Pith. sign in

REVIEW 2 major objections 5 cited by

Safety of Embodied Navigation: A Survey

T0 review · 2 major / 0 minor · reviewed 2026-08-05 · deepseek-v4-flash

Pith's one-line read This survey argues that safety in embodied navigation—agents that perceive and move through real, unfamiliar environments—should be organized as attacks, defenses, and evaluation methods, and that verification frameworks are the field's mai

desk verdict The abstract describes a useful survey, but the supplied manuscript's full text is unreadable and headed as a different paper, so nothing beyond the abstract can be checked. read the letter →

arxiv 2508.05855 v1 pith:QLYXULY4 submitted 2025-08-07 cs.AI cs.RO

classification cs.AIcs.RO
keywords embodiednavigationsafetyadversarialattacksdefensemechanismsevaluationmethodologiesdatasetsandmetricsverificationframeworksLLM-drivenagents
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper takes the rapid advance of LLM-driven embodied AI as motivation and focuses on navigation, where agents must perceive, interact with, and adapt to unfamiliar environments while moving toward a target. It argues that because these systems will operate in dynamic real-world settings, safety must be studied as a field of its own rather than as an afterthought. To that end, it develops a three-part map of the literature: attack strategies, defense mechanisms, and evaluation methodologies. The intended contribution is an accurate synthesis of existing challenges, mitigation technologies, datasets, and metrics, together with a research agenda pointing to better evaluation and formal verification.

What carries the argument

The central object is the taxonomy of safety in embodied navigation, a tripartite classification into attack strategies, defense mechanisms, and evaluation methodologies. The taxonomy carries the argument by converting a scattered literature into a field-level map; the gaps it exposes—especially the absence of standardized evaluation and verification frameworks—are the paper's forward-looking findings.

What would settle it

Cross-check every entry in the survey's tables of attacks, defenses, datasets, and metrics against the original cited papers: any materially misclassified or missing entry undercuts the claim to a comprehensive map. Separately, resolving the arXiv identifier mismatch—the body's header reads 2508.05854 [quant-ph] rather than the submission's 2508.05855—would determine whether the body text belongs to this survey at all.

Watch

Extended reading notes

Core claim

Building on the observation that embodied navigation systems are being deployed in dynamic, unfamiliar, real-world environments, the survey's central claim is that their safety can and should be analyzed through three lenses: attack strategies (how an adversary can compromise an agent), defense mechanisms (how to resist or detect those compromises), and evaluation methodologies (datasets and metrics that measure effectiveness and robustness). It presents this tripartite analysis as a map of the current literature and argues that the map reveals unresolved problems—new attack classes, better mitigation strategies, more reliable evaluation, and formal verification frameworks. On the paper's ow

Load-bearing premise

The survey's central claim depends on its summaries of the cited literature being accurate and complete, and in the provided text that premise is unverifiable because the body is garbled and carries a header identifying a different paper.

Editorial extensions

If this is right

  • A common taxonomy makes it possible to compare attacks and defenses that currently live in separate papers, because each attack can be matched with the defense designed to stop it and the dataset or metric used to test it.
  • The survey's gap analysis implies that success rate alone is insufficient; evaluation must also count safety violations in unfamiliar environments.
  • The open problems named in the survey—new attack methods, better mitigations, reliable evaluation, verification frameworks—map to concrete research tasks rather than vague calls for safe AI.
  • If the field follows this agenda, safer embodied navigation becomes a prerequisite for critical applications, with the stated payoff of societal safety and industrial efficiency.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same attack-defense-evaluation structure could be lifted from navigation to related embodied tasks—manipulation, inspection, search and rescue—giving the survey a wider reach than its title claims.
  • A testable extension of the survey's gap analysis is that robustness measured in simulation will not predict robustness under physically plausible disturbances; benchmarks should include real-world or physics-grounded attacks, not only sensor-space perturbations.
  • Because the abstract motivates safety through LLMs, an implicit open question is whether attacks on the LLM planner are categorically different from attacks on perception; the taxonomy would be stronger if it separated them.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 0 minor

Summary. The submission presents only an abstract of a survey on safety in embodied navigation, claiming to review attack strategies, defense mechanisms, evaluation methodologies, datasets, and metrics, plus a research agenda. The full text supplied to the reviewer is unreadable mojibake, and the visible header reads 'arXiv:2508.05854v3 [quant-ph] 11 Jun 2026', which does not match the claimed paper identifier or category. Consequently, no substantive content could be audited.

