Pith. sign in

REVIEW 1 major objections 4 minor 2 cited by

Embodied AI safety is organized by a capability-risk duality: deeper autonomy expands the attack surface, and inner-layer failures cascade outward.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-13 17:03 UTC pith:VICWIOCY

load-bearing objection A large, usable survey that finally maps digital attacks onto closed-loop physical risk under one capability-risk stack; the taxonomy is the real product. the 1 major comments →

arxiv 2605.02900 v2 pith:VICWIOCY submitted 2026-03-28 cs.CR cs.AIcs.CVcs.RO

Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses

classification cs.CR cs.AIcs.CVcs.RO
keywords Embodied AI SafetyTrustworthy Embodied AIMultimodal SafetyAttacks and DefensesCapability-Risk DualityVision-Language-ActionHuman-Robot Interaction
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

This survey argues that safety for robots and other embodied agents cannot be treated as a digital-only problem. Because these systems sense, reason, plan, and act in the physical world, a failure at any stage can produce real harm. The authors organize more than five hundred papers into a multi-level taxonomy that follows the full pipeline from perception through cognition, planning, action and interaction, and full agentic systems. Their central device is the capability-risk duality: each new capability layer enlarges the attack surface and lets vulnerabilities at inner layers cascade to outer ones. The resulting map reveals overlooked weak points such as fragile multimodal fusion, jailbreak-unstable planning, and untrustworthy open-ended human-agent interaction, and supplies a concrete roadmap for building agents that remain safe once they leave the lab.

Core claim

A multi-level taxonomy built on the capability-risk duality unifies fragmented embodied-safety research across perception, cognition, planning, action and interaction, and agentic systems, connects it to broader vision-language work, and surfaces critical gaps that existing digital-only surveys miss.

What carries the argument

Capability-risk duality (deeper capability entails broader risk) together with the five-layer pipeline taxonomy: perception, cognition, planning, action & interaction, and agentic systems. This structure assigns attacks and defenses, traces cascade paths, and exposes gaps.

Load-bearing premise

That the nested capability layers and their cascade of inner-to-outer failures form a complete, non-overlapping way to organize the whole literature so that papers can be cleanly assigned and gaps reliably named.

What would settle it

A substantial body of high-impact embodied-safety results that cannot be placed in any of the five layers without forced double-counting or that demonstrate cascade patterns opposite to the claimed inner-to-outer flow.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • Safety evaluation protocols must test cascade paths from sensor spoofing through planning to physical action rather than isolated modules.
  • Defenses for multimodal fusion and jailbreak-resistant planning become first-order research priorities for any deployable robot.
  • Human-agent interaction and agentic tool/memory layers require dedicated risk-aware design, not just bolted-on filters.
  • Standards and benchmarks for embodied systems will need to adopt the layered taxonomy to compare claims across platforms.
  • Roadmaps for foundation-model robots can treat safety as an intrinsic property of the full sense-think-act loop instead of an afterthought.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If the cascade model holds, certification of commercial robots should require red-team tests that begin at the sensor and end at the actuator, not separate module audits.
  • The same duality may apply to non-robotic cyber-physical systems (smart factories, medical devices), suggesting a portable evaluation template.
  • Overlooked gaps in open-ended human trust and multi-agent collusion imply that social-safety benchmarks will become as necessary as collision-avoidance tests.
  • A natural next experiment is a controlled sim-to-real study that injects a single inner-layer attack and measures how far the failure propagates under different fusion and planning defenses.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

1 major / 4 minor

Summary. This survey reviews safety research in embodied AI across the full pipeline of perception, cognition, planning, action & interaction, and agentic systems. It organizes the literature via a multi-level taxonomy grounded in a capability–risk duality (deeper capability entails broader risk; Figure 1), synthesizes over 500 papers on adversarial, backdoor, jailbreak, and hardware attacks plus defenses, and contrasts the contribution with nine prior surveys. The manuscript identifies overlooked challenges (multimodal fusion fragility, planning instability under jailbreaks, open-ended HRI trustworthiness) and closes with open challenges and future trends as a deployment roadmap.

