REVIEW 1 major objections 4 minor 2 cited by
Embodied AI safety is organized by a capability-risk duality: deeper autonomy expands the attack surface, and inner-layer failures cascade outward.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.5
2026-07-13 17:03 UTC pith:VICWIOCY
load-bearing objection A large, usable survey that finally maps digital attacks onto closed-loop physical risk under one capability-risk stack; the taxonomy is the real product. the 1 major comments →
Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
A multi-level taxonomy built on the capability-risk duality unifies fragmented embodied-safety research across perception, cognition, planning, action and interaction, and agentic systems, connects it to broader vision-language work, and surfaces critical gaps that existing digital-only surveys miss.
What carries the argument
Capability-risk duality (deeper capability entails broader risk) together with the five-layer pipeline taxonomy: perception, cognition, planning, action & interaction, and agentic systems. This structure assigns attacks and defenses, traces cascade paths, and exposes gaps.
Load-bearing premise
That the nested capability layers and their cascade of inner-to-outer failures form a complete, non-overlapping way to organize the whole literature so that papers can be cleanly assigned and gaps reliably named.
What would settle it
A substantial body of high-impact embodied-safety results that cannot be placed in any of the five layers without forced double-counting or that demonstrate cascade patterns opposite to the claimed inner-to-outer flow.
If this is right
- Safety evaluation protocols must test cascade paths from sensor spoofing through planning to physical action rather than isolated modules.
- Defenses for multimodal fusion and jailbreak-resistant planning become first-order research priorities for any deployable robot.
- Human-agent interaction and agentic tool/memory layers require dedicated risk-aware design, not just bolted-on filters.
- Standards and benchmarks for embodied systems will need to adopt the layered taxonomy to compare claims across platforms.
- Roadmaps for foundation-model robots can treat safety as an intrinsic property of the full sense-think-act loop instead of an afterthought.
Where Pith is reading between the lines
- If the cascade model holds, certification of commercial robots should require red-team tests that begin at the sensor and end at the actuator, not separate module audits.
- The same duality may apply to non-robotic cyber-physical systems (smart factories, medical devices), suggesting a portable evaluation template.
- Overlooked gaps in open-ended human trust and multi-agent collusion imply that social-safety benchmarks will become as necessary as collision-avoidance tests.
- A natural next experiment is a controlled sim-to-real study that injects a single inner-layer attack and measures how far the failure propagates under different fusion and planning defenses.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This survey reviews safety research in embodied AI across the full pipeline of perception, cognition, planning, action & interaction, and agentic systems. It organizes the literature via a multi-level taxonomy grounded in a capability–risk duality (deeper capability entails broader risk; Figure 1), synthesizes over 500 papers on adversarial, backdoor, jailbreak, and hardware attacks plus defenses, and contrasts the contribution with nine prior surveys. The manuscript identifies overlooked challenges (multimodal fusion fragility, planning instability under jailbreaks, open-ended HRI trustworthiness) and closes with open challenges and future trends as a deployment roadmap.
Significance. If the synthesis holds, the paper supplies a usable organizing frame for a rapidly expanding, previously fragmented literature that spans robotics, foundation-model safety, and physical-world risk. Strengths include explicit comparison to nine prior surveys, dense citation tables that quantify attack/defense coverage per layer (Figure 4 and Tables 1–18), concrete gap statements (e.g., sparse backdoor defenses for spatial/auditory perception and VLAs), and a public GitHub resource. The capability–risk duality and cascade emphasis (Table 1, §6.4) give practitioners a clearer map of where inner-layer failures amplify. For a survey venue this is a substantial consolidating contribution rather than a theorem or new empirical result.
major comments (1)
- The central claim is organizational synthesis under the capability–risk duality (Figure 1, §§1–6), not a theorem that the five layers are exhaustive or non-overlapping. The manuscript already notes cascade/cross-layer effects (Table 1, §6.4) and places multi-agent material in both planning (§4.3) and action (§5.3) with scope notes. Residual overlaps therefore do not falsify the synthesis; no load-bearing inconsistency that would require major revision of the taxonomy was found.
minor comments (4)
- §1 and the abstract state “over 500 papers” without an explicit inclusion/exclusion protocol or search window; a short methods paragraph would improve reproducibility of the corpus.
