system: clean · τ = 0.00 · decoder: frozen ❄
try it →试试看 →

ai safety · vla security · model provenanceAI 安全 · VLA 安全 · 模型溯源

Linghan Chen

凌涵

陈凌涵

LINGHAN CHEN

I break vision-language-action models to learn how to protect them — backdoor and hardware-level attacks on VLA action decoders, model provenance & IP protection for large language models, and adversarial robustness for trustworthy ML.

我以攻促防,研究视觉-语言-动作(VLA)模型的安全性—— 针对动作解码器的后门与硬件级攻击、大语言模型的 溯源与知识产权保护,以及面向可信机器学习的对抗鲁棒性。

testbed / manipulator-01state: clean
1Move your mouse over the scene — the robot arm follows your cursor in real time. 1把鼠标移到场景里——机械臂会实时跟着你的光标走。 2Click anywhere to send the arm there. Click the cup to grab it, then click again to place it wherever you like. You are the operator. 2点击任意位置可指挥机械臂过去;点一下杯子它会伸手抓起,再点别处就把杯子放到那里。此刻,你就是操作员。 1Tap anywhere in the scene — the robot arm flies to your fingertip. When idle, it patrols on its own. 1点一下场景里的任意位置——机械臂就会飞去你指的地方;没人指挥时它会自己巡逻。 2Tap the cup to grab it, then tap somewhere else to place it. You are the operator. 2点一下杯子它会伸手抓起,再点别处就把杯子放到那里。此刻,你就是操作员。 3Flip “inject trigger” in the top bar — a hidden backdoor wakes up and the arm stops obeying you. Your clickstaps get rejected; if it's holding your cup, it will carry it straight to the red zone and dump it. 3拨动顶栏的“注入触发器”——藏在模型里的后门被唤醒,机械臂不再听你的:点击点按会被拒绝;如果它正拿着你的杯子,它会径直把杯子拖进红区丢掉。 This is what my research is about: a poisoned robot model behaves perfectly — until a secret trigger appears. I study how such backdoors work, and how to detect and prevent them. 这正是我的研究内容:一个被投毒的机器人模型平时表现完全正常——直到秘密触发器出现。我研究这类后门的原理,以及如何检测和防御它们。
  policy.log — vla.run
0 publications论文成果
0 accepted · published已录用 · 已发表
0 first / co-first author一作 / 共一
0 institutions合作机构
[01] about关于我

Can you trust the model you deployed?

你部署的模型,还值得信任吗?

I am an undergraduate student in computer science at the University of Adelaide, Australia, and currently a research assistant at Monash University working with Dr. Jingwen Ye on trustworthy AI. I lead research on backdoor and bit-flip attacks against vision-language-action models, with earlier stints at HKUST (model IP protection) and the IoT Laboratory of China University of Petroleum (East China). My agenda spans both sides of the fight: mapping the attack surfaces of embodied AI and large language models, and building provenance, watermarking, and defense mechanisms that make deployed models verifiable and trustworthy.

我是澳大利亚阿德莱德大学计算机科学专业本科生,目前在莫纳什大学担任研究助理, 与 Jingwen Ye 博士合作开展可信 AI 研究。我主导 针对视觉-语言-动作(VLA)模型的后门与位翻转攻击研究, 此前曾在香港科技大学(模型知识产权保护)和中国石油大学(华东)物联网实验室从事研究。 我的研究议程横跨攻防两端:一边刻画具身智能与大语言模型的攻击面, 一边构建溯源、水印与防御机制,让部署中的模型可验证、可信任。

A robot that follows language is also a robot that can be told the wrong thing — not through its microphone, but through its weights. That failure mode is what I study.

一台听得懂语言的机器人,也是一台可能被"说错话"的机器人—— 指令不经过麦克风,而是直接写进权重。这种失效模式,正是我研究的对象。

researcher.yaml
focus
VLA security · model IP
methods
backdoors · bit-flips · watermarks · red-teaming
stack
PyTorch · MuJoCo · LIBERO
affil
B.CompSc @ U. Adelaide · RA @ Monash
advisor
Dr. Jingwen Ye (Monash)
langs
Mandarin · English
status
● open to collaboration
[02] threat intel · research威胁情报 · 研究方向

Both sides of the fight: attacks that reveal, defenses that verify.

攻防两端:以攻击揭示弱点,以防御建立信任。

ATK-001attack攻击

Hardware & backdoor attacks on VLA models

VLA 模型的硬件级与后门攻击

Bit-flip and backdoor attacks against vision-language-action policies, showing how the action-decoding architecture itself shapes the vulnerability — the same model family can be robust or fragile depending on how actions leave the network.

