LLM控制的多机器人系统通信漏洞可被利用,导致危险动作发生。
When Coordination Becomes a Threat: Communication Attacks in LLM-Controlled Multi-Robot Systems

- 设计两类通信攻击,模拟不同权限下的恶意信息注入
- 三种架构下攻击成功率超88%,最高达100%任务失败率
- 提出验证机制,将违规率从70%降至36.6%,适合安全关键场景
大型语言模型(LLMs)正越来越多地作为具身多机器人系统的高层规划器,使机器人能够理解自然语言指令并协同执行动作。然而,对LLM规划器的依赖也带来了安全风险。现有研究主要关注单个机器人,而多机器人协作中的通信风险尚未充分理解。已有研究局限于去中心化多智能体系统(DMAS)架构的初步分析,尚不清楚这些风险是否在其他常见通信架构中依然存在,以及攻击者权限如何影响风险传播。为填补这一空白,我们提出了两种对应不同攻击者访问权限的通信攻击:外部入口攻击与特权系统内攻击。我们在三种架构(DMAS、HMAS-1、HMAS-2)上,使用三种LLMs和五项具身多机器人任务评估了这两种攻击。结果表明,不安全信息可在所有架构中转化为不安全动作:DMAS达到96.7%的入口认可率和100%的动作激活率,HMAS-1实现97.8%的不安全动作成功率,HMAS-2触发了88.3%的任务定义不安全动作槽位。为缓解可信信息流带来的风险,我们引入了声明溯源与验证(CPV)门控机制,该机制在下游复用前验证通信内容,将违规率从70.0%降低至36.6%。
原文摘要 · Abstract (English)
Large Language Models (LLMs) are increasingly used as high-level planners in embodied multi-robot systems, enabling robots to interpret natural language instructions and coordinate executable actions. Yet, this growing reliance on LLM planners also raises security concerns. Prior work has focused mainly on individual robots, while communication risks in multi-robot collaboration remain insufficiently understood. Existing multi-robot studies are further limited to preliminary analysis under the Decentralized Multi-agent System (DMAS) architecture, so it remains unclear whether these risks persist across other common communication architectures and how attacker access settings shape their propagation. To fill this gap, we formulate two communication attacks corresponding to distinct attacker access settings: the External Entry Point Attack and the Privileged In-System Attack. We evaluate both attacks across DMAS, HMAS-1, and HMAS-2 using three LLMs and five embodied multi-robot tasks. Results show that unsafe information can turn into unsafe actions across all three architectures: DMAS reaches a 96.7\% entry endorsement rate and a 100\% post endorsement activation rate, HMAS-1 reaches a 97.8\% unsafe action success rate, and HMAS-2 triggers 88.3\% of task defined unsafe action slots. To mitigate risks from trusted information flow, we introduce the Claim Provenance and Verification (CPV) Gate, which verifies communicated claims before downstream reuse and reduces the violation rate from 70.0\% to 36.6\%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。