{"id":"https://openalex.org/W4413925879","doi":"https://doi.org/10.1109/icra55743.2025.11128119","title":"Jailbreaking LLM-Controlled Robots","display_name":"Jailbreaking LLM-Controlled Robots","publication_year":2025,"publication_date":"2025-05-19","ids":{"openalex":"https://openalex.org/W4413925879","doi":"https://doi.org/10.1109/icra55743.2025.11128119"},"language":"en","primary_location":{"id":"doi:10.1109/icra55743.2025.11128119","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icra55743.2025.11128119","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Robotics and Automation (ICRA)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5028501158","display_name":"Alexander Robey","orcid":"https://orcid.org/0009-0003-5693-2819"},"institutions":[{"id":"https://openalex.org/I36788626","display_name":"California University of Pennsylvania","ror":"https://ror.org/01spssf70","country_code":"US","type":"education","lineage":["https://openalex.org/I36788626"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alexander Robey","raw_affiliation_strings":["University of Pennsylvania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Pennsylvania","institution_ids":["https://openalex.org/I36788626"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050088824","display_name":"Zachary Ravichandran","orcid":null},"institutions":[{"id":"https://openalex.org/I36788626","display_name":"California University of Pennsylvania","ror":"https://ror.org/01spssf70","country_code":"US","type":"education","lineage":["https://openalex.org/I36788626"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zachary Ravichandran","raw_affiliation_strings":["University of Pennsylvania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Pennsylvania","institution_ids":["https://openalex.org/I36788626"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102102279","display_name":"Vijay Kumar","orcid":null},"institutions":[{"id":"https://openalex.org/I36788626","display_name":"California University of Pennsylvania","ror":"https://ror.org/01spssf70","country_code":"US","type":"education","lineage":["https://openalex.org/I36788626"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Vijay Kumar","raw_affiliation_strings":["University of Pennsylvania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Pennsylvania","institution_ids":["https://openalex.org/I36788626"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059354479","display_name":"Hamed Hassani","orcid":"https://orcid.org/0000-0002-9448-8750"},"institutions":[{"id":"https://openalex.org/I36788626","display_name":"California University of Pennsylvania","ror":"https://ror.org/01spssf70","country_code":"US","type":"education","lineage":["https://openalex.org/I36788626"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hamed Hassani","raw_affiliation_strings":["University of Pennsylvania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Pennsylvania","institution_ids":["https://openalex.org/I36788626"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029243115","display_name":"George J. Pappas","orcid":"https://orcid.org/0000-0001-9081-0637"},"institutions":[{"id":"https://openalex.org/I36788626","display_name":"California University of Pennsylvania","ror":"https://ror.org/01spssf70","country_code":"US","type":"education","lineage":["https://openalex.org/I36788626"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"George J. Pappas","raw_affiliation_strings":["University of Pennsylvania"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Pennsylvania","institution_ids":["https://openalex.org/I36788626"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I36788626"],"apc_list":null,"apc_paid":null,"fwci":9.1248,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.98339725,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"11948","last_page":"11956"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.972599983215332,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.972599983215332,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12784","display_name":"Modular Robots and Swarm Intelligence","score":0.9391999840736389,"subfield":{"id":"https://openalex.org/subfields/2210","display_name":"Mechanical Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9279000163078308,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robot","display_name":"Robot","score":0.6790643930435181},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5446914434432983},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.23641687631607056}],"concepts":[{"id":"https://openalex.org/C90509273","wikidata":"https://www.wikidata.org/wiki/Q11012","display_name":"Robot","level":2,"score":0.6790643930435181},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5446914434432983},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.23641687631607056}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icra55743.2025.11128119","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icra55743.2025.11128119","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Robotics and Automation (ICRA)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W3035574168","https://openalex.org/W4380319827","https://openalex.org/W4383097638","https://openalex.org/W4383108296","https://openalex.org/W4385430679","https://openalex.org/W4391407102","https://openalex.org/W4392866655","https://openalex.org/W4394862623","https://openalex.org/W4401413894","https://openalex.org/W4402264152","https://openalex.org/W4402354012","https://openalex.org/W4402354036","https://openalex.org/W4402687726","https://openalex.org/W4402753802","https://openalex.org/W4404654684","https://openalex.org/W4407950247"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"The":[0],"recent":[1],"introduction":[2],"of":[3,12,62,169,205,240,257],"large":[4],"language":[5],"models":[6],"(LLMs)":[7],"has":[8,110,127,150],"revolutionized":[9],"the":[10,60,73,108,114,125,148,155,199,203,214,225,232,236,254],"field":[11],"robotics":[13],"by":[14,53],"enabling":[15],"contextual":[16],"reasoning":[17],"and":[18,29,142,164,186],"intuitive":[19],"human-robot":[20],"interaction":[21],"in":[22,65,67,100,224,259],"domains":[23],"as":[24,26,34,177,179],"varied":[25],"manipulation,":[27],"locomotion,":[28],"self-driving":[30,118],"vehicles.":[31],"When":[32],"viewed":[33],"a":[35,95,104,121,131,139,144,241],"stand-alone":[36],"technology,":[37],"LLMs":[38,64,207,258],"are":[39],"known":[40],"to":[41,44,77,113,130,154],"be":[42],"vulnerable":[43],"jailbreaking":[45],"attacks,":[46],"wherein":[47,107,124,147],"mali-cious":[48],"prompters":[49],"elicit":[50],"harmful":[51,89,170],"text":[52,211],"bypassing":[54],"LLM":[55,86],"safety":[56],"guardrails.":[57],"To":[58],"assess":[59],"risks":[61,204],"deploying":[63],"robotics,":[66],"this":[68,247],"paper,":[69],"we":[70,97,173],"introduce":[71],"ROBOPAIR,":[72,176],"first":[74,200,237],"algorithm":[75],"designed":[76],"jailbreak":[78,239],"LLM-controlled":[79,93],"robots.":[80],"Unlike":[81],"existing,":[82],"textual":[83],"attacks":[84],"on":[85,231],"chatbots,":[87],"Robopairelicits":[88],"physical":[90,222],"actions":[91],"from":[92],"robots,":[94],"phenomenon":[96],"experimentally":[98],"demonstrate":[99,174],"three":[101,166],"scenarios:":[102],"(i)":[103],"white-box":[105],"setting,":[106,123,146],"attacker":[109,126,149],"full":[111],"access":[112,129,153],"NVID":[115],"IA":[116],"Dolphins":[117],"LLM,":[119],"(ii)":[120],"gray-box":[122],"partial":[128],"Clearpath":[132],"Robotics":[133,158],"Jackal":[134],"UGV":[135],"robot