- Figure 3 strip widths are said to be proportional to paper counts, but absolute counts per strip are not tabulated; adding them would make the distribution claim checkable.
- Occasional typographic issues remain (e.g., “hijacking,” “Hijack,” mixed en-dashes); a final copy-edit pass would help.
- Some very recent 2026 entries appear only as arXiv preprints; flagging preprint status in the tables would set reader expectations.
Circularity Check
No significant circularity; the multi-level taxonomy is an organizational framing imposed on independently published attack/defense papers, not a derivation that reduces to its own inputs by construction.
full rationale
This is a survey that synthesizes >500 external papers into a capability-risk duality taxonomy (Figure 1, Sections 1-6) spanning perception through agentic systems. The taxonomy does not redefine success metrics, force empirical results, or derive predictions from fitted parameters; it merely assigns existing independent works (adversarial, backdoor, jailbreak, sensor, etc.) to layers and notes cascades (Table 1, Section 6.4). Self-citations of the authors' own attack/defense papers appear as ordinary literature entries, not as load-bearing uniqueness theorems or sole support for the organizing principle. No equations, fitted inputs called predictions, self-definitional loops, or ansatz smuggling via citation chains exist. The paper is self-contained as literature organization and gap identification; residual overlaps (e.g., multi-agent material in both planning and action) are explicitly scoped rather than hidden. Score 0 is therefore the correct, proportionate finding.
Axiom & Free-Parameter Ledger
axioms (3)
- domain assumption Perception errors propagate and amplify through cognition, planning, and action, so inner-layer vulnerabilities cascade to outer-layer physical harm.
- domain assumption Embodied agents operate under uncertain sensing, incomplete knowledge, and dynamic human-robot interaction where failures can cause physical harm, distinguishing them from digital-only AI.
- ad hoc to paper The five capability layers (perception, cognition, planning, action & interaction, agentic system) are jointly exhaustive and sufficiently non-overlapping for taxonomy construction.
invented entities (1)
-
Capability-risk duality / multi-level taxonomy of embodied AI safety
no independent evidence
read the original abstract
Embodied Artificial Intelligence (Embodied AI) integrates perception, cognition, planning, and interaction into agents that operate in open-world, safety-critical environments. As these systems gain autonomy and enter domains such as transportation, healthcare, and industrial or assistive robotics, ensuring their safety becomes both technically challenging and socially indispensable. Unlike digital AI systems, embodied agents must act under uncertain sensing, incomplete knowledge, and dynamic human-robot interactions, where failures can directly lead to physical harm. This survey provides a comprehensive and structured review of safety research in embodied AI, examining attacks and defenses across the full embodied pipeline, from perception and cognition to planning, action and interaction, and agentic system. We introduce a multi-level taxonomy that unifies fragmented lines of work and connects embodied-specific safety findings with broader advances in vision, language, and multimodal foundation models. Our review synthesizes insights from over 500 papers spanning adversarial, backdoor, jailbreak, and hardware-level attacks; attack detection, safe training and robust inference; and risk-aware human-agent interaction. This analysis reveals several overlooked challenges, including the fragility of multimodal perception fusion, the instability of planning under jailbreak attacks, and the trustworthiness of human-agent interaction in open-ended scenarios. By organizing the field into a coherent framework and identifying critical research gaps, this survey provides a roadmap for building embodied agents that are not only capable and autonomous but also safe, robust, and reliable in real-world deployment.
Forward citations
Cited by 2 Pith papers
-
Towards Trustworthy Embodied Intelligence: A Systems Framework and Graded Trustworthiness Levels
A four-layer systems framework and T0–T5 hierarchy for grading and maintaining bounded trustworthiness claims in embodied AI systems.
-
Physical AI Governance: From Theory to Practice Across Life Cycle
A survey that organizes Physical AI governance into five principles and a five-stage lifecycle, with stage-specific operational practices.