Significance. If the intended paper were properly available, a systematic survey of embodied navigation safety could be a useful contribution, particularly the proposed synthesis of attacks, defenses, and evaluation frameworks. However, because the supplied artifact's body is inaccessible and appears to belong to a different paper, the significance of the actual submission cannot be assessed. No strengths in terms of machine-checked proofs, reproducible code, or verifiable taxonomies can be identified from the available material.

major comments (2)
  1. [Full text (visible header)] The complete body of the submission is corrupted, unreadable text, and the visible header 'arXiv:2508.05854v3 [quant-ph] 11 Jun 2026' does not match the claimed identifier arXiv:2508.05855 (cs.AI). Under the reviewing rule that all manuscript passages are in-scope evidence, this is not a pipeline artifact: it means the document under review is not the claimed survey. The paper's central claim—that it provides a comprehensive analysis of embodied navigation safety—cannot be checked for coverage, citation accuracy, or correctness of the taxonomy. This is a load-bearing defect that no revision can fix short of replacing the entire artifact with the intended paper.
  2. [Abstract] The abstract asserts a 'comprehensive analysis' of attack strategies, defense mechanisms, evaluation methodologies, datasets, and metrics, but none of these elements appear in the readable material. Given the full-text corruption, the assertion is unverifiable and currently unsupported. If the correct manuscript is resubmitted, the authors should ensure that the abstract's claims of comprehensiveness are backed by explicit sections, tables, and citations.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity identified: the readable abstract makes a survey claim, not a derived result, and the supplied unreadable/mismatched body prevents any content-level circularity audit without providing evidence of one.

full rationale

The submission is a survey. The only substantive readable content is the abstract, which claims to provide a comprehensive analysis of attack strategies, defense mechanisms, and evaluation methodologies for embodied-navigation safety. A survey does not derive a technical result from its own inputs; its value lies in coverage, organization, and synthesis of cited literature. No equations, fitted parameters, uniqueness theorems, or self-citation chains are visible in the supplied text, so none of the enumerated circularity patterns can be established with the required quote-and-reduction evidence. The full text is mojibake and the visible arXiv header reads 'arXiv:2508.05854v3 [quant-ph] 11 Jun 2026', which does not match the claimed identifier arXiv:2508.05855 (cs.AI). This is a serious provenance and verifiability problem: the body of the claimed survey cannot be audited from the supplied artifact. However, the mismatch and unreadability are not circularity. They do not show that a claimed output is equivalent by construction to its input. The proper finding is therefore no circularity identifiable from the abstract, with the body-level audit blocked by the corrupted and mismatched full text. If a readable, correctly matched version is supplied, the analysis should be revisited.

Assumptions & free parameters 0 free parameters · 2 assumptions · 0 invented entities

The central claim of this survey rests on the reliability of its synthesis of prior literature. In the abstract, the load-bearing inputs are: (1) the cited attack strategies, defense mechanisms, datasets, and metrics exist as described, and (2) the paper correctly summarizes them. Because the full text is unreadable in the supplied form, neither input can be audited. No free parameters or invented entities appear in a survey of this kind. The two listed axioms capture the dependence on faithful representation of the cited literature and on the completeness of the organizing taxonomy.

assumptions (2)
  • domain assumption The cited primary works on embodied navigation safety are accurately summarized and representative of the field.
    A survey's value rests on faithful representation of prior literature, which is claimed in the abstract but cannot be checked because the supplied full text is unreadable.
  • domain assumption The three-part organization (attacks, defenses, evaluation) and the listed open problems (verification frameworks, etc.) cover the important work in the area.
    The abstract asserts comprehensiveness ('comprehensive analysis from multiple perspectives'), but no completeness criteria or comparison with prior taxonomies are visible in the abstract.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Safety of Embodied Navigation: A Survey." pith.science (2026). https://pith.science/paper/QLYXULY4

