大模型驱动的具身智能体中的安全与隐私:攻击、防御与未来方向
Security and Privacy in Large-Model-Driven Embodied Agents: Attacks, Defenses, and Future Directions
浏览论文内容
中文总结 AI 辅助
本综述基于生命周期五阶段框架,系统分析大模型驱动的具身智能体面临的安全与隐私攻击、防御及评估方法,揭示端到端保护与现实评估的差距,并指出未来关键研究方向。
中文摘要 AI 辅助
大模型驱动的具身智能体将基础模型与感知、推理、规划及物理动作相结合,将传统模型层面的风险扩展至具身闭环中。现有关于其安全与隐私的研究在不同系统组件和操作阶段之间较为分散,难以理解风险如何产生、传播并最终影响物理行为或敏感信息。本综述提出了一种基于生命周期的分析方法,用于研究大模型驱动的具身智能体中的安全与隐私问题。我们将现有研究组织为五个阶段:模型构建与供应链、多模态输入与交互、语义推理与任务规划、动作执行与物理反馈,以及长期部署。在此生命周期内,我们系统性地回顾了代表性的攻击、防御和评估方法。我们的分析表明,攻击入口、后果实现和防御干预通常发生在具身闭环的不同阶段。进一步揭示了端到端保护、现实世界评估和长期隐私治理方面的重大差距。本综述为理解当前进展和识别保障大模型驱动的具身智能体安全的关键方向提供了统一视角。
英文摘要
Large-model-driven embodied agents integrate foundation models with perception, reasoning, planning, and physical action, extending conventional model-level risks into embodied closed loops. Existing studies on their security and privacy remain fragmented across different system components and operational stages, making it difficult to understand how risks arise, propagate, and ultimately affect physical behavior or sensitive information. This survey presents a lifecycle-based analysis of security and privacy in large-model-driven embodied agents. We organize existing research into five stages: model construction and supply chain, multimodal input and interaction, semantic reasoning and task planning, action execution and physical feedback, and long-term deployment. Within this lifecycle, we systematically review representative attacks, defenses, and evaluation methods. Our analysis shows that attack entry, consequence realization, and defense intervention often occur at different stages of the embodied closed loop. It further reveals substantial gaps in end-to-end protection, real-world evaluation, and long-term privacy governance. This survey provides a unified perspective for understanding current progress and identifying critical directions for securing large-model-driven embodied agents.
发表机构
- Xidian University(西安电子科技大学)
机构由 AI 辅助整理,请以论文原文为准。