Significance. If the synthesis holds, the paper supplies a usable organizing frame for a rapidly expanding, previously fragmented literature that spans robotics, foundation-model safety, and physical-world risk. Strengths include explicit comparison to nine prior surveys, dense citation tables that quantify attack/defense coverage per layer (Figure 4 and Tables 1–18), concrete gap statements (e.g., sparse backdoor defenses for spatial/auditory perception and VLAs), and a public GitHub resource. The capability–risk duality and cascade emphasis (Table 1, §6.4) give practitioners a clearer map of where inner-layer failures amplify. For a survey venue this is a substantial consolidating contribution rather than a theorem or new empirical result.

major comments (1)
  1. The central claim is organizational synthesis under the capability–risk duality (Figure 1, §§1–6), not a theorem that the five layers are exhaustive or non-overlapping. The manuscript already notes cascade/cross-layer effects (Table 1, §6.4) and places multi-agent material in both planning (§4.3) and action (§5.3) with scope notes. Residual overlaps therefore do not falsify the synthesis; no load-bearing inconsistency that would require major revision of the taxonomy was found.
minor comments (4)
  1. §1 and the abstract state “over 500 papers” without an explicit inclusion/exclusion protocol or search window; a short methods paragraph would improve reproducibility of the corpus.
  2. Figure 3 strip widths are said to be proportional to paper counts, but absolute counts per strip are not tabulated; adding them would make the distribution claim checkable.
  3. Occasional typographic issues remain (e.g., “hijacking,” “Hijack,” mixed en-dashes); a final copy-edit pass would help.
  4. Some very recent 2026 entries appear only as arXiv preprints; flagging preprint status in the tables would set reader expectations.

Circularity Check

0 steps flagged

No significant circularity; the multi-level taxonomy is an organizational framing imposed on independently published attack/defense papers, not a derivation that reduces to its own inputs by construction.

full rationale

This is a survey that synthesizes >500 external papers into a capability-risk duality taxonomy (Figure 1, Sections 1-6) spanning perception through agentic systems. The taxonomy does not redefine success metrics, force empirical results, or derive predictions from fitted parameters; it merely assigns existing independent works (adversarial, backdoor, jailbreak, sensor, etc.) to layers and notes cascades (Table 1, Section 6.4). Self-citations of the authors' own attack/defense papers appear as ordinary literature entries, not as load-bearing uniqueness theorems or sole support for the organizing principle. No equations, fitted inputs called predictions, self-definitional loops, or ansatz smuggling via citation chains exist. The paper is self-contained as literature organization and gap identification; residual overlaps (e.g., multi-agent material in both planning and action) are explicitly scoped rather than hidden. Score 0 is therefore the correct, proportionate finding.

Axiom & Free-Parameter Ledger

0 free parameters · 3 axioms · 1 invented entities

As a survey the paper introduces almost no free parameters or physical constants. Its load-bearing commitments are domain assumptions about how embodied pipelines work and one invented organizing entity (the layered taxonomy). No numerical fits appear.

axioms (3)
  • domain assumption Perception errors propagate and amplify through cognition, planning, and action, so inner-layer vulnerabilities cascade to outer-layer physical harm.
    Stated in the Capability-Risk Duality section and used to justify the nested taxonomy; treated as given rather than derived.
  • domain assumption Embodied agents operate under uncertain sensing, incomplete knowledge, and dynamic human-robot interaction where failures can cause physical harm, distinguishing them from digital-only AI.
    Opening premise of the abstract and introduction; grounds the entire safety motivation.
  • ad hoc to paper The five capability layers (perception, cognition, planning, action & interaction, agentic system) are jointly exhaustive and sufficiently non-overlapping for taxonomy construction.
    Introduced by the authors as the organizing scaffold; alternative partitions (e.g., by threat model or by embodiment type) are possible but not explored.
invented entities (1)
  • Capability-risk duality / multi-level taxonomy of embodied AI safety no independent evidence
    purpose: Unifies previously fragmented attack and defense literature and surfaces overlooked challenges.
    The taxonomy is the paper's primary novel construct; it is not independently measured outside the survey itself.

pith-pipeline@v1.1.0-grok45 · 53602 in / 2302 out tokens · 133235 ms · 2026-07-13T17:03:52.460070+00:00 · methodology

0 comments
read the original abstract

Embodied Artificial Intelligence (Embodied AI) integrates perception, cognition, planning, and interaction into agents that operate in open-world, safety-critical environments. As these systems gain autonomy and enter domains such as transportation, healthcare, and industrial or assistive robotics, ensuring their safety becomes both technically challenging and socially indispensable. Unlike digital AI systems, embodied agents must act under uncertain sensing, incomplete knowledge, and dynamic human-robot interactions, where failures can directly lead to physical harm. This survey provides a comprehensive and structured review of safety research in embodied AI, examining attacks and defenses across the full embodied pipeline, from perception and cognition to planning, action and interaction, and agentic system. We introduce a multi-level taxonomy that unifies fragmented lines of work and connects embodied-specific safety findings with broader advances in vision, language, and multimodal foundation models. Our review synthesizes insights from over 500 papers spanning adversarial, backdoor, jailbreak, and hardware-level attacks; attack detection, safe training and robust inference; and risk-aware human-agent interaction. This analysis reveals several overlooked challenges, including the fragility of multimodal perception fusion, the instability of planning under jailbreak attacks, and the trustworthiness of human-agent interaction in open-ended scenarios. By organizing the field into a coherent framework and identifying critical research gaps, this survey provides a roadmap for building embodied agents that are not only capable and autonomous but also safe, robust, and reliable in real-world deployment.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Towards Trustworthy Embodied Intelligence: A Systems Framework and Graded Trustworthiness Levels

    cs.RO 2026-07 conditional novelty 5.0

    A four-layer systems framework and T0–T5 hierarchy for grading and maintaining bounded trustworthiness claims in embodied AI systems.

