arXiv:2602.17345cs.CRcs.AI2026-02被引 6

揭示具身AI安全失效的深层原因:系统级错配远比模型漏洞更致命。

What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?

  • 提出四类系统级错配机制,解释为何传统防御失效
  • 小误差在感知-决策-执行环中放大,导致全局不安全
  • 适合关注具身AI安全、机器人与自动驾驶的研究者

具身AI系统(如自动驾驶、服务机器人、大语言模型驱动的交互代理)正快速从受控环境走向关键安全场景。与非具身AI不同,其故障会引发不可逆物理后果,对安全、可靠性和鲁棒性提出严峻挑战。现有研究多从大语言模型(LLM)漏洞或经典网络物理系统(CPS)故障视角分析,但本文认为这些视角均不足以解释现代具身系统的诸多崩溃现象。我们提出,大量故障源于具身带来的系统级不匹配,而非孤立的模型缺陷或传统攻击。具体识别出四大核心洞察:(i) 语义正确不等于物理安全,因语言推理忽略几何、动力学与接触约束;(ii) 相同动作在不同物理状态下可能产生截然不同结果,源于非线性动力学与状态不确定性;(iii) 小误差在紧密耦合的感知-决策-行动闭环中传播并放大;(iv) 安全性不具有时间或层级上的可组合性,局部安全决策可能累积为全局危险行为。这表明,保障具身AI需超越组件级防御,转向对物理风险、不确定性和故障传播的系统级建模与推理。

原文摘要 · Abstract (English)

Embodied AI systems (e.g., autonomous vehicles, service robots, and LLM-driven interactive agents) are rapidly transitioning from controlled environments to safety critical real-world deployments. Unlike disembodied AI, failures in embodied intelligence lead to irreversible physical consequences, raising fundamental questions about security, safety, and reliability. While existing research predominantly analyzes embodied AI through the lenses of Large Language Model (LLM) vulnerabilities or classical Cyber-Physical System (CPS) failures, this survey argues that these perspectives are individually insufficient to explain many observed breakdowns in modern embodied systems. We posit that a significant class of failures arises from embodiment-induced system-level mismatches, rather than from isolated model flaws or traditional CPS attacks. Specifically, we identify four core insights that explain why embodied AI is fundamentally harder to secure: (i) semantic correctness does not imply physical safety, as language-level reasoning abstracts away geometry, dynamics, and contact constraints; (ii) identical actions can lead to drastically different outcomes across physical states due to nonlinear dynamics and state uncertainty; (iii) small errors propagate and amplify across tightly coupled perception-decision-action loops; and (iv) safety is not compositional across time or system layers, enabling locally safe decisions to accumulate into globally unsafe behavior. These insights suggest that securing embodied AI requires moving beyond component-level defenses toward system-level reasoning about physical risk, uncertainty, and failure propagation.

具身AI系统安全风险传播物理安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。