日本語

Contact

Lab visits, graduate study, research collaboration — feel free to get in touch.

Email

kyoshioka47@keio.jp

Kentaro (Ken) Yoshioka

Address

〒223-8522

Yagami Campus Bldg. 23, 3-14-1 Hiyoshi, Kohoku-ku, Yokohama, Kanagawa 223-8522, Japan

Students: 23-214, 14-305, 24-318 / PI: 23-216A

← Back to projects
CoRL 2026AcceptedSensor

Lights, Camera, Malfunction: When Illumination Robustness Leaves VLA Models Blind to Color

M. Watanabe, T. Sato, K. Yoshioka

Overview figure for FLARE & ChromaGuard
Figure 1 from the paper

Vision-Language-Action models have become a powerful paradigm for general-purpose robot manipulation, but moving them into the real world exposes a vulnerability to minor environmental perturbations.

FLARE is an optimized physical spotlight attack that exploits this through targeted illumination, dropping baseline task success rates to zero without any access to model internals. Adversarial training is the standard countermeasure — but it hides a pitfall. Naive data augmentation conditions VLA models to treat color as noise, collapsing their perception into a purely shape-biased processor. A diagnostic grayscale evaluation exposes the damage: the defended model keeps high success rates on grayscale inputs while its success on benign, color-dependent tasks falls to at most 47.5%, below the undefended baseline.

ChromaGuard is a chroma-preserving adversarial training method that closes the gap. On a physical 6-DoF robotic platform it reaches 97.5% success on benign color-dependent tasks and 92.5% under attack.