  2. Physical AI Governance: From Theory to Practice Across Life Cycle

    cs.AI 2026-07 conditional novelty 4.0

    A survey that organizes Physical AI governance into five principles and a five-stage lifecycle, with stage-specific operational practices.

Reference graph

Works this paper leans on

299 extracted references · 72 linked inside Pith · cited by 2 Pith papers

  1. [1]

    Practical hidden voice attacks against speech and speaker recognition systems.arXiv preprint arXiv:1904.05734, 2019

    Hadi Abdullah, Washington Garcia, Christian Peeters, Patrick Traynor, Kevin RB Butler, and Joseph Wilson. Practical hidden voice attacks against speech and speaker recognition systems.arXiv preprint arXiv:1904.05734, 2019

  2. [2]

    Vision-onlyrobotnavigationinaneuralradianceworld.IEEERoboticsandAutomationLetters(RA-L), 2022

    Michal Adamkiewicz, Timothy Chen, Adam Caccavale, Rachel Gardner, Preston Culbertson, Jeannette Bohg, and MacSchwager. Vision-onlyrobotnavigationinaneuralradianceworld.IEEERoboticsandAutomationLetters(RA-L), 2022

  3. [3]

    Cascading failures in agentic ai.https://adversa.ai/blog/cascading-failures-in-age ntic-ai-complete-owasp-asi08-security-guide-2026/, 2025

    Adversa AI. Cascading failures in agentic ai.https://adversa.ai/blog/cascading-failures-in-age ntic-ai-complete-owasp-asi08-security-guide-2026/, 2025

  4. [4]

    Distributionally adaptive meta reinforcement learning

    Anurag Ajay, Abhishek Gupta, Dibya Ghosh, Sergey Levine, and Pulkit Agrawal. Distributionally adaptive meta reinforcement learning. InNeurIPS, 2022

  5. [5]

    Ataxonomyoffactorsinfluencingperceived safety in human–robot interaction.Robotics, 2023

    NezihaAkalin,AndreyKiselev,AnnicaKristoffersson,andAmyLoutfi. Ataxonomyoffactorsinfluencingperceived safety in human–robot interaction.Robotics, 2023

  6. [6]

    Remembering more, risking more: Longitudinal safety risks in memory-equipped LLM agents.arXiv preprint arXiv:2605.17830, 2026

    Ahmad Al-Tawaha, Shangding Gu, Peizhi Niu, Ruoxi Jia, and Ming Jin. Remembering more, risking more: Longitudinal safety risks in memory-equipped LLM agents.arXiv preprint arXiv:2605.17830, 2026

  7. [7]

    The adolescence of technology.https://www.darioamodei.com/essay/the-adolescen ce-of-technology, 2025

    Dario Amodei. The adolescence of technology.https://www.darioamodei.com/essay/the-adolescen ce-of-technology, 2025

  8. [8]

    FlowHijack: Adynamics-aware backdoor attack on flow-matching vision-language-action models

    XinyuanAn,TaoLuo,GengyunPeng,YaobingWang,KuiRen,andDongxiaWang. FlowHijack: Adynamics-aware backdoor attack on flow-matching vision-language-action models. InCVPR, 2026

  9. [9]

    Chips-messagerobustauthentication(chimera)forgpscivilian signals

    Jon M Anderson, Katherine L Carroll, Nathan P DeVilbiss, James T Gillis, Joanna C Hinks, Brady W O’Hanlon, JosephJRushanan,LoganScott,andReneeAYazdi. Chips-messagerobustauthentication(chimera)forgpscivilian signals. InGNSS+, 2017

  10. [10]

    Vision-and-language navigation: Interpreting visually-grounded navigation instructions in real environments

    Peter Anderson, Qi Wu, Damien Teney, Jake Bruce, Mark Johnson, Niko Sünderhauf, Ian Reid, Stephen Gould, and Anton van den Hengel. Vision-and-language navigation: Interpreting visually-grounded navigation instructions in real environments. InCVPR, 2018

  11. [11]

    A survey of self-evolving agents: What, when, how, and where to evolve on the path to artificial super intelligence.arXiv preprint arXiv:2507.21046, 2025

    Huan ang Gao, Jiayi Geng, Wenyue Hua, Mengkang Hu, Xinzhe Juan, Hongzhang Liu, Shilong Liu, Jiahao Qiu, Xuan Qi, Yiran Wu, Hongru Wang, Han Xiao, Yuhang Zhou, Shaokun Zhang, Jiayi Zhang, Jinyu Xiang, Yixiong Fang, Qiwen Zhao, Dongrui Liu, Qihan Ren, Cheng Qian, Zhenhailong Wang, Minda Hu, Huazheng Wang, Qingyun Wu, Heng Ji, and Mengdi Wang. A survey of se...