@misc{pith2026250805855,
  author       = {Pith},
  title        = {Pith review of: Safety of Embodied Navigation: A Survey},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/QLYXULY4}},
  note         = {Machine review of arXiv:2508.05855}
}
read the original abstract

As large language models (LLMs) continue to advance and gain influence, the development of embodied AI has accelerated, drawing significant attention, particularly in navigation scenarios. Embodied navigation requires an agent to perceive, interact with, and adapt to its environment while moving toward a specified target in unfamiliar settings. However, the integration of embodied navigation into critical applications raises substantial safety concerns. Given their deployment in dynamic, real-world environments, ensuring the safety of such systems is critical. This survey provides a comprehensive analysis of safety in embodied navigation from multiple perspectives, encompassing attack strategies, defense mechanisms, and evaluation methodologies. Beyond conducting a comprehensive examination of existing safety challenges, mitigation technologies, and various datasets and metrics that assess effectiveness and robustness, we explore unresolved issues and future research directions in embodied navigation safety. These include potential attack methods, mitigation strategies, more reliable evaluation techniques, and the implementation of verification frameworks. By addressing these critical gaps, this survey aims to provide valuable insights that can guide future research toward the development of safer and more reliable embodied navigation systems. Furthermore, the findings of this study have broader implications for enhancing societal safety and increasing industrial efficiency.

Discussion (0). Sign in to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. ForesightSafety-VLA: A Unified Diagnostic Safety Benchmark for Vision-Language-Action Models

    cs.RO 2026-06 unverdicted novelty 7.0 of 10

    ForesightSafety-VLA is a new benchmark with 13 safety categories, cumulative cost and risk exposure metrics, and controlled variations to diagnose safety failures in VLA models rather than aggregate task success.

  2. ForesightSafety-VLA: A Unified Diagnostic Safety Benchmark for Vision-Language-Action Models

    cs.RO 2026-06 unverdicted novelty 7.0 of 10

    ForesightSafety-VLA creates a diagnostic benchmark for VLA safety with taxonomy across physical, language, and visual risks, showing perception and structure variations cause more safety degradation than language chan...

  3. AdvNav: Behavior-Guided Black-Box Adversarial Attacks on Vision-Language Navigation

    cs.AI 2026-07 conditional novelty 6.0 of 10

    AdvNav disrupts multi-step vision-language navigation with gradient-free, behavior-guided visual noise, reaching 49.7–87.3% attack success on HAMT and MapGPT without model internals.

  4. AdvNav: Behavior-Guided Black-Box Adversarial Attacks on Vision-Language Navigation

    cs.AI 2026-07 conditional novelty 6.0 of 10

    AdvNav is a gradient-free attack that overlays Perlin noise on a VLN agent's camera and uses behavior feedback plus genetic search, breaking 49.70-87.30% of successful R2R navigations.

  5. Security of World-Model-Based Embodied AI: A Lifecycle of Threats, Defenses, and Evaluation

    cs.CR 2026-07 conditional novelty 5.5 of 10

    World-model-based embodied AI creates a predictive security boundary where attacks on data, sensors, imagination, ranking, and feedback can turn into unsafe physical action and false safety certificates.

Reference graph

Works this paper leans on

52 extracted references · 48 canonical work pages · cited by 3 Pith papers

  1. [1]

    Synthesizing robust adversarial examples

    Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. Synthesizing robust adversarial examples. In ICML , 2018

  2. [2]

    Adversarial patch

    Tom B Brown, Dandelion Man \'e , Aurko Roy, Mart \' n Abadi, and Justin Gilmer. Adversarial patch. arXiv , 2017

  3. [3]

    Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector

    Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng (Polo) Chau. Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. In ECML PKDD , 2018

  4. [4]

    Towards physically-realizable adversarial attacks in embodied vision navigation

    Meng Chen, Jiawei Tu, Chao Qi, Yonghao Dang, Feng Zhou, Wei Wei, and Jianqin Yin. Towards physically-realizable adversarial attacks in embodied vision navigation. arXiv preprint arXiv:2409.10071 , 2024