Reference graph
Works this paper leans on
-
[1]
Hadi Abdullah, Washington Garcia, Christian Peeters, Patrick Traynor, Kevin RB Butler, and Joseph Wilson. Practical hidden voice attacks against speech and speaker recognition systems.arXiv preprint arXiv:1904.05734, 2019
Pith/arXiv arXiv 1904
-
[2]
Vision-onlyrobotnavigationinaneuralradianceworld.IEEERoboticsandAutomationLetters(RA-L), 2022
Michal Adamkiewicz, Timothy Chen, Adam Caccavale, Rachel Gardner, Preston Culbertson, Jeannette Bohg, and MacSchwager. Vision-onlyrobotnavigationinaneuralradianceworld.IEEERoboticsandAutomationLetters(RA-L), 2022
2022
-
[3]
Cascading failures in agentic ai.https://adversa.ai/blog/cascading-failures-in-age ntic-ai-complete-owasp-asi08-security-guide-2026/, 2025
Adversa AI. Cascading failures in agentic ai.https://adversa.ai/blog/cascading-failures-in-age ntic-ai-complete-owasp-asi08-security-guide-2026/, 2025
2026
-
[4]
Distributionally adaptive meta reinforcement learning
Anurag Ajay, Abhishek Gupta, Dibya Ghosh, Sergey Levine, and Pulkit Agrawal. Distributionally adaptive meta reinforcement learning. InNeurIPS, 2022
2022
-
[5]
Ataxonomyoffactorsinfluencingperceived safety in human–robot interaction.Robotics, 2023
NezihaAkalin,AndreyKiselev,AnnicaKristoffersson,andAmyLoutfi. Ataxonomyoffactorsinfluencingperceived safety in human–robot interaction.Robotics, 2023
2023
-
[6]
Ahmad Al-Tawaha, Shangding Gu, Peizhi Niu, Ruoxi Jia, and Ming Jin. Remembering more, risking more: Longitudinal safety risks in memory-equipped LLM agents.arXiv preprint arXiv:2605.17830, 2026
Pith/arXiv arXiv 2026
-
[7]
The adolescence of technology.https://www.darioamodei.com/essay/the-adolescen ce-of-technology, 2025
Dario Amodei. The adolescence of technology.https://www.darioamodei.com/essay/the-adolescen ce-of-technology, 2025
2025
-
[8]
FlowHijack: Adynamics-aware backdoor attack on flow-matching vision-language-action models
XinyuanAn,TaoLuo,GengyunPeng,YaobingWang,KuiRen,andDongxiaWang. FlowHijack: Adynamics-aware backdoor attack on flow-matching vision-language-action models. InCVPR, 2026
2026
-
[9]
Chips-messagerobustauthentication(chimera)forgpscivilian signals
Jon M Anderson, Katherine L Carroll, Nathan P DeVilbiss, James T Gillis, Joanna C Hinks, Brady W O’Hanlon, JosephJRushanan,LoganScott,andReneeAYazdi. Chips-messagerobustauthentication(chimera)forgpscivilian signals. InGNSS+, 2017
2017
-
[10]
Vision-and-language navigation: Interpreting visually-grounded navigation instructions in real environments
Peter Anderson, Qi Wu, Damien Teney, Jake Bruce, Mark Johnson, Niko Sünderhauf, Ian Reid, Stephen Gould, and Anton van den Hengel. Vision-and-language navigation: Interpreting visually-grounded navigation instructions in real environments. InCVPR, 2018
2018
-
[11]
Huan ang Gao, Jiayi Geng, Wenyue Hua, Mengkang Hu, Xinzhe Juan, Hongzhang Liu, Shilong Liu, Jiahao Qiu, Xuan Qi, Yiran Wu, Hongru Wang, Han Xiao, Yuhang Zhou, Shaokun Zhang, Jiayi Zhang, Jinyu Xiang, Yixiong Fang, Qiwen Zhao, Dongrui Liu, Qihan Ren, Cheng Qian, Zhenhailong Wang, Minda Hu, Huazheng Wang, Qingyun Wu, Heng Ji, and Mengdi Wang. A survey of se...