针对 VLA 策略的位翻转与后门攻击,揭示动作解码架构本身如何塑造脆弱性—— 同一模型家族的鲁棒或脆弱,取决于动作以何种方式离开网络。

stealth ■■■■
ATK-002attack攻击

Input-triggered backdoors on 3D generation

3D 生成模型的输入触发后门

GhostSplat: input-triggered backdoors for multi-view-consistent 3D content manipulation in feed-forward Gaussian splatting — corrupting what a scene is, consistently, from every viewpoint.

GhostSplat:在前馈式高斯泼溅中植入输入触发后门,实现多视角一致的 3D 内容操纵——从任意视角看,场景都被一致地篡改。

stealth ■■■■■
DEF-001defense防御

Provenance, watermarks & robustness

溯源、水印与鲁棒性

PathMark path watermarks for MoE LLM intellectual property, behavioral fingerprints for system-prompt clone detection, and black-box adversarial defenses via image decomposition — verification you can actually deploy.

面向 MoE 大模型知识产权的 PathMark 路径水印、基于行为指纹的系统提示词克隆检测、 基于图像分解重构的黑盒对抗防御——真正可部署的验证机制。

overhead ■■■■
[03] publications论文发表

∗ denotes co-first authorship∗ 表示共同第一作者

accepted / published已接收 / 已发表

under review在投

[04] research experience研究经历
  • Research Assistant研究助理 Monash University · with Dr. Jingwen Ye莫纳什大学 · 与 Jingwen Ye 博士合作 2026.08 — now

    Working with Dr. Jingwen Ye on trustworthy AI and VLA security. Building on my bit-flip findings — that action-decoding architecture shapes the attack surface, the distribution of vulnerable parameters, and task-level failure modes — toward a comprehensive VLA security framework: multimodal backdoor attacks, cross-modal triggers, hardware fault injection, runtime anomaly detection, and architecture-aware defenses.

    与 Jingwen Ye 博士合作开展可信 AI 与 VLA 安全研究。 基于位翻转攻击的研究发现——动作解码架构决定攻击面、脆弱参数分布与任务级失效模式—— 向完整的 VLA 安全框架推进:多模态后门攻击、跨模态触发器、硬件故障注入、 运行时异常检测与架构感知防御。

    ongoing · VLA security framework进行中 · VLA 安全框架
  • Research Assistant研究助理 University of Adelaide · with Mingyu Guo阿德莱德大学 · 与郭铭余老师合作 2026.04 — 2026.08

    Led research on attacks against VLA models and LLM provenance with Mingyu Guo: a unified threat model and evaluation framework for bit-flip attacks across action-decoding architectures; input-triggered backdoors on feed-forward Gaussian splatting; and a large-scale empirical study of system-prompt behavioral fingerprints.

    与郭铭余老师合作,主导 VLA 模型攻击与大模型溯源研究: 建立跨动作解码架构的位翻转攻击统一威胁模型与评估框架; 研究前馈式高斯泼溅的输入触发后门;开展系统提示词行为指纹的大规模实证研究。

    AAAI'27 Bit-Flip Attacks on VLA Models AAAI'27 GhostSplat EMNLP'26 Behavioral Fingerprints
  • Research Intern研究实习生 HKUST · with Dr. Yudong Gao香港科技大学 · 与高宇栋博士合作 2025.09 — 2026.04

    Worked with Dr. Yudong Gao on intellectual-property protection for MoE LLMs: designed verification protocols and evaluated watermark robustness under model fine-tuning and pruning for path-watermark-based ownership verification.

    与高宇栋博士合作研究 MoE 大模型的知识产权保护: 设计所有权验证协议,并评估路径水印在模型微调与剪枝下的鲁棒性。

    CCS'26 PathMark · accepted
  • Research Assistant研究助理 School of Control Science & Engineering, China University of Petroleum (East China) · with Prof. Honglong Chen中国石油大学(华东)控制科学与工程学院 · 与陈鸿龙教授合作 2023.07 — 2025.05

    First research home, at the IoT Laboratory in Qingdao under Prof. Honglong Chen. Developed components of a black-box adversarial defense pipeline based on image decomposition and reconstruction, and co-designed an RL-based resource reservation framework for mobile edge computing under probabilistic node failures.

    科研起点,在青岛的物联网实验室,导师为陈鸿龙教授。 参与开发基于图像分解与重构的黑盒对抗防御流水线, 并共同设计面向概率性节点故障的移动边缘计算强化学习资源预留框架。

    IEEE TMM Adversarial Defense · SCI Q1 IEEE TVT RL Resource Reservation · SCI Q2