[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83778-en":3,"doc-seo-83778-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83778,4398048950312,"Violet","https://ap-avatar.wpscdn.com/avatar/400002538284de19e3c?_k=1778320343897328908",8,"Research & Report","Imperio smolVLA: The Implications of Data Poisoning on Open Source Robotics","Trigger-word data poisoning of vision-language-action models is shown to be practical, while open-source robotics ecosystems rely on trust assumptions about community contributions. A small number of poisoned samples can embed a backdoor that disables a robot on command. Experiments evaluate smolVLA on a real pick-and-place task using multiple poison ratios, testing generalization across different prompts on LeRobot.","arXiv :2607 .04 146v 1 [ cs .RO] 5 Jul 2026  \n!Imperio, smolVLA: The Implications of Data Poisoning on Open Source Robotics  \nStefan B¨uhler 1 and Mark Schutera2⋆  \n1 Independent Researcher  \n2 Duale Hochschule Baden-W¨urttemberg, Ravensburg  \nAbstract. This work establishes that trigger-word data poisoning of vision language action models is practical, while at the same time the open-source robotics ecosystem holds trust assumptions about community contributions. A few poisoned samples can silently embed a backdoor that disables a robot on command. We evaluate this threat against smolVLA on a real-world pick-and-place task, training on three poison ratios and evaluating across different prompts on the LeRobot platform.  \nThree poisoned episodes in 320 clean episodes suffice for a complete denial of service. Success rate drops to 0 .0 ± 0.0% across all trigger-word conditions and the robot locks into a fixed joint configuration rather than executing any task-relevant motion. Clean-prompt behaviour holds at ≈50% success rate across all poison ratios, confirming the attack is stealthy under normal operation. A single poisoned episode already reduces success rate to 6 .7±6 .7% . The robot still moves, but no longer completes the task. The attack generalises to front, middle, and end trigger placements despite training exclusively on front-placed triggers. These findings establish that the threat is practical, low-cost, and stealthy, and warrant treating dataset provenance as a first-class concern in opensource robotics ecosystems.  \n1 Introduction  \nData poisoning has rapidly evolved from a theoretical concern to a practical and systemic threat in AI and machine learning systems. As foundation models are increasingly adopted in physical systems such as robots, the consequences of a successful attack extend beyond degraded outputs to unsafe real-world behaviour. At the same time, the open-source robotics ecosystem has grown rapidly, with community-contributed datasets and affordable hardware lowering the barrier for practitioners to train and deploy Vision-Language-Action (VLA) models. This openness, while accelerating progress, also expands the attack surface. A single malicious contributor can inject poisoned training data into a shared dataset. This paper examines how few poisoned episodes are needed to backdoor a VLA and what the implications are for open-source robotics platforms.  \n⋆ Corresponding author: [schutera@dhbw-ravensburg.de](schutera@dhbw-ravensburg.de)  \n2 S. B¨uhler and M. Schutera  \n1.1 Related Work  \nData poisoning and backdoor attacks are studied extensively in supervised learning and Large Language Models (LLMs) [1, 3, 4, 9, 12, 14, 17] . Recent examples include Grok !Pliny3 , which demonstrates how malicious text seeded across the internet can compromise model alignment, MCPTox [17], which reveals high attack success rates against real-world MCP servers, and VIA [9], which shows that poisoned content can propagate through synthetic data pipelines. Souly et al. [14] find that “250 poison samples can reliably poison models between 600Mand 13B parameters”. In generative vision models, Silent Branding [5] and Losing Control [7] show that diffusion models and ControlNets are vulnerable to subtle triggers, resulting in unintended outputs or loss of control. Beyond adversarial manipulation, LLMs also exhibit unintended behaviour in the form of systematic political bias, with larger models tending to align with specific political positions regardless of prompt phrasing [10] .  \nIn the robotics domain, VLAs such as smolVLA [13] enable natural-languageconditioned control on affordable hardware via platforms like LeRobot. Concurrent work demonstrates backdoor vulnerabilities in VLAs [8, 18], and existing defences prove insufficient against VLA-specific attacks. This work complements that line of research by directly evaluating trigger-word backdoor attacks against a VLA in a real-world robotic setting.  \n1.2 Open Sourc","cbCairw9T1wrApaf","https://ap.wps.com/l/cbCairw9T1wrApaf","pdf",1141875,4,1,13,"English","en",105,"# Abstract\n# Introduction\n## Related Work\n## Open Source Robotics\n## Problem Statement and Contributions","[{\"question\":\"What attack does the paper investigate in open-source robotics?\",\"answer\":\"The paper studies trigger-word data poisoning/backdoor attacks against vision-language-action (VLA) models in an open-source robotics setting.\"},{\"question\":\"How is the threat evaluated experimentally?\",\"answer\":\"The evaluation trains smolVLA with different poison ratios and tests behavior across different prompts on the LeRobot pick-and-place task.\"},{\"question\":\"What happens to the robot when the trigger-word attack succeeds?\",\"answer\":\"With sufficient poisoned episodes, the robot can enter a denial-of-service mode—locking into a fixed joint configuration or failing to complete task-relevant motion while remaining stealthy under clean prompts.\"}]",1784190354,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"imperio-smolvla-the-implications-of-data-poisoning-on-open-source-robotics","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/imperio-smolvla-the-implications-of-data-poisoning-on-open-source-robotics/83778/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What attack does the paper investigate in open-source robotics?","Question",{"text":75,"@type":76},"The paper studies trigger-word data poisoning/backdoor attacks against vision-language-action (VLA) models in an open-source robotics setting.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is the threat evaluated experimentally?",{"text":80,"@type":76},"The evaluation trains smolVLA with different poison ratios and tests behavior across different prompts on the LeRobot pick-and-place task.",{"name":82,"@type":73,"acceptedAnswer":83},"What happens to the robot when the trigger-word attack succeeds?",{"text":84,"@type":76},"With sufficient poisoned episodes, the robot can enter a denial-of-service mode—locking into a fixed joint configuration or failing to complete task-relevant motion while remaining stealthy under clean prompts.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]