首次系统揭示具身智能十大安全漏洞,暴露设备全链路风险
Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
- 通过蓝牙抓包、APK逆向等手段,跨三层架构发现10类漏洞
- 可实现设备劫持、命令注入、密钥泄露及物理控制权夺取
- 适合安全研究者与具身机器人平台开发者参考
具身智能系统将语言模型与现实感知、移动能力及云端移动端应用结合。尽管模型越狱问题已受关注,但其整体系统栈仍缺乏深入探索。本文首次对Unitree Go2平台进行全方位安全分析,识别出十类跨层漏洞,统称为“具身智能安全十大罪”。通过蓝牙嗅探、流量拦截、APK逆向工程、云接口测试和硬件探测,发现无线配置、核心模块与外部接口层面存在硬编码密钥、可预测握手令牌、WiFi凭证泄露、缺失TLS验证、静态SSH密码、多语言安全绕过行为、不安全本地中继通道、弱绑定逻辑及无限制固件访问等问题。这些缺陷使攻击者可劫持设备、注入任意指令、提取敏感信息或获得完全物理控制权。研究显示,保障具身智能安全远超模型对齐范畴。文中总结系统级经验教训,并提出构建软硬件协同鲁棒平台的建议。
原文摘要 · Abstract (English)
Embodied AI systems integrate language models with real world sensing, mobility, and cloud connected mobile apps. Yet while model jailbreaks have drawn significant attention, the broader system stack of embodied intelligence remains largely unexplored. In this work, we conduct the first holistic security analysis of the Unitree Go2 platform and uncover ten cross layer vulnerabilities the "Ten Sins of Embodied AI Security." Using BLE sniffing, traffic interception, APK reverse engineering, cloud API testing, and hardware probing, we identify systemic weaknesses across three architectural layers: wireless provisioning, core modules, and external interfaces. These include hard coded keys, predictable handshake tokens, WiFi credential leakage, missing TLS validation, static SSH password, multilingual safety bypass behavior, insecure local relay channels, weak binding logic, and unrestricted firmware access. Together, they allow adversaries to hijack devices, inject arbitrary commands, extract sensitive information, or gain full physical control.Our findings show that securing embodied AI requires far more than aligning the model itself. We conclude with system level lessons learned and recommendations for building embodied platforms that remain robust across their entire software hardware ecosystem.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。