  12. [12]

    Ashcraft, Ted Staley, Josh Carney, Cameron Hickert, Derek Juba, Kiran Karra, and Nathan Drenkow

    C. Ashcraft, Ted Staley, Josh Carney, Cameron Hickert, Derek Juba, Kiran Karra, and Nathan Drenkow. Backdoors in drl: Four environments focusing on in-distribution triggers.arXiv preprint arXiv:2505.17248, 2025

  13. [13]

    Mash-vlm: Mitigating action-scene hallucination in video-llms through disentangled spatial-temporal representations

    Kyungho Bae, Jinhyung Kim, Sihaeng Lee, Soonyoung Lee, Gunhee Lee, and Jinwoo Choi. Mash-vlm: Mitigating action-scene hallucination in video-llms through disentangled spatial-temporal representations. InCVPR, 2025

  14. [14]

    Multi-robot coordination with adversarial perception

    Rayan Bahrami and Hamidreza Jafarnejadsani. Multi-robot coordination with adversarial perception. InICUAS, 2025

  15. [15]

    Rat: Adversarial attacks on deep reinforcement agents for targeted behaviors

    Fengshuo Bai, Runze Liu, Yali Du, Ying Wen, and Yaodong Yang. Rat: Adversarial attacks on deep reinforcement agents for targeted behaviors. InAAAI, 2025

  16. [16]

    Universal closed-box adversarial attack for trajectory representation via controlling high-dimensional iterative constraints.IEEE Internet of Things Journal (IoT-J), 2025

    Guangyao Bai, Jie Li, Yucheng Shi, Lei Shi, Yufei Gao, Chenguang Fan, and Guanxi Chen. Universal closed-box adversarial attack for trajectory representation via controlling high-dimensional iterative constraints.IEEE Internet of Things Journal (IoT-J), 2025

  17. [17]

    CleanCLIP: Mitigating data poisoning attacks in multimodal contrastive learning

    Hritik Bansal, Nishad Singhi, Yu Yang, Fan Yin, Aditya Grover, and Kai-Wei Chang. CleanCLIP: Mitigating data poisoning attacks in multimodal contrastive learning. InICCV, 2023

  18. [18]

    The safety challenge of world models for embodied ai agents: A review.arXiv preprint arXiv:2510.05865, 2025

    Lorenzo Baraldi, Zifan Zeng, Chongzhe Zhang, Aradhana Nayak, Hongbo Zhu, Feng Liu, Qunli Zhang, Peng Wang, Shiming Liu, Zheng Hu, et al. The safety challenge of world models for embodied ai agents: A review.arXiv preprint arXiv:2510.05865, 2025. 49

  19. [19]

    On minimizing adversarial counterfactual error

    Roman Belaire, Arunesh Sinha, and Pradeep Varakantham. On minimizing adversarial counterfactual error. In ICLR, 2024

  20. [20]

    Regret-based defense in adversarial reinforcement learning

    Roman Belaire, Pradeep Varakantham, Thanh Nguyen, and David Lo. Regret-based defense in adversarial reinforcement learning. InAAMAS, 2024

  21. [21]

    Kelleher

    Yannis Belkhiter, Giulio Zizzo, Sergio Maffeis, Seshu Tirupathi, and John D. Kelleher. Breaking MCP with function hijacking attacks: Novel threats for function calling and agentic models.arXiv preprint arXiv:2604.20994, 2026

  22. [22]

    International ai safety report 2025: Second key update — technical safeguards and risk management.arXiv preprint arXiv:2511.19863, 2025

    Yoshua Bengio et al. International ai safety report 2025: Second key update — technical safeguards and risk management.arXiv preprint arXiv:2511.19863, 2025

  23. [23]

    Hello me, meet the real me: Audio deepfake attacks on voice assistants.arXiv preprint arXiv:2302.10328, 2023

    Domna Bilika, Nikoletta Michopoulou, Efthimios Alepis, and Constantinos Patsakis. Hello me, meet the real me: Audio deepfake attacks on voice assistants.arXiv preprint arXiv:2302.10328, 2023

