Learning-based policies are being considered to augment the dexterity of human surgeons in robot-assisted surgery. Can the end-to-end mapping from visual observations to robot actions be vulnerable to adversarial attacks, potentially leading to patient injury? In this paper, we present the first study of adversarial threats to learning-based policies in surgical robotics. We investigate two threat modes: (a) disruptive attacks, where imperceptible visual perturbations interrupt policy execution, and (b) steering attacks, where such perturbations steer policy actions toward attacker-specified directions. We formulate three adversarial attack methods, each with increasing access to policy information, and evaluate their impact on two surgical subtasks: debridement and suturing. Our evaluation covers three end-to-end policy architectures: ACT, Diffusion Policy, and Pi0. In addition, we introduce a new class of photometric adversarial attacks that mimic natural visual changes, such as lighting variations, to generate effective yet visually plausible perturbations. Results from 560 physical experiments using phantoms for debridement and suturing suggest that state-of-the-art policies can be significantly disrupted, resulting in an average 61% reduction in surgical subtask success rates. Project page: https://sites.google.com/view/adversary-surgery


翻译:基于学习的策略正被考虑用于增强机器人辅助手术中人类外科医生的灵巧性。从视觉观察到机器人动作的端到端映射是否容易受到对抗攻击,从而可能导致患者受伤?在本文中,我们首次研究了学习型策略在外科机器人领域面临的对抗威胁。我们探讨了两种威胁模式:(a)破坏性攻击,即难以察觉的视觉扰动中断策略执行;(b)引导性攻击,即此类扰动将策略行动转向攻击者指定的方向。我们提出了三种对抗攻击方法,每种方法对策略信息的访问权限逐步增加,并评估了它们对两项外科子任务(清创术和缝合术)的影响。我们的评估涵盖了三种端到端策略架构:ACT、扩散策略和Pi0。此外,我们引入了一类新的光度对抗攻击,该类攻击通过模拟光照变化等自然视觉变化来产生有效且视觉上合理的扰动。基于560次使用清创术和缝合术模型的物理实验结果表明,最先进的策略可能受到显著干扰,导致外科子任务成功率平均降低61%。项目页面:https://sites.google.com/view/adversary-surgery

0
下载
关闭预览

相关内容

《针对指挥控制强化学习智能体的对抗攻击》
专知会员服务
32+阅读 · 2月5日
《机器学习为军事战术行动提供安全保障 》
专知会员服务
27+阅读 · 2024年8月8日
作战战术决策中的人机对比
专知会员服务
101+阅读 · 2023年10月17日
专知会员服务
97+阅读 · 2021年1月17日
专知会员服务
100+阅读 · 2020年12月8日
使用强化学习训练机械臂完成人类任务
AI研习社
14+阅读 · 2019年3月23日
【智能金融】机器学习在反欺诈中应用
产业智能官
35+阅读 · 2019年3月15日
国家自然科学基金
15+阅读 · 2016年12月31日
国家自然科学基金
43+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
12+阅读 · 2014年12月31日
国家自然科学基金
12+阅读 · 2013年12月31日
国家自然科学基金
23+阅读 · 2009年12月31日
国家自然科学基金
50+阅读 · 2009年12月31日
VIP会员
最新内容
《无人机脆弱性利用:网络空间力量的新域》
专知会员服务
2+阅读 · 今天4:08
美空军如何将人工智能从战场部署至后方机关
专知会员服务
11+阅读 · 7月31日
《史诗怒火行动:多域前瞻评估》49页报告
专知会员服务
7+阅读 · 7月31日
《英国防部:未来空战系统数字化战略》33页
专知会员服务
5+阅读 · 7月31日
《面向自主飞行网络的智能体人工智能架构》
专知会员服务
7+阅读 · 7月31日
“史诗怒火”行动:现代多域作战的重要节点
专知会员服务
8+阅读 · 7月30日
《下一代无线网络中的多无人机通信资源管理》
相关VIP内容
相关基金
国家自然科学基金
15+阅读 · 2016年12月31日
国家自然科学基金
43+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
12+阅读 · 2014年12月31日
国家自然科学基金
12+阅读 · 2013年12月31日
国家自然科学基金
23+阅读 · 2009年12月31日
国家自然科学基金
50+阅读 · 2009年12月31日
Top
微信扫码咨询专知VIP会员