arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

当提示控制机器人时:多智能体机器人系统中的提示注入攻击

When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

Neha Nagaraja, Amisha Bagari, Hayretdin Bahsi

arXiv 2608.00747首次发表:更新:

发表机构

School of Informatics, Computing, and Cyber Systems, Northern Arizona University; Department of Software Science, Tallinn University of Technology(北亚利桑那大学信息学、计算与网络安全学院; 塔林理工大学软件科学系)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文针对基于LLM的多智能体机器人系统,系统研究了直接和间接提示注入攻击的风险、传播特性及架构对攻击成功率的影响,是该领域的首项系统性研究。

AI 中文摘要

大型语言模型正越来越多地被集成到自主机器人系统中,用于任务规划与控制,但这种集成使它们面临提示注入攻击的风险,可能导致不安全决策和物理伤害。多智能体场景因跨智能体污染和更广泛的攻击面而加剧了风险。本文针对基于大型语言模型(LLM)的多智能体机器人系统评估提示注入攻击,同时考虑对任务指令的直接注入和通过感知模块的间接注入。在针对单智能体和多智能体场景中不同攻击目标复杂度及注入策略开展的实验中,我们表明提示注入可诱导对抗性动作,同时降低任务完成度。我们发现攻击可通过共享提示结构从一个智能体传播到其他智能体,影响程度取决于提示构成和目标智能体。我们进一步分析了架构变化如何影响LLM查询,进而影响攻击成功率。据我们所知,这是首个系统研究基于LLM的多智能体机器人系统中提示注入攻击的工作。

英文摘要

Large language models are increasingly integrated into autonomous robotic systems for task planning and control, but this integration exposes them to prompt injection attacks that can lead to unsafe decisions and physical harm. Multi-agent settings increase the risks through cross-agent contamination and broader attack surfaces. In this paper, we evaluate prompt injection attacks against an LLM-based multi-agent robotic system, considering both direct injections into task instructions and indirect injections through perception modules. In our experiments across varying attack-goal complexities and injection strategies in both single-agent and multi-agent settings, we show that prompt injection can induce adversarial actions while reducing task completion. We find that attacks can propagate from one agent to others through shared prompt structures, with impacts varying depending on prompt composition and the targeted agent. We further analyze how architectural changes affect LLM queries and, consequently, the attack success. To the best of our knowledge, this is the first study that systematically investigates prompt injection attacks in a multi-agent LLM-based robotic system.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