Pith/arXiv arXiv 2025
-
[12]
Ashcraft, Ted Staley, Josh Carney, Cameron Hickert, Derek Juba, Kiran Karra, and Nathan Drenkow
C. Ashcraft, Ted Staley, Josh Carney, Cameron Hickert, Derek Juba, Kiran Karra, and Nathan Drenkow. Backdoors in drl: Four environments focusing on in-distribution triggers.arXiv preprint arXiv:2505.17248, 2025
arXiv 2025
-
[13]
Mash-vlm: Mitigating action-scene hallucination in video-llms through disentangled spatial-temporal representations
Kyungho Bae, Jinhyung Kim, Sihaeng Lee, Soonyoung Lee, Gunhee Lee, and Jinwoo Choi. Mash-vlm: Mitigating action-scene hallucination in video-llms through disentangled spatial-temporal representations. InCVPR, 2025
2025
-
[14]
Multi-robot coordination with adversarial perception
Rayan Bahrami and Hamidreza Jafarnejadsani. Multi-robot coordination with adversarial perception. InICUAS, 2025
2025
-
[15]
Rat: Adversarial attacks on deep reinforcement agents for targeted behaviors
Fengshuo Bai, Runze Liu, Yali Du, Ying Wen, and Yaodong Yang. Rat: Adversarial attacks on deep reinforcement agents for targeted behaviors. InAAAI, 2025
2025
-
[16]
Universal closed-box adversarial attack for trajectory representation via controlling high-dimensional iterative constraints.IEEE Internet of Things Journal (IoT-J), 2025
Guangyao Bai, Jie Li, Yucheng Shi, Lei Shi, Yufei Gao, Chenguang Fan, and Guanxi Chen. Universal closed-box adversarial attack for trajectory representation via controlling high-dimensional iterative constraints.IEEE Internet of Things Journal (IoT-J), 2025
2025
-
[17]
CleanCLIP: Mitigating data poisoning attacks in multimodal contrastive learning
Hritik Bansal, Nishad Singhi, Yu Yang, Fan Yin, Aditya Grover, and Kai-Wei Chang. CleanCLIP: Mitigating data poisoning attacks in multimodal contrastive learning. InICCV, 2023
2023
-
[18]
Lorenzo Baraldi, Zifan Zeng, Chongzhe Zhang, Aradhana Nayak, Hongbo Zhu, Feng Liu, Qunli Zhang, Peng Wang, Shiming Liu, Zheng Hu, et al. The safety challenge of world models for embodied ai agents: A review.arXiv preprint arXiv:2510.05865, 2025. 49
arXiv 2025
-
[19]
On minimizing adversarial counterfactual error
Roman Belaire, Arunesh Sinha, and Pradeep Varakantham. On minimizing adversarial counterfactual error. In ICLR, 2024
2024
-
[20]
Regret-based defense in adversarial reinforcement learning
Roman Belaire, Pradeep Varakantham, Thanh Nguyen, and David Lo. Regret-based defense in adversarial reinforcement learning. InAAMAS, 2024
2024
-
[21]
Yannis Belkhiter, Giulio Zizzo, Sergio Maffeis, Seshu Tirupathi, and John D. Kelleher. Breaking MCP with function hijacking attacks: Novel threats for function calling and agentic models.arXiv preprint arXiv:2604.20994, 2026
Pith/arXiv arXiv 2026
-
[22]
Yoshua Bengio et al. International ai safety report 2025: Second key update — technical safeguards and risk management.arXiv preprint arXiv:2511.19863, 2025
arXiv 2025
-
[23]
Domna Bilika, Nikoletta Michopoulou, Efthimios Alepis, and Constantinos Patsakis. Hello me, meet the real me: Audio deepfake attacks on voice assistants.arXiv preprint arXiv:2302.10328, 2023
Pith/arXiv arXiv 2023
-
[24]
Kevin Black, Noah Brown, Danny Driess, Adnan Esmail, Michael Equi, Chelsea Finn, Niccolo Fusai, Lachy Groom, Karol Hausman, Brian Ichter, et al.π0: A vision-language-action flow model for general robot control.arXiv preprint arXiv:2410.24164, 2024
Pith/arXiv arXiv 2024
-
[25]
Securing the lane: Defences against patch attacks on autonomous vehicle’s lane detection