  5. [5]

    Embodiedeval: Evaluate multimodal llms as embodied agents

    Zhili Cheng, Yuge Tu, Ran Li, Shiqi Dai, Jinyi Hu, Shengding Hu, Jiahao Li, Yang Shi, Tianyu Yu, Weize Chen, et al. Embodiedeval: Evaluate multimodal llms as embodied agents. arXiv , 2025

  6. [6]

    Lota-bench: Benchmarking language-oriented task planners for embodied agents

    Jae-Woo Choi, Youngwoo Yoon, Hyobin Ong, Jaehong Kim, and Minsu Jang. Lota-bench: Benchmarking language-oriented task planners for embodied agents. arXiv , 2024

  7. [7]

    Safeguarding large language models: A survey

    Yi Dong, Ronghui Mu, Yanghao Zhang, Siqi Sun, Tianle Zhang, Changshun Wu, Gaojie Jin, Yi Qi, Jinwei Hu, Jie Meng, et al. Safeguarding large language models: A survey. arXiv , 2024

  8. [8]

    Adversarial laser spot: Robust and covert physical-world attack to dnns

    Chengyin Hu, Yilong Wang, Kalibinuer Tiliwalidi, and Wen Li. Adversarial laser spot: Robust and covert physical-world attack to dnns. In ACML , 2023

Show all 52 references
  1. [9]

    Physically realizable natural-looking clothing textures evade person detectors via 3d modeling

    Zhanhao Hu, Wenda Chu, Xiaopei Zhu, Hui Zhang, Bo Zhang, and Xiaolin Hu. Physically realizable natural-looking clothing textures evade person detectors via 3d modeling. In CVPR , 2023

  2. [10]

    Spaa: Stealthy projector-based adversarial attacks on deep image classifiers

    Bingyao Huang and Haibin Ling. Spaa: Stealthy projector-based adversarial attacks on deep image classifiers. In IEEE VR , 2022

  3. [11]

    Inner monologue: Embodied reasoning through planning with language models

    Wenlong Huang, Fei Xia, Ted Xiao, Harris Chan, Jacky Liang, Pete Florence, Andy Zeng, Jonathan Tompson, Igor Mordatch, Yevgen Chebotar, et al. Inner monologue: Embodied reasoning through planning with language models. arXiv , 2022

  4. [12]

    A survey of safety and trustworthiness of large language models through the lens of verification and validation

    Xiaowei Huang, Wenjie Ruan, Wei Huang, Gaojie Jin, Yi Dong, Changshun Wu, Saddek Bensalem, Ronghui Mu, Yi Qi, Xingyu Zhao, et al. A survey of safety and trustworthiness of large language models through the lens of verification and validation. Artificial Intelligence Review , 2024

  5. [13]

    Towards transferable targeted 3d adversarial attack in the physical world, 2024

    Yao Huang, Yinpeng Dong, Shouwei Ruan, Xiao Yang, Hang Su, and Xingxing Wei. Towards transferable targeted 3d adversarial attack in the physical world, 2024

  6. [14]

    Exploring backdoor attacks against large language model-based decision making

    Ruochen Jiao, Shaoyuan Xie, Justin Yue, Takami Sato, Lixu Wang, Yixuan Wang, Qi Alfred Chen, and Qi Zhu. Exploring backdoor attacks against large language model-based decision making. arXiv , 2024

  7. [15]

    Goat-bench: A benchmark for multi-modal lifelong navigation

    Mukul Khanna, Ram Ramrakhya, Gunjan Chhablani, Sriram Yenamandra, Theophile Gervet, Matthew Chang, Zsolt Kira, Devendra Singh Chaplot, Dhruv Batra, and Roozbeh Mottaghi. Goat-bench: A benchmark for multi-modal lifelong navigation. In CVPR , 2024

  8. [16]

    Realfred: An embodied instruction following benchmark in photo-realistic environments