  24. [24]

    Kevin Black, Noah Brown, Danny Driess, Adnan Esmail, Michael Equi, Chelsea Finn, Niccolo Fusai, Lachy Groom, Karol Hausman, Brian Ichter, et al.π0: A vision-language-action flow model for general robot control.arXiv preprint arXiv:2410.24164, 2024

  25. [25]

    Securing the lane: Defences against patch attacks on autonomous vehicle’s lane detection

    Romana Blazevic, Alexander Toch, Omar Veledar, and Georg Macher. Securing the lane: Defences against patch attacks on autonomous vehicle’s lane detection. InEuroS&PW, 2025

  26. [26]

    The emergence of adversarial communication in multi-agent reinforcement learning

    Jan Blumenkamp and Amanda Prorok. The emergence of adversarial communication in multi-agent reinforcement learning. InCoRL, 2021

  27. [27]

    Stochastic model predictive control with a safety guarantee for automated driving.IEEE Transactions on Intelligent Vehicles, 2021

    Tim Brüdigam, Michael Olbrich, Dirk Wollherr, and Marion Leibold. Stochastic model predictive control with a safety guarantee for automated driving.IEEE Transactions on Intelligent Vehicles, 2021

  28. [28]

    Schoellig

    Lukas Brunke, Yanni Zhang, Ralf Romer, Jack Naimer, Nikola Staykov, Siqi Zhou, and Angela P. Schoellig. Semantically safe robot manipulation: From semantic scene understanding to motion safeguards.IEEE Robotics and Automation Letters (RA-L), 2025

  29. [29]

    Luis Burbano, D. O. Barbosa, Qi Sun, Siwei Yang, Haoqin Tu, Cihang Xie, Yinzhi Cao, and Alvaro A. Cárdenas. Chai: Command hijacking against embodied ai.arXiv preprint arXiv:2510.00181, 2025

  30. [30]

    Diffusion models-based purification for common corruptions on robust 3d object detection.Sensors, 2024

    Mumuxin Cai, Xupeng Wang, Ferdous Sohel, and Hang Lei. Diffusion models-based purification for common corruptions on robust 3d object detection.Sensors, 2024

  31. [31]

    Summit: A simulator for urban driving in massive mixed traffic

    Panpan Cai, Yiyuan Lee, Yuanfu Luo, and David Hsu. Summit: A simulator for urban driving in massive mixed traffic. InICRA, 2020

  32. [32]

    Adversarial objects against lidar-based autonomous driving systems.arXiv preprint arXiv:1907.05418, 2019

    Yulong Cao, Chaowei Xiao, Dawei Yang, Jing Fang, Ruigang Yang, Mingyan Liu, and Bo Li. Adversarial objects against lidar-based autonomous driving systems.arXiv preprint arXiv:1907.05418, 2019

  33. [33]

    Invisible for both camera and lidar: Security of multi-sensor fusion based perception in autonomous driving under physical-world attacks

    Yulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang, Jin Fang, Ruigang Yang, Qi Alfred Chen, Mingyan Liu, and Bo Li. Invisible for both camera and lidar: Security of multi-sensor fusion based perception in autonomous driving under physical-world attacks. InS&P, 2021

  34. [34]

    Advdo: Realistic adversarial attacks for trajectory prediction

    Yulong Cao, Chaowei Xiao, Anima Anandkumar, Danfei Xu, and Marco Pavone. Advdo: Realistic adversarial attacks for trajectory prediction. InECCV, 2022

  35. [35]

    Hidden voice commands

    Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner, and Wenchao Zhou. Hidden voice commands. InUSENIX Security, 2016

  36. [36]

    Jeyapratap, Kaidi Xu, and Lifeng Zhou

    Amirhosein Chahe, Chenan Wang, Abhishek S. Jeyapratap, Kaidi Xu, and Lifeng Zhou. Dynamic adversarial attacks on autonomous driving systems. InRSS, 2023

  37. [37]

    Heal: An empirical study on hallucinations in embodied agents driven by large language models.arXiv preprint arXiv:2506.15065, 2025

    Trishna Chakraborty, Udita Ghosh, Xiaopan Zhang, Fahim Faisal Niloy, Yue Dong, Jiachen Li, Amit K Roy- Chowdhury, and Chengyu Song. Heal: An empirical study on hallucinations in embodied agents driven by large language models.arXiv preprint arXiv:2506.15065, 2025

  38. [38]

    Kanhere, and Hammond Pearce

    Jiamin Chang, Minhui Xue, Ruoxi Sun, Shuchao Pang, Salil S. Kanhere, and Hammond Pearce. Mitigating trust boundary confusion from visual injections on vision-language agentic systems.arXiv preprint arXiv:2604.19844, 2026. 50