Romana Blazevic, Alexander Toch, Omar Veledar, and Georg Macher. Securing the lane: Defences against patch attacks on autonomous vehicle’s lane detection. InEuroS&PW, 2025
2025
-
[26]
The emergence of adversarial communication in multi-agent reinforcement learning
Jan Blumenkamp and Amanda Prorok. The emergence of adversarial communication in multi-agent reinforcement learning. InCoRL, 2021
2021
-
[27]
Stochastic model predictive control with a safety guarantee for automated driving.IEEE Transactions on Intelligent Vehicles, 2021
Tim Brüdigam, Michael Olbrich, Dirk Wollherr, and Marion Leibold. Stochastic model predictive control with a safety guarantee for automated driving.IEEE Transactions on Intelligent Vehicles, 2021
2021
-
[28]
Schoellig
Lukas Brunke, Yanni Zhang, Ralf Romer, Jack Naimer, Nikola Staykov, Siqi Zhou, and Angela P. Schoellig. Semantically safe robot manipulation: From semantic scene understanding to motion safeguards.IEEE Robotics and Automation Letters (RA-L), 2025
2025
-
[29]
Luis Burbano, D. O. Barbosa, Qi Sun, Siwei Yang, Haoqin Tu, Cihang Xie, Yinzhi Cao, and Alvaro A. Cárdenas. Chai: Command hijacking against embodied ai.arXiv preprint arXiv:2510.00181, 2025
arXiv 2025
-
[30]
Diffusion models-based purification for common corruptions on robust 3d object detection.Sensors, 2024
Mumuxin Cai, Xupeng Wang, Ferdous Sohel, and Hang Lei. Diffusion models-based purification for common corruptions on robust 3d object detection.Sensors, 2024
2024
-
[31]
Summit: A simulator for urban driving in massive mixed traffic
Panpan Cai, Yiyuan Lee, Yuanfu Luo, and David Hsu. Summit: A simulator for urban driving in massive mixed traffic. InICRA, 2020
2020
-
[32]
Yulong Cao, Chaowei Xiao, Dawei Yang, Jing Fang, Ruigang Yang, Mingyan Liu, and Bo Li. Adversarial objects against lidar-based autonomous driving systems.arXiv preprint arXiv:1907.05418, 2019
Pith/arXiv arXiv 1907
-
[33]
Invisible for both camera and lidar: Security of multi-sensor fusion based perception in autonomous driving under physical-world attacks
Yulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang, Jin Fang, Ruigang Yang, Qi Alfred Chen, Mingyan Liu, and Bo Li. Invisible for both camera and lidar: Security of multi-sensor fusion based perception in autonomous driving under physical-world attacks. InS&P, 2021
2021
-
[34]
Advdo: Realistic adversarial attacks for trajectory prediction
Yulong Cao, Chaowei Xiao, Anima Anandkumar, Danfei Xu, and Marco Pavone. Advdo: Realistic adversarial attacks for trajectory prediction. InECCV, 2022
2022
-
[35]
Hidden voice commands
Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner, and Wenchao Zhou. Hidden voice commands. InUSENIX Security, 2016
2016
-
[36]
Jeyapratap, Kaidi Xu, and Lifeng Zhou
Amirhosein Chahe, Chenan Wang, Abhishek S. Jeyapratap, Kaidi Xu, and Lifeng Zhou. Dynamic adversarial attacks on autonomous driving systems. InRSS, 2023
2023
-
[37]
Trishna Chakraborty, Udita Ghosh, Xiaopan Zhang, Fahim Faisal Niloy, Yue Dong, Jiachen Li, Amit K Roy- Chowdhury, and Chengyu Song. Heal: An empirical study on hallucinations in embodied agents driven by large language models.arXiv preprint arXiv:2506.15065, 2025
arXiv 2025
-
[38]
Jiamin Chang, Minhui Xue, Ruoxi Sun, Shuchao Pang, Salil S. Kanhere, and Hammond Pearce. Mitigating trust boundary confusion from visual injections on vision-language agentic systems.arXiv preprint arXiv:2604.19844, 2026. 50
Pith/arXiv arXiv 2026
-
[39]
Adversarial attacks on monocular pose estimation
Hemang Chawla, Arnav Varma, Elahe Arani, and Bahram Zonooz. Adversarial attacks on monocular pose estimation. InIROS, 2022
2022
-
[40]
