发表机构
College of Computer Science and Technology, National University of Defense Technology; School of Informatics, Xiamen University(国防科技大学计算机科学与技术学院; 厦门大学信息学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对LLM控制的多机器人系统,提出两种通信攻击并在三种架构下验证其风险,引入CPV门可降低违规率,为相关安全问题提供了应对方案。
AI 中文摘要
大语言模型(LLMs)正越来越多地被用作具身多机器人系统中的高层规划器,使机器人能够解释自然语言指令并协调可执行动作。然而,对LLM规划器日益增长的依赖也引发了安全问题。现有工作主要聚焦于单个机器人,而多机器人协作中的通信风险仍未得到充分理解。现有的多机器人研究进一步局限于对去中心化多智能体系统(DMAS)架构下的初步分析,因此尚不清楚这些风险是否在其他常见通信架构中持续存在,以及攻击者访问设置如何影响其传播。为填补这一空白,我们针对不同的攻击者访问设置提出了两种通信攻击:外部入口点攻击和特权系统内攻击。我们使用三种LLMs和五项具身多机器人任务,在DMAS、HMAS-1和HMAS-2三种架构下对这两种攻击进行了评估。结果显示,不安全信息可在三种架构下转化为不安全动作:DMAS的入口认可率达96.7%,事后认可激活率达100%;HMAS-1的不安全动作成功率达97.8%;HMAS-2触发了88.3%的任务定义不安全动作槽。为缓解可信信息流带来的风险,我们引入了声明来源与验证(CPV)门,该门在下游复用前验证通信声明,可将违规率从70.0%降至36.6%。
英文摘要
Large Language Models (LLMs) are increasingly used as high-level planners in embodied multi-robot systems, enabling robots to interpret natural language instructions and coordinate executable actions. Yet, this growing reliance on LLM planners also raises security concerns. Prior work has focused mainly on individual robots, while communication risks in multi-robot collaboration remain insufficiently understood. Existing multi-robot studies are further limited to preliminary analysis under the Decentralized Multi-agent System (DMAS) architecture, so it remains unclear whether these risks persist across other common communication architectures and how attacker access settings shape their propagation. To fill this gap, we formulate two communication attacks corresponding to distinct attacker access settings: the External Entry Point Attack and the Privileged In-System Attack. We evaluate both attacks across DMAS, HMAS-1, and HMAS-2 using three LLMs and five embodied multi-robot tasks. Results show that unsafe information can turn into unsafe actions across all three architectures: DMAS reaches a 96.7\% entry endorsement rate and a 100\% post endorsement activation rate, HMAS-1 reaches a 97.8\% unsafe action success rate, and HMAS-2 triggers 88.3\% of task defined unsafe action slots. To mitigate risks from trusted information flow, we introduce the Claim Provenance and Verification (CPV) Gate, which verifies communicated claims before downstream reuse and reduces the violation rate from 70.0\% to 36.6\%.
Comments17 pages, 8 figures, 4 tables