    Taewoong Kim, Cheolhong Min, Byeonghwi Kim, Jinyeon Kim, Wonje Jeung, and Jonghyun Choi. Realfred: An embodied instruction following benchmark in photo-realistic environments. In ECCV , 2024

  9. [17]

    Adversarial examples in the physical world

    Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. Adversarial examples in the physical world. In Artificial intelligence safety and security , pages 99--112. Chapman and Hall/CRC, 2018

  10. [18]

    Generative dynamic patch attack, 2021

    Xiang Li and Shihao Ji. Generative dynamic patch attack, 2021

  11. [19]

    Towards benchmarking and assessing visual naturalness of physical world adversarial attacks

    Simin Li, Shuning Zhang, Gujun Chen, Dong Wang, Pu Feng, Jiakai Wang, Aishan Liu, Xin Yi, and Xianglong Liu. Towards benchmarking and assessing visual naturalness of physical world adversarial attacks. In CVPR , 2023

  12. [20]

    Behavior-1k: A human-centered, embodied ai benchmark with 1,000 everyday activities and realistic simulation

    Chengshu Li, Ruohan Zhang, Josiah Wong, Cem Gokmen, Sanjana Srivastava, Roberto Mart \' n-Mart \' n, Chen Wang, Gabrael Levine, Wensi Ai, Benjamin Martinez, et al. Behavior-1k: A human-centered, embodied ai benchmark with 1,000 everyday activities and realistic simulation. arX...

  13. [21]

    Maybank, and Dacheng Tao

    Aishan Liu, Tairan Huang, Xianglong Liu, Yitao Xu, Yuqing Ma, Xinyun Chen, Stephen J. Maybank, and Dacheng Tao. Spatiotemporal attacks for embodied agents, 2020

  14. [22]

    Exploring the robustness of decision-level through adversarial attacks on llm-based embodied models

    Shuyuan Liu, Jiawei Chen, Shouwei Ruan, Hang Su, and Zhaoxia Yin. Exploring the robustness of decision-level through adversarial attacks on llm-based embodied models. In ICM , 2024

  15. [23]

    From screens to scenes: A survey of embodied ai in healthcare

    Yihao Liu, Xu Cao, Tingting Chen, Yankai Jiang, Junjie You, Minghua Wu, Xiaosong Wang, Mengling Feng, Yaochu Jin, and Jintai Chen. From screens to scenes: A survey of embodied ai in healthcare. arXiv , 2025

  16. [24]

    Poex: Policy executable embodied ai jailbreak attacks

    Xuancun Lu, Zhengxian Huang, Xinfeng Li, Wenyuan Xu, et al. Poex: Policy executable embodied ai jailbreak attacks. arXiv , 2024

  17. [25]

    Privacy and robustness in federated learning: Attacks and defenses

    Lingjuan Lyu, Han Yu, Xingjun Ma, Chen Chen, Lichao Sun, Jun Zhao, Qiang Yang, and S Yu Philip. Privacy and robustness in federated learning: Attacks and defenses. TNNLS , 2022

  18. [26]

    Memory-augmented reinforcement learning for image-goal navigation

    Lina Mezghan, Sainbayar Sukhbaatar, Thibaut Lavril, Oleksandr Maksymets, Dhruv Batra, Piotr Bojanowski, and Karteek Alahari. Memory-augmented reinforcement learning for image-goal navigation. In IROS , 2022

  19. [27]

    Reward certification for policy smoothed reinforcement learning

    Ronghui Mu, Leandro Soriano Marcolino, Yanghao Zhang, Tianle Zhang, Xiaowei Huang, and Wenjie Ruan. Reward certification for policy smoothed reinforcement learning. In Proceedings of the AAAI Conference on Artificial Intelligence , volume 38, pages 21429--21437, 2024

  20. [28]

    Llm-assist: Enhancing closed-loop planning with language-based reasoning

    SP Sharan, Francesco Pittaluga, Manmohan Chandraker, et al. Llm-assist: Enhancing closed-loop planning with language-based reasoning. arXiv , 2023

  21. [29]

    Embodied laser attack: Leveraging scene priors to achieve agent-based robust non-contact attacks