Adversary is on the road: Attacks on visual{SLAM} using unnoticeable adversarial patch
Baodong Chen, Wei Wang, Pascal Sikorski, and Ting Zhu. Adversary is on the road: Attacks on visual{SLAM} using unnoticeable adversarial patch. InUSENIX Security, 2024
2024
-
[41]
Alemzadeh, and Xugui Zhou
Cheng Chen, Grant Xiao, Daehyun Lee, Lishan Yang, Evgenia Smirni, H. Alemzadeh, and Xugui Zhou. Safety interventions against adversarial patches in an open-source driver assistance system. InDSN, 2025
2025
-
[42]
Jiawei Chen, Simin Huang, Jiawei Du, Shuaihang Chen, Yu Tian, Mingjie Wei, Chao Yu, and Zhaoxia Yin. Tex3D: Objects as attack surfaces via adversarial 3D textures for vision-language-action models.arXiv preprint arXiv:2604.01618, 2026
arXiv 2026
-
[43]
Lidattack: Robust black-box attack on lidar-based object detection
Jinyin Chen, Danxin Liao, Yunjie Yan, Sheng Xiang, and Haibin Zheng. Lidattack: Robust black-box attack on lidar-based object detection. InITSC, 2025
2025
-
[44]
Towardsphysically-realizable adversarial attacks in embodied vision navigation
MengChen,JiaweiTu,ChaoQi,YonghaoDang,FengZhou,WeiWei,andJianqinYin. Towardsphysically-realizable adversarial attacks in embodied vision navigation. InIROS, 2024
2024
-
[45]
Ruolin Chen, Yinqian Sun, Jihang Wang, Mingyang Lv, Qian Zhang, and Yi Zeng. Safemind: Benchmarking and mitigating safety risks in embodied llm agents.arXiv preprint arXiv:2509.25885, 2025
arXiv 2025
-
[46]
Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector
Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng Chau. Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. InECML PKDD, 2018
2018
-
[47]
Metamorph: Injecting inaudible commands into over-the-air voice controlled systems
Tao Chen, Longfei Shangguan, Zhenjiang Li, and Kyle Jamieson. Metamorph: Injecting inaudible commands into over-the-air voice controlled systems. InNDSS, 2020
2020
-
[48]
Catnips: Collision avoidance through neural implicit probabilistic scenes.IEEE Transactions on Robotics (T-RO), 2024
Timothy Chen, Preston Culbertson, and Mac Schwager. Catnips: Collision avoidance through neural implicit probabilistic scenes.IEEE Transactions on Robotics (T-RO), 2024
2024
-
[49]
Timothy Chen, Aiden Swann, Javier Yu, Ola Shorinwa, Riku Murai, Monroe Kennedy III, and Mac Schwager. Safer-splat: A control barrier function for safe navigation with online gaussian splatting maps.arXiv preprint arXiv:2409.09868, 2024
Pith/arXiv arXiv 2024
-
[50]
Splat-nav: Safe real-time robot navigation in gaussian splatting maps.IEEE Transactions on Robotics (T-RO), 2025
Timothy Chen, Ola Shorinwa, Joseph Bruno, Aiden Swann, Javier Yu, Weijia Zeng, Keiko Nagami, Philip Dames, and Mac Schwager. Splat-nav: Safe real-time robot navigation in gaussian splatting maps.IEEE Transactions on Robotics (T-RO), 2025
2025
-
[51]
Metawave: Attackingmmwavesensingwithmeta-material-enhancedtags
Xingyu Chen, Zhengxiong Li, Biacheng Chen, Yi Zhu, Chris Xiaoxuan Lu, Zhengyu Peng, Feng Lin, Wenyao Xu, KuiRen, andChunmingQiao. Metawave: Attackingmmwavesensingwithmeta-material-enhancedtags. InNDSS, 2023
2023
-
[52]
Fouhey, and Joyce Chai
Xuweiyi Chen, Ziqiao Ma, Xuejun Zhang, Sihan Xu, Shengyi Qian, Jianing Yang, David F. Fouhey, and Joyce Chai. Multi-object hallucination in vision-language models. InNeurIPS, 2024
2024
-
[53]
Marnet: Backdoor attacks against cooperative multi-agent reinforcement learning.IEEE Transactions on Dependable and Secure Computing (TDSC), 2023
