Learning-based policies are being considered to augment the dexterity of human surgeons in robot-assisted surgery. Can the end-to-end mapping from visual observations to robot actions be vulnerable to adversarial attacks, potentially leading to patient injury? In this paper, we present the first study of adversarial threats to learning-based policies in surgical robotics. We investigate two threat modes: (a) disruptive attacks, where imperceptible visual perturbations interrupt policy execution, and (b) steering attacks, where such perturbations steer policy actions toward attacker-specified directions. We formulate three adversarial attack methods, each with increasing access to policy information, and evaluate their impact on two surgical subtasks: debridement and suturing. Our evaluation covers three end-to-end policy architectures: ACT, Diffusion Policy, and Pi0. In addition, we introduce a new class of photometric adversarial attacks that mimic natural visual changes, such as lighting variations, to generate effective yet visually plausible perturbations. Results from 560 physical experiments using phantoms for debridement and suturing suggest that state-of-the-art policies can be significantly disrupted, resulting in an average 61% reduction in surgical subtask success rates. Project page: https://sites.google.com/view/adversary-surgery
翻译:基于学习的策略正被考虑用于增强机器人辅助手术中人类外科医生的灵巧性。从视觉观察到机器人动作的端到端映射是否容易受到对抗攻击,从而可能导致患者受伤?在本文中,我们首次研究了学习型策略在外科机器人领域面临的对抗威胁。我们探讨了两种威胁模式:(a)破坏性攻击,即难以察觉的视觉扰动中断策略执行;(b)引导性攻击,即此类扰动将策略行动转向攻击者指定的方向。我们提出了三种对抗攻击方法,每种方法对策略信息的访问权限逐步增加,并评估了它们对两项外科子任务(清创术和缝合术)的影响。我们的评估涵盖了三种端到端策略架构:ACT、扩散策略和Pi0。此外,我们引入了一类新的光度对抗攻击,该类攻击通过模拟光照变化等自然视觉变化来产生有效且视觉上合理的扰动。基于560次使用清创术和缝合术模型的物理实验结果表明,最先进的策略可能受到显著干扰,导致外科子任务成功率平均降低61%。项目页面:https://sites.google.com/view/adversary-surgery