    Yitong Sun, Yao Huang, and Xingxing Wei. Embodied laser attack: Leveraging scene priors to achieve agent-based robust non-contact attacks. In ICM , 2024

  22. [30]

    Active: Towards highly transferable 3d physical camouflage for universal and robust vehicle evasion, 2023

    Naufal Suryanto, Yongsu Kim, Harashta Tatimma Larasati, Hyoeun Kang, Thi-Thu-Huong Le, Yoonyoung Hong, Hunmin Yang, Se-Yoon Oh, and Howon Kim. Active: Towards highly transferable 3d physical camouflage for universal and robust vehicle evasion, 2023

  23. [31]

    Fca: Learning a 3d full-coverage vehicle camouflage for multi-view physical adversarial attack, 2021

    Donghua Wang, Tingsong Jiang, Jialiang Sun, Weien Zhou, Xiaoya Zhang, Zhiqiang Gong, Wen Yao, and Xiaoqian Chen. Fca: Learning a 3d full-coverage vehicle camouflage for multi-view physical adversarial attack, 2021

  24. [32]

    Trojanrobot: Physical-world backdoor attacks against vlm-based robotic manipulation

    Xianlong Wang, Hewen Pan, Hangtao Zhang, Minghui Li, Shengshan Hu, Ziqi Zhou, Lulu Xue, Peijin Guo, Yichen Wang, Wei Wan, et al. Trojanrobot: Physical-world backdoor attacks against vlm-based robotic manipulation. arXiv , 2024

  25. [33]

    Divscene: Benchmarking lvlms for object navigation with diverse scenes and objects

    Zhaowei Wang, Hongming Zhang, Tianqing Fang, Ye Tian, Yue Yang, Kaixin Ma, Xiaoman Pan, Yangqiu Song, and Dong Yu. Divscene: Benchmarking lvlms for object navigation with diverse scenes and objects. arXiv preprint arXiv:2410.02730 , 2024

  26. [34]

    Distributional modeling for location-aware adversarial patches, 2023

    Xingxing Wei, Shouwei Ruan, Yinpeng Dong, and Hang Su. Distributional modeling for location-aware adversarial patches, 2023

  27. [35]

    Jailbroken: How does llm safety training fail? NeurIPSs , 2024

    Alexander Wei, Nika Haghtalab, and Jacob Steinhardt. Jailbroken: How does llm safety training fail? NeurIPSs , 2024

  28. [36]

    Physical adversarial textures that fool visual object tracking, 2019

    Rey Reza Wiyatno and Anqi Xu. Physical adversarial textures that fool visual object tracking, 2019

  29. [37]

    Embodied active defense: Leveraging recurrent feedback to counter adversarial patches

    Lingxuan Wu, Xiao Yang, Yinpeng Dong, Liuwei Xie, Hang Su, and Jun Zhu. Embodied active defense: Leveraging recurrent feedback to counter adversarial patches. arXiv , 2024

  30. [38]

    Napguard: Towards detecting naturalistic adversarial patches

    Siyang Wu, Jiakai Wang, Jiejie Zhao, Yazhe Wang, and Xianglong Liu. Napguard: Towards detecting naturalistic adversarial patches. In CVPR , 2024

  31. [39]

    \ PatchGuard \ : A provably robust defense against adversarial patches via small receptive fields and masking

    Chong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal. \ PatchGuard \ : A provably robust defense against adversarial patches via small receptive fields and masking. In USENIX , 2021

  32. [40]

    \ PatchCURE \ : Improving certifiable robustness, model utility, and computation efficiency of adversarial patch defenses

    Chong Xiang, Tong Wu, Sihui Dai, Jonathan Petit, Suman Jana, and Prateek Mittal. \ PatchCURE \ : Improving certifiable robustness, model utility, and computation efficiency of adversarial patch defenses. In USENIX , 2024

  33. [41]

    Adversarial t-shirt! evading person detectors in a physical world, 2020

    Kaidi Xu, Gaoyuan Zhang, Sijia Liu, Quanfu Fan, Mengshu Sun, Hongge Chen, Pin-Yu Chen, Yanzhi Wang, and Xue Lin. Adversarial t-shirt! evading person detectors in a physical world, 2020