Yanjiao Chen, Zhicong Zheng, and Xueluan Gong. Marnet: Backdoor attacks against cooperative multi-agent reinforcement learning.IEEE Transactions on Dependable and Secure Computing (TDSC), 2023
2023
-
[54]
Diffusion policy attacker: Crafting adversarial attacks for diffusion- based policies
Yipu Chen, Haotian Xue, and Yongxin Chen. Diffusion policy attacker: Crafting adversarial attacks for diffusion- based policies. InNeurIPS, 2024
2024
-
[55]
Revisiting adversarial perception attacks and defense methods on autonomous driving systems
Yuxin Chen et al. Revisiting adversarial perception attacks and defense methods on autonomous driving systems. arXiv preprint arXiv:2505.11532, 2025
Pith/arXiv arXiv 2025
-
[56]
Devil’s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices
Yuxuan Chen, Xuejing Yuan, Jiangshan Zhang, Yue Zhao, Shengzhi Zhang, Kai Chen, and XiaoFeng Wang. Devil’s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices. InUSENIX Security, 2020
2020
-
[57]
Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases
Zhaorun Chen, Zhen Xiang, Chaowei Xiao, Dawn Song, and Bo Li. Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases. InNeurIPS, 2024
2024
-
[58]
Zhaorun Chen, Xun Liu, Haibo Tong, Chengquan Guo, Yuzhou Nie, Jiawei Zhang, Mintong Kang, Chejian Xu, Qichang Liu, Xiaogeng Liu, Tianneng Shi, Chaowei Xiao, Sanmi Koyejo, Percy Liang, Wenbo Guo, Dawn Song, and 51 Bo Li. DecodingTrust-Agent platform (DTap): A controllable and interactive red-teaming platform for AI agents. arXiv preprint arXiv:2605.04808, 2026
Pith/arXiv arXiv 2026
-
[59]
Zixing Chen, Yifeng Gao, Li Wang, Yunhan Zhao, Yi Liu, Jiayu Li, Xiang Zheng, Zuxuan Wu, et al. HazardArena: Evaluating semantic safety in vision-language-action models.arXiv preprint arXiv:2604.12447, 2026
Pith/arXiv arXiv 2026
-
[60]
Hao Cheng, Erjia Xiao, Chengyuan Yu, Zhao Yao, Jiahang Cao, Qiang Zhang, Jiaxu Wang, Mengshu Sun, Kaidi Xu, Jindong Gu, and Renjing Xu. Manipulation facing threats: Evaluating physical vulnerabilities in end-to-end vision language action models.arXiv preprint arXiv:2409.13174, 2024
arXiv 2024
-
[61]
Universal adversarial attack against 3d object tracking
Riran Cheng, Nan Sang, Yinyuan Zhou, and Xupeng Wang. Universal adversarial attack against 3d object tracking. InHPCC, 2021
2021
-
[62]
Black-box explainability-guided adversarial attack for 3d object tracking.IEEE Transactions on Circuits and Systems for Video Technology (TCSVT), 2025
Riran Cheng, Xupeng Wang, Ferdous Sohel, and Hang Lei. Black-box explainability-guided adversarial attack for 3d object tracking.IEEE Transactions on Circuits and Systems for Video Technology (TCSVT), 2025
2025
-
[63]
Physical attack on monocular depth estimation with optimal adversarial patches
Zhiyuan Cheng, James Liang, Hongjun Choi, Guanhong Tao, Zhiwen Cao, Dongfang Liu, and Xiangyu Zhang. Physical attack on monocular depth estimation with optimal adversarial patches. InECCV, 2022
2022
-
[64]
Minkyoung Cho, Yulong Cao, Zixiang Zhou, and Z Morley Mao. Adopt: Lidar spoofing attack detection based on point-level temporal consistency.arXiv preprint arXiv:2310.14504, 2023
Pith/arXiv arXiv 2023
-
[65]
Sentinet: Detecting localized universal attacks against deep learning systems
Edward Chou, Florian Tramer, and Giancarlo Pellegrino. Sentinet: Detecting localized universal attacks against deep learning systems. InSPW, 2020
2020
-
[66]
Gupta, Mykel J
Shushman Choudhury, Jayesh K. Gupta, Mykel J. Kochenderfer, Dorsa Sadigh, and Jeannette Bohg. Dynamic multi-robot task allocation under uncertainty and temporal constraints.Autonomous Robots, 2022
2022
-
[67]