  39. [39]

    Adversarial attacks on monocular pose estimation

    Hemang Chawla, Arnav Varma, Elahe Arani, and Bahram Zonooz. Adversarial attacks on monocular pose estimation. InIROS, 2022

  40. [40]

    Adversary is on the road: Attacks on visual{SLAM} using unnoticeable adversarial patch

    Baodong Chen, Wei Wang, Pascal Sikorski, and Ting Zhu. Adversary is on the road: Attacks on visual{SLAM} using unnoticeable adversarial patch. InUSENIX Security, 2024

  41. [41]

    Alemzadeh, and Xugui Zhou

    Cheng Chen, Grant Xiao, Daehyun Lee, Lishan Yang, Evgenia Smirni, H. Alemzadeh, and Xugui Zhou. Safety interventions against adversarial patches in an open-source driver assistance system. InDSN, 2025

  42. [42]

    Tex3D: Objects as attack surfaces via adversarial 3D textures for vision-language-action models.arXiv preprint arXiv:2604.01618, 2026

    Jiawei Chen, Simin Huang, Jiawei Du, Shuaihang Chen, Yu Tian, Mingjie Wei, Chao Yu, and Zhaoxia Yin. Tex3D: Objects as attack surfaces via adversarial 3D textures for vision-language-action models.arXiv preprint arXiv:2604.01618, 2026

  43. [43]

    Lidattack: Robust black-box attack on lidar-based object detection

    Jinyin Chen, Danxin Liao, Yunjie Yan, Sheng Xiang, and Haibin Zheng. Lidattack: Robust black-box attack on lidar-based object detection. InITSC, 2025

  44. [44]

    Towardsphysically-realizable adversarial attacks in embodied vision navigation

    MengChen,JiaweiTu,ChaoQi,YonghaoDang,FengZhou,WeiWei,andJianqinYin. Towardsphysically-realizable adversarial attacks in embodied vision navigation. InIROS, 2024

  45. [45]

    Safemind: Benchmarking and mitigating safety risks in embodied llm agents.arXiv preprint arXiv:2509.25885, 2025

    Ruolin Chen, Yinqian Sun, Jihang Wang, Mingyang Lv, Qian Zhang, and Yi Zeng. Safemind: Benchmarking and mitigating safety risks in embodied llm agents.arXiv preprint arXiv:2509.25885, 2025

  46. [46]

    Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector

    Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng Chau. Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. InECML PKDD, 2018

  47. [47]

    Metamorph: Injecting inaudible commands into over-the-air voice controlled systems

    Tao Chen, Longfei Shangguan, Zhenjiang Li, and Kyle Jamieson. Metamorph: Injecting inaudible commands into over-the-air voice controlled systems. InNDSS, 2020

  48. [48]

    Catnips: Collision avoidance through neural implicit probabilistic scenes.IEEE Transactions on Robotics (T-RO), 2024

    Timothy Chen, Preston Culbertson, and Mac Schwager. Catnips: Collision avoidance through neural implicit probabilistic scenes.IEEE Transactions on Robotics (T-RO), 2024

  49. [49]

    Safer-splat: A control barrier function for safe navigation with online gaussian splatting maps.arXiv preprint arXiv:2409.09868, 2024

    Timothy Chen, Aiden Swann, Javier Yu, Ola Shorinwa, Riku Murai, Monroe Kennedy III, and Mac Schwager. Safer-splat: A control barrier function for safe navigation with online gaussian splatting maps.arXiv preprint arXiv:2409.09868, 2024

  50. [50]

    Splat-nav: Safe real-time robot navigation in gaussian splatting maps.IEEE Transactions on Robotics (T-RO), 2025

    Timothy Chen, Ola Shorinwa, Joseph Bruno, Aiden Swann, Javier Yu, Weijia Zeng, Keiko Nagami, Philip Dames, and Mac Schwager. Splat-nav: Safe real-time robot navigation in gaussian splatting maps.IEEE Transactions on Robotics (T-RO), 2025

  51. [51]

    Metawave: Attackingmmwavesensingwithmeta-material-enhancedtags

    Xingyu Chen, Zhengxiong Li, Biacheng Chen, Yi Zhu, Chris Xiaoxuan Lu, Zhengyu Peng, Feng Lin, Wenyao Xu, KuiRen, andChunmingQiao. Metawave: Attackingmmwavesensingwithmeta-material-enhancedtags. InNDSS, 2023

  52. [52]

    Fouhey, and Joyce Chai

    Xuweiyi Chen, Ziqiao Ma, Xuejun Zhang, Sihan Xu, Shengyi Qian, Jianing Yang, David F. Fouhey, and Joyce Chai. Multi-object hallucination in vision-language models. InNeurIPS, 2024

