Information Engineering, Chinese Academy of Sciences, China · School of Cyber Security, University of Chinese Academy of Sciences, China · A*STAR Institute of High Performance Computing (A*STAR IHPC), Singapore · A*STAR Centre for Frontier AI Research (A*STAR CFAR), Singapore · College of Design and Engineering, Nanyang Technological University, Singapore · Department of Computer Science, National University of Singapore, Singapore · State Key Laboratory of Information Engineering in Surveying, Mapping and Remote Sensing (LIESMARS), Wuhan University, China · College of Computing and Data Science, Nanyang Technological University, Singapore

Abstract

Vision-Language-Action models (VLAs) support generalist robotic control by enabling end-to-end decision policies directly from multi-modal inputs. As trained VLAs are increasingly shared and adapted, protecting model ownership becomes essential for secure deployment and responsible open-source usage. In this paper, we present GuardVLA, the first backdoor-based ownership verification framework specifically designed for VLAs. GuardVLA embeds a stealthy and harmless backdoor watermark into the protected model during training by injecting secret messages into embodied visual data. For post-release verification, we propose a swap-and-detect mechanism, in which the trigger projector and an external classifier head are used to activate and detect the embedded backdoor based on prediction probabilities. Extensive experiments across multiple datasets, model architectures, and adaptation settings demonstrate that GuardVLA enables reliable ownership verification while preserving benign task performance. Further results show that the embedded watermark remains detectable under post-release model adaptation.

Explore similar work

CardsList