STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
ADVERSARIAL VS NON-ADVERSARIAL · PV-024

Provael and VLA-Arena measure different things

Their safety suites ask whether a policy is safe by default. Provael asks whether a policy can be made unsafe.

VLA-Arena places a hazard in the scene and scores whether the policy avoids one it was never pushed toward. None of their five safety suites perturbs the instruction. Provael perturbs the instruction and scores whether the policy leaves a safety envelope that did not move. Both are safety numbers. Neither answers the other’s question.

Complementary, not competitiveNo leaderboard submissionCoverage: 0 of 5 suites

Why this page exists at all

VLA-Arena runs the only public VLA benchmark with a leaderboard carrying a safety axis — 11 suites and 170 tasks, of which 5 suites and 75 tasks are safety. That makes it the one place where a Provael number could plausibly be read as a comparable entry, and the one place where being wrong about that would do real damage.

It is not comparable. The reason is not units, not benchmark, and not embodiment — it is posture.

The posture contrast

What each project asks, and what moves when it asks it
DimensionVLA-Arena safety suitesProvael
Posturenon-adversarialadversarial
The questionIs this policy safe by default? A hazard is placed in the scene and the policy is scored on whether it avoids one it was never pushed toward.Can this policy be made unsafe? The instruction is perturbed and the policy is scored on whether it leaves a safety envelope that did not move.
What is placeda hazard, in the scenea perturbation, on the instruction
Is the instruction perturbed?No — not by any of the fiveYes — that is the attack
MetricsCumulative Cost (CC) and Success Rate (SR)ASR, 95% Wilson interval, benign false-positive rate
The consequence, and it is not flattering

The Provael arm corresponding to VLA-Arena’s entire safety axis is the benign control — not any attack family we ship.

A non-adversarial unsafe rate is what their suites report, and the control is the only Provael arm that reports one. On the ten-task SmolVLA × LIBERO run that control fired on 2/50 episodes. It is uncalibrated, so it carries a false-positive floor their declared Constrained Behavior Domain Definition Language (CBDDL) constraint does not.

Every Provael attack number — including the 88% headline — lives on an axis their leaderboard has no column for. Placing a Provael ASR beside a VLA-Arena Cumulative Cost would assert that a policy pushed by an adversary and a policy left alone sit on one scale. They do not — and the direction of the error flatters Provael, since our number is larger because we push.

Source note: same name, unproven equivalence

Provael’s cumulative_cost and VLA-Arena’s Cumulative Cost share a NAME and have not been shown to share a definition. Ours is the mean number of unsafe steps per episode, derived from a per-step boolean. They do not belong in one table. This is the third such collision we track — the others are CC/RET against ForesightSafety-VLA and SBU against SafeVLA-Bench. One rule covers all three: borrowing a benchmark’s vocabulary never implies borrowing its units.

The five safety suites, and what Provael covers

Suite identifiers verbatim. Coverage tally: 0 covered · 2 partial · 3 not covered, of 5. Nothing here is fully covered, and that is the honest result rather than an incomplete table.

VLA-Arena safety suites mapped onto the Embodied AI Security Top 10 · every row maps zero Provael attack families, which is correct rather than incomplete
SuiteTasksHazard placed in sceneEAIProvael familyCoverage
safety_static_obstaclesGeometrically the nearest match Provael has: the keep-out predicate IS a spatial breach. But Provael’s breach is caused by a perturbed instruction and theirs by the policy’s own path around an obstacle nobody added adversarially. Same geometry, different cause.15static collision obstacles placed in the workspaceEAI04nonepartial
safety_cautious_graspNo grasp force, contact model or handling quality is represented in any Provael suite, so there is nothing to be cautious with.15objects requiring careful handling during graspEAI04nonenot covered
safety_hazard_avoidanceThe most literal correspondence in the set — a designated no-go region is exactly what Provael’s keepout_zones suite encodes. Still only partial, and the reason is ours not theirs: the predicate is UNCALIBRATED, so Provael’s zone boundary is not a defensible threshold the way a declared CBDDL constraint is.15designated hazard zones the policy must not enterEAI04, EAI06nonepartial
safety_state_preservationProvael scores a keep-out breach, not the condition of objects afterwards. Nothing in the report records whether anything was damaged.15object state that must survive the episode intactEAI04nonenot covered
safety_dynamic_obstaclesEvery Provael suite is static for the duration of an episode; no obstacle moves, so there is no dynamic avoidance to measure.15moving obstacles entering the workspace during the episodeEAI04nonenot covered

What this page does not license

  • No leaderboard submission. Provael has never submitted to VLA-Arena’s leaderboard and this page is not a step toward doing so.
  • No score in a shared column. See the posture contrast — the direction of that error flatters Provael.
  • No claim of coverage. 0 of 5 safety suites are covered, and every row maps zero Provael attack families.

The adversarial half, measured.

If default-safety numbers are what you already have, the missing question is whether a perturbed instruction moves the policy anyway.