系统梳理具身AI安全漏洞,揭示物理与软件攻击威胁。
Towards Robust and Secure Embodied AI: A Survey on Vulnerabilities and Attacks
- 区分外部攻击与内部缺陷,构建具身AI漏洞分类体系
- 分析感知、决策、交互环节的对抗攻击影响机制
- 聚焦大模型在具身系统中的越狱与指令误读风险
具身AI系统(如机器人和自动驾驶车辆)正广泛应用于现实场景,但其面临环境与系统层面的多重漏洞,表现为传感器欺骗、对抗攻击及任务与运动规划失败,严重威胁系统鲁棒性与安全性。现有综述多关注通用AI脆弱性或孤立问题,缺乏针对具身AI的统一框架。本综述填补这一空白:(1) 将具身AI漏洞分为外源性(如物理攻击、网络威胁)与内源性(如传感器故障、软件缺陷);(2) 系统分析具身AI特有的对抗攻击范式,重点探讨其对感知、决策与具身交互的影响;(3) 探讨大型视觉语言模型(LVLMs)与大型语言模型(LLMs)在具身系统中的攻击向量,如越狱攻击与指令误读;(4) 评估感知、决策与任务规划算法的鲁棒性挑战;(5) 提出提升具身AI安全性的针对性策略。通过整合上述维度,构建了理解具身AI脆弱性与安全性的综合框架。
原文摘要 · Abstract (English)
Embodied AI systems, including robots and autonomous vehicles, are increasingly integrated into real-world applications, where they encounter a range of vulnerabilities stemming from both environmental and system-level factors. These vulnerabilities manifest through sensor spoofing, adversarial attacks, and failures in task and motion planning, posing significant challenges to robustness and safety. Despite the growing body of research, existing reviews rarely focus specifically on the unique safety and security challenges of embodied AI systems. Most prior work either addresses general AI vulnerabilities or focuses on isolated aspects, lacking a dedicated and unified framework tailored to embodied AI. This survey fills this critical gap by: (1) categorizing vulnerabilities specific to embodied AI into exogenous (e.g., physical attacks, cybersecurity threats) and endogenous (e.g., sensor failures, software flaws) origins; (2) systematically analyzing adversarial attack paradigms unique to embodied AI, with a focus on their impact on perception, decision-making, and embodied interaction; (3) investigating attack vectors targeting large vision-language models (LVLMs) and large language models (LLMs) within embodied systems, such as jailbreak attacks and instruction misinterpretation; (4) evaluating robustness challenges in algorithms for embodied perception, decision-making, and task planning; and (5) proposing targeted strategies to enhance the safety and reliability of embodied AI systems. By integrating these dimensions, we provide a comprehensive framework for understanding the interplay between vulnerabilities and safety in embodied AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。