  53. [53]

    Marnet: Backdoor attacks against cooperative multi-agent reinforcement learning.IEEE Transactions on Dependable and Secure Computing (TDSC), 2023

    Yanjiao Chen, Zhicong Zheng, and Xueluan Gong. Marnet: Backdoor attacks against cooperative multi-agent reinforcement learning.IEEE Transactions on Dependable and Secure Computing (TDSC), 2023

  54. [54]

    Diffusion policy attacker: Crafting adversarial attacks for diffusion- based policies

    Yipu Chen, Haotian Xue, and Yongxin Chen. Diffusion policy attacker: Crafting adversarial attacks for diffusion- based policies. InNeurIPS, 2024

  55. [55]

    Revisiting adversarial perception attacks and defense methods on autonomous driving systems

    Yuxin Chen et al. Revisiting adversarial perception attacks and defense methods on autonomous driving systems. arXiv preprint arXiv:2505.11532, 2025

  56. [56]

    Devil’s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices

    Yuxuan Chen, Xuejing Yuan, Jiangshan Zhang, Yue Zhao, Shengzhi Zhang, Kai Chen, and XiaoFeng Wang. Devil’s whisper: A general approach for physical adversarial attacks against commercial black-box speech recognition devices. InUSENIX Security, 2020

  57. [57]

    Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases

    Zhaorun Chen, Zhen Xiang, Chaowei Xiao, Dawn Song, and Bo Li. Agentpoison: Red-teaming llm agents via poisoning memory or knowledge bases. InNeurIPS, 2024

  58. [58]

    DecodingTrust-Agent platform (DTap): A controllable and interactive red-teaming platform for AI agents

    Zhaorun Chen, Xun Liu, Haibo Tong, Chengquan Guo, Yuzhou Nie, Jiawei Zhang, Mintong Kang, Chejian Xu, Qichang Liu, Xiaogeng Liu, Tianneng Shi, Chaowei Xiao, Sanmi Koyejo, Percy Liang, Wenbo Guo, Dawn Song, and 51 Bo Li. DecodingTrust-Agent platform (DTap): A controllable and interactive red-teaming platform for AI agents. arXiv preprint arXiv:2605.04808, 2026

  59. [59]

    HazardArena: Evaluating semantic safety in vision-language-action models.arXiv preprint arXiv:2604.12447, 2026

    Zixing Chen, Yifeng Gao, Li Wang, Yunhan Zhao, Yi Liu, Jiayu Li, Xiang Zheng, Zuxuan Wu, et al. HazardArena: Evaluating semantic safety in vision-language-action models.arXiv preprint arXiv:2604.12447, 2026

  60. [60]

    Manipulation facing threats: Evaluating physical vulnerabilities in end-to-end vision language action models.arXiv preprint arXiv:2409.13174, 2024

    Hao Cheng, Erjia Xiao, Chengyuan Yu, Zhao Yao, Jiahang Cao, Qiang Zhang, Jiaxu Wang, Mengshu Sun, Kaidi Xu, Jindong Gu, and Renjing Xu. Manipulation facing threats: Evaluating physical vulnerabilities in end-to-end vision language action models.arXiv preprint arXiv:2409.13174, 2024

  61. [61]

    Universal adversarial attack against 3d object tracking

    Riran Cheng, Nan Sang, Yinyuan Zhou, and Xupeng Wang. Universal adversarial attack against 3d object tracking. InHPCC, 2021

  62. [62]

    Black-box explainability-guided adversarial attack for 3d object tracking.IEEE Transactions on Circuits and Systems for Video Technology (TCSVT), 2025

    Riran Cheng, Xupeng Wang, Ferdous Sohel, and Hang Lei. Black-box explainability-guided adversarial attack for 3d object tracking.IEEE Transactions on Circuits and Systems for Video Technology (TCSVT), 2025

  63. [63]

    Physical attack on monocular depth estimation with optimal adversarial patches

    Zhiyuan Cheng, James Liang, Hongjun Choi, Guanhong Tao, Zhiwen Cao, Dongfang Liu, and Xiangyu Zhang. Physical attack on monocular depth estimation with optimal adversarial patches. InECCV, 2022

  64. [64]

    Adopt: Lidar spoofing attack detection based on point-level temporal consistency.arXiv preprint arXiv:2310.14504, 2023

    Minkyoung Cho, Yulong Cao, Zixiang Zhou, and Z Morley Mao. Adopt: Lidar spoofing attack detection based on point-level temporal consistency.arXiv preprint arXiv:2310.14504, 2023

  65. [65]

    Sentinet: Detecting localized universal attacks against deep learning systems

    Edward Chou, Florian Tramer, and Giancarlo Pellegrino. Sentinet: Detecting localized universal attacks against deep learning systems. InSPW, 2020

  66. [66]

    Gupta, Mykel J

    Shushman Choudhury, Jayesh K. Gupta, Mykel J. Kochenderfer, Dorsa Sadigh, and Jeannette Bohg. Dynamic multi-robot task allocation under uncertainty and temporal constraints.Autonomous Robots, 2022

  67. [67]

    Handover control for human-robot and robot-robot collaboration.Frontiers in Robotics and AI, 2021

    Marco Costanzo, Giuseppe De Maria, and Ciro Natale. Handover control for human-robot and robot-robot collaboration.Frontiers in Robotics and AI, 2021

  68. [68]

    Pybullet, a python module for physics simulation for games, robotics and machine learning.http://pybullet.org, 2016–2021

    Erwin Coumans and Yunfei Bai. Pybullet, a python module for physics simulation for games, robotics and machine learning.http://pybullet.org, 2016–2021

  69. [69]

    SagarDasgupta,AbdullahAhmed,MizanurRahman,andThejeshNBandi. Unveilingthestealthythreat: Analyzing slow drift gps spoofing attacks for autonomous vehicles in urban environments and enabling the resilience.arXiv preprint arXiv:2401.01394, 2024

  70. [70]

    Navsim: Data-drivennon-reactiveautonomousvehiclesimulation and benchmarking

    Daniel Dauner, Marcel Hallgarten, Tianyu Li, Xinshuo Weng, Zhiyu Huang, Zetong Yang, Hongyang Li, Igor Gilitschenski,BorisIvanovic,MarcoPavone,etal. Navsim: Data-drivennon-reactiveautonomousvehiclesimulation and benchmarking. InNeurIPS, 2024

  71. [71]

    Open challenges in multi-agent security: Towards secure systems of interacting ai

    Christian Schroeder de Witt. Open challenges in multi-agent security: Towards secure systems of interacting ai. arXiv preprint arXiv:2505.02077, 2025

  72. [72]

    Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 2025

    Zehang Deng, Yongjian Guo, Changzhou Han, Wanlun Ma, Junwu Xiong, Sheng Wen, and Yang Xiang. Ai agents under threat: A survey of key security challenges and future pathways.ACM Computing Surveys, 2025

  73. [73]

    Learning to collide: An adaptive safety-critical scenarios generating method

    Wenhao Ding, Baiming Chen, Minjun Xu, and Ding Zhao. Learning to collide: An adaptive safety-critical scenarios generating method. InIROS, 2020

  74. [74]

    Doan, Yingjie Lao, Peng Yang, and Ping Li

    Khoa D. Doan, Yingjie Lao, Peng Yang, and Ping Li. Defending backdoor attacks on vision transformer via patch processing. InAAAI, 2023

  75. [75]

    Viewfool: Evaluating the robustness of visual recognition to adversarial viewpoints

    Yinpeng Dong, Shouwei Ruan, Hang Su, Caixin Kang, Xingxing Wei, and Jun Zhu. Viewfool: Evaluating the robustness of visual recognition to adversarial viewpoints. InNeurIPS, 2022

  76. [76]

    Carla: An open urban driving simulator

    Alexey Dosovitskiy, German Ros, Felipe Codevilla, Antonio Lopez, and Vladlen Koltun. Carla: An open urban driving simulator. InCoRL, 2017

  77. [77]

    Human–robot object handover: Recent progress and future direction.Robotics, 2024

    Haonan Duan, Yifan Yang, Daheng Li, and Peng Wang. Human–robot object handover: Recent progress and future direction.Robotics, 2024

  78. [78]

    TRAP: Tail-aware ranking attack for world-model planning.arXiv preprint arXiv:2605.01950, 2026

    Siyuan Duan, Ke Zhang, and Xizhao Luo. TRAP: Tail-aware ranking attack for world-model planning.arXiv preprint arXiv:2605.01950, 2026. 52

  79. [79]

    A robust multi-sensor fusion model against adversarial patch attack.Wireless Networks, 2026

    Aya El-Fatyany. A robust multi-sensor fusion model against adversarial patch attack.Wireless Networks, 2026

  80. [80]

    Drones in distress: A game-theoretic countermeasure for protecting uavs against gps spoofing.IEEE Internet of Things Journal (IoT-J), 2019

    AbdelRahman Eldosouky, Aidin Ferdowsi, and Walid Saad. Drones in distress: A game-theoretic countermeasure for protecting uavs against gps spoofing.IEEE Internet of Things Journal (IoT-J), 2019

Showing first 80 references.