  34. [42]

    Patchzero: Defending against adversarial patch attacks by detecting and zeroing the patch

    Ke Xu, Yao Xiao, Zhaoheng Zheng, Kaijie Cai, and Ram Nevatia. Patchzero: Defending against adversarial patch attacks by detecting and zeroing the patch. In WACV , 2023

  35. [43]

    Hijacking vision-and-language navigation agents with adversarial environmental attacks

    Zijiao Yang, Xiangxi Shi, Eric Slyman, and Stefan Lee. Hijacking vision-and-language navigation agents with adversarial environmental attacks. arXiv , 2024

  36. [44]

    Safeagentbench: A benchmark for safe task planning of embodied llm agents

    Sheng Yin, Xianghe Pang, Yuanzhuo Ding, Menglan Chen, Yutong Bi, Yichen Xiong, Wenhao Huang, Zhen Xiang, Jing Shao, and Siheng Chen. Safeagentbench: A benchmark for safe task planning of embodied llm agents. arXiv preprint arXiv:2412.13178 , 2024

  37. [45]

    Consistent attack: Universal adversarial perturbation on embodied vision navigation

    Chengyang Ying, You Qiaoben, Xinning Zhou, Hang Su, Wenbo Ding, and Jianyong Ai. Consistent attack: Universal adversarial perturbation on embodied vision navigation. Pattern Recognition Letters , 168, 2023

  38. [46]

    Xiaohui Zeng, Chenxi Liu, Yu-Siang Wang, Weichao Qiu, Lingxi Xie, Yu-Wing Tai, Chi Keung Tang, and Alan L. Yuille. Adversarial attacks beyond the image space, 2019

  39. [47]

    Navigation as attackers wish? towards building byzantine-robust embodied agents under federated learning

    Yunchao Zhang, Zonglin Di, Kaiwen Zhou, Cihang Xie, and Xin Eric Wang. Navigation as attackers wish? towards building byzantine-robust embodied agents under federated learning. arXiv , 2022

  40. [48]

    Badrobot: Manipulating embodied llms in the physical world

    Hangtao Zhang, Chenyu Zhu, Xianlong Wang, Ziqi Zhou, Changgan Yin, Minghui Li, Lulu Xue, Yichen Wang, Shengshan Hu, Aishan Liu, et al. Badrobot: Manipulating embodied llms in the physical world. arXiv , 2024

  41. [49]

    Fu, Qinhong Jiang, Chen Yan, Sze-Yiu Chau, Grace Ngai, Hong-Va Leong, Xiapu Luo, and Wenyuan Xu

    Youqian Zhang, Chunxi Yang, Eugene Y. Fu, Qinhong Jiang, Chen Yan, Sze-Yiu Chau, Grace Ngai, Hong-Va Leong, Xiapu Luo, and Wenyuan Xu. Understanding impacts of electromagnetic signal injection attacks on object detection, 2024

  42. [50]

    Vision-and-language navigation today and tomorrow: A survey in the era of foundation models

    Yue Zhang, Ziqiao Ma, Jialu Li, Yanyuan Qiao, Zun Wang, Joyce Chai, Qi Wu, Mohit Bansal, and Parisa Kordjamshidi. Vision-and-language navigation today and tomorrow: A survey in the era of foundation models. arXiv , 2024

  43. [51]

    Earbench: Towards evaluating physical risk awareness for task planning of foundation model-based embodied ai agents, 2024

    Zihao Zhu, Bingzhe Wu, Zhengyou Zhang, Lei Han, Qingshan Liu, and Baoyuan Wu. Earbench: Towards evaluating physical risk awareness for task planning of foundation model-based embodied ai agents, 2024

  44. [52]

    write newline

    " write newline "" before.all 'output.state := FUNCTION fin.entry add.period write newline FUNCTION new.block output.state before.all = 'skip after.block 'output.state := if FUNCTION new.sentence output.state after.block = 'skip output.state before.all = 'skip after.sentence '...

Pith tools

Reviewed August 5, 2026 · model on record in the stance chip above.