Handover control for human-robot and robot-robot collaboration.Frontiers in Robotics and AI, 2021
Marco Costanzo, Giuseppe De Maria, and Ciro Natale. Handover control for human-robot and robot-robot collaboration.Frontiers in Robotics and AI, 2021
2021
-
[68]
Pybullet, a python module for physics simulation for games, robotics and machine learning.http://pybullet.org, 2016–2021
Erwin Coumans and Yunfei Bai. Pybullet, a python module for physics simulation for games, robotics and machine learning.http://pybullet.org, 2016–2021
2016
-
[69]
SagarDasgupta,AbdullahAhmed,MizanurRahman,andThejeshNBandi. Unveilingthestealthythreat: Analyzing slow drift gps spoofing attacks for autonomous vehicles in urban environments and enabling the resilience.arXiv preprint arXiv:2401.01394, 2024
Pith/arXiv arXiv 2024
-
[70]
Navsim: Data-drivennon-reactiveautonomousvehiclesimulation and benchmarking
Daniel Dauner, Marcel Hallgarten, Tianyu Li, Xinshuo Weng, Zhiyu Huang, Zetong Yang, Hongyang Li, Igor Gilitschenski,BorisIvanovic,MarcoPavone,etal. Navsim: Data-drivennon-reactiveautonomousvehiclesimulation and benchmarking. InNeurIPS, 2024
2024
-
[71]
Open challenges in multi-agent security: Towards secure systems of interacting ai
Christian Schroeder de Witt. Open challenges in multi-agent security: Towards secure systems of interacting ai. arXiv preprint arXiv:2505.02077, 2025
Pith/arXiv arXiv 2025
-
[72]
Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 2025
Zehang Deng, Yongjian Guo, Changzhou Han, Wanlun Ma, Junwu Xiong, Sheng Wen, and Yang Xiang. Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 2025
2025
-
[73]
Learning to collide: An adaptive safety-critical scenarios generating method
Wenhao Ding, Baiming Chen, Minjun Xu, and Ding Zhao. Learning to collide: An adaptive safety-critical scenarios generating method. InIROS, 2020
2020
-
[74]
Doan, Yingjie Lao, Peng Yang, and Ping Li
Khoa D. Doan, Yingjie Lao, Peng Yang, and Ping Li. Defending backdoor attacks on vision transformer via patch processing. InAAAI, 2023
2023
-
[75]
Viewfool: Evaluating the robustness of visual recognition to adversarial viewpoints
Yinpeng Dong, Shouwei Ruan, Hang Su, Caixin Kang, Xingxing Wei, and Jun Zhu. Viewfool: Evaluating the robustness of visual recognition to adversarial viewpoints. InNeurIPS, 2022
2022
-
[76]
Carla: An open urban driving simulator
Alexey Dosovitskiy, German Ros, Felipe Codevilla, Antonio Lopez, and Vladlen Koltun. Carla: An open urban driving simulator. InCoRL, 2017
2017
-
[77]
Human–robot object handover: Recent progress and future direction.Robotics, 2024
Haonan Duan, Yifan Yang, Daheng Li, and Peng Wang. Human–robot object handover: Recent progress and future direction.Robotics, 2024
2024
-
[78]
TRAP: Tail-aware ranking attack for world-model planning.arXiv preprint arXiv:2605.01950, 2026
Siyuan Duan, Ke Zhang, and Xizhao Luo. TRAP: Tail-aware ranking attack for world-model planning.arXiv preprint arXiv:2605.01950, 2026. 52
Pith/arXiv arXiv 2026
-
[79]
A robust multi-sensor fusion model against adversarial patch attack.Wireless Networks, 2026
Aya El-Fatyany. A robust multi-sensor fusion model against adversarial patch attack.Wireless Networks, 2026
2026
-
[80]
Drones in distress: A game-theoretic countermeasure for protecting uavs against gps spoofing.IEEE Internet of Things Journal (IoT-J), 2019
AbdelRahman Eldosouky, Aidin Ferdowsi, and Walid Saad. Drones in distress: A game-theoretic countermeasure for protecting uavs against gps spoofing.IEEE Internet of Things Journal (IoT-J), 2019
2019
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.