{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:R33KB7PVKLIBXEJKDXX3TSRI5V","short_pith_number":"pith:R33KB7PV","schema_version":"1.0","canonical_sha256":"8ef6a0fdf552d01b912a1defb9ca28ed4f8c2c34fee3f489a324e97bbce6fa99","source":{"kind":"arxiv","id":"2608.00747","version":1},"attestation_state":"computed","paper":{"title":"When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.MA"],"primary_cat":"cs.RO","authors_text":"Amisha Bagari, Hayretdin Bahsi, Neha Nagaraja","submitted_at":"2026-08-01T16:31:00Z","abstract_excerpt":"Large language models are increasingly integrated into autonomous robotic systems for task planning and control, but this integration exposes them to prompt injection attacks that can lead to unsafe decisions and physical harm. Multi-agent settings increase the risks through cross-agent contamination and broader attack surfaces. In this paper, we evaluate prompt injection attacks against an LLM-based multi-agent robotic system, considering both direct injections into task instructions and indirect injections through perception modules. In our experiments across varying attack-goal complexities"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2608.00747","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.RO","submitted_at":"2026-08-01T16:31:00Z","cross_cats_sorted":["cs.AI","cs.CR","cs.MA"],"title_canon_sha256":"05ec38165baa894c93cfccdd3662268827e699429aaf73342b01b184e948e0ae","abstract_canon_sha256":"1cec1fd05025ca89227482b98c2478be49e89ba0af6c651d574d9e676410fe6a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-08-04T01:54:51.970374Z","signature_b64":"Mu99InN8JbQDExZ7MEXoRL1IVRQLcCUnzXYA8pGR1Xs8g5cR008/A1UhfZf+4o8hklFGrDJg8gRQI8B7RmSKBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8ef6a0fdf552d01b912a1defb9ca28ed4f8c2c34fee3f489a324e97bbce6fa99","last_reissued_at":"2026-08-04T01:54:51.968545Z","signature_status":"signed_v1","first_computed_at":"2026-08-04T01:54:51.968545Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.MA"],"primary_cat":"cs.RO","authors_text":"Amisha Bagari, Hayretdin Bahsi, Neha Nagaraja","submitted_at":"2026-08-01T16:31:00Z","abstract_excerpt":"Large language models are increasingly integrated into autonomous robotic systems for task planning and control, but this integration exposes them to prompt injection attacks that can lead to unsafe decisions and physical harm. Multi-agent settings increase the risks through cross-agent contamination and broader attack surfaces. In this paper, we evaluate prompt injection attacks against an LLM-based multi-agent robotic system, considering both direct injections into task instructions and indirect injections through perception modules. In our experiments across varying attack-goal complexities"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2608.00747","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2608.00747/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2608.00747","created_at":"2026-08-04T01:54:51.970008+00:00"},{"alias_kind":"arxiv_version","alias_value":"2608.00747v1","created_at":"2026-08-04T01:54:51.970008+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2608.00747","created_at":"2026-08-04T01:54:51.970008+00:00"},{"alias_kind":"pith_short_12","alias_value":"R33KB7PVKLIB","created_at":"2026-08-04T01:54:51.970008+00:00"},{"alias_kind":"pith_short_16","alias_value":"R33KB7PVKLIBXEJK","created_at":"2026-08-04T01:54:51.970008+00:00"},{"alias_kind":"pith_short_8","alias_value":"R33KB7PV","created_at":"2026-08-04T01:54:51.970008+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V","json":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V.json","graph_json":"https://pith.science/api/pith-number/R33KB7PVKLIBXEJKDXX3TSRI5V/graph.json","events_json":"https://pith.science/api/pith-number/R33KB7PVKLIBXEJKDXX3TSRI5V/events.json","paper":"https://pith.science/paper/R33KB7PV"},"agent_actions":{"view_html":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V","download_json":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V.json","view_paper":"https://pith.science/paper/R33KB7PV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2608.00747&json=true","fetch_graph":"https://pith.science/api/pith-number/R33KB7PVKLIBXEJKDXX3TSRI5V/graph.json","fetch_events":"https://pith.science/api/pith-number/R33KB7PVKLIBXEJKDXX3TSRI5V/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V/action/timestamp_anchor","attest_storage":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V/action/storage_attestation","attest_author":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V/action/author_attestation","sign_citation":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V/action/citation_signature","submit_replication":"https://pith.science/pith/R33KB7PVKLIBXEJKDXX3TSRI5V/action/replication_record"}},"created_at":"2026-08-04T01:54:51.970008+00:00","updated_at":"2026-08-04T01:54:51.970008+00:00"}