PulseAugur
EN
LIVE 12:34:37

Physical prompt injection attacks compromise VLM-controlled robots

Researchers have investigated prompt injection attacks on robots controlled by Vision-Language Models (VLMs). The first study systematically examined physical prompt injection using adversarial text in the robot's visual field, categorizing attacks and testing them on three frontier VLMs (GPT-4o, Gemini 2.5 Flash, Qwen3-VL-32B). These attacks succeeded at rates between 5% and 29.4%, with authority-impersonating and negation attacks proving cross-model transferable. The second study focused on multi-agent robotic systems, demonstrating that prompt injection can induce adversarial actions and propagate between agents, impacting task completion and safety. Both studies highlight the vulnerability of VLM-controlled robots to such attacks and explore potential mitigation strategies. AI

IMPACT Highlights significant security vulnerabilities in AI-controlled robotics, necessitating the development of robust defenses against adversarial manipulation.

RANK_REASON The cluster consists of two academic papers published on arXiv detailing research into prompt injection attacks on robots controlled by Vision-Language Models.

Read on arXiv cs.MA (Multiagent) →

AI-generated summary · Google Gemini · from 4 sources. How we write summaries →

Physical prompt injection attacks compromise VLM-controlled robots

COVERAGE [4]

  1. arXiv cs.AI TIER_1 English(EN) · S. M . Bhagya P. Samarakoon, M. A. Viraj J. Muthugala, W. K. R. Sachinthana, Mohan Rajesh Elara ·

    Hijacking Robots with a Piece of Paper: A Systematic Study of Physical Prompt Injection in VLM-Controlled Robots

    arXiv:2608.05715v1 Announce Type: cross Abstract: Vision-Language Models (VLMs) are increasingly deployed as planners in robotic systems, where they translate natural-language commands into executable actions grounded in visual scene understanding. This tight coupling between per…

  2. arXiv cs.AI TIER_1 English(EN) · Neha Nagaraja, Amisha Bagari, Hayretdin Bahsi ·

    When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

    arXiv:2608.00747v2 Announce Type: replace-cross Abstract: Large language models are increasingly integrated into autonomous robotic systems for task planning and control, but this integration exposes them to prompt injection attacks that can lead to unsafe decisions and physical …

  3. arXiv cs.MA (Multiagent) TIER_1 English(EN) · Hayretdin Bahsi ·

    When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

    Large language models are increasingly integrated into autonomous robotic systems for task planning and control, but this integration exposes them to prompt injection attacks that can lead to unsafe decisions and physical harm. Multi-agent settings increase the risks through cros…

  4. arXiv cs.MA (Multiagent) TIER_1 English(EN) · Hayretdin Bahsi ·

    When Prompts Control Robots: Prompt Injection Attacks in Multi-Agent Robotic Systems

    Large language models are increasingly integrated into autonomous robotic systems for task planning and control, but this integration exposes them to prompt injection attacks that can lead to unsafe decisions and physical harm. Multi-agent settings increase the risks through cros…