用大模型当裁判,检测机器人任务计划的隐藏攻击
PROTEA: Securing Robot Task Planning and Execution
- 让大模型评估任务计划的安全性,解决评估维度多、历史依赖难题
- 在隐蔽性不同的恶意计划上测试,验证防御机制有效性
- 适合关注机器人安全与可信执行的开发者和研究者
机器人需通过任务规划生成复杂任务的动作序列。近期研究表明,基于基础模型的现有任务规划器存在显著安全漏洞,易受对抗攻击。本文提出PROTEA,一种基于大语言模型的评判式防御机制,用于评估任务计划的安全性。该方法针对计划安全性评估中的维度高和历史依赖难题进行设计。我们采用不同大模型实现多个版本的PROTEA以作对比。为系统评估,构建了一个包含良性与恶意任务计划的数据集,其中危害行为以不同隐蔽程度注入。实验结果为机器人系统从业者提升任务规划系统的鲁棒性与安全性提供了可操作的洞察。完整细节、数据集及演示见:https://protea-secure.github.io/PROTEA/
原文摘要 · Abstract (English)
Robots need task planning methods to generate action sequences for complex tasks. Recent work on adversarial attacks has revealed significant vulnerabilities in existing robot task planners, especially those built on foundation models. In this paper, we aim to address these security challenges by introducing PROTEA, an LLM-as-a-Judge defense mechanism, to evaluate the security of task plans. PROTEA is developed to address the dimensionality and history challenges in plan safety assessment. We used different LLMs to implement multiple versions of PROTEA for comparison purposes. For systemic evaluations, we created a dataset containing both benign and malicious task plans, where the harmful behaviors were injected at varying levels of stealthiness. Our results provide actionable insights for robotic system practitioners seeking to enhance robustness and security of their task planning systems. Details, dataset and demos are provided: https://protea-secure.github.io/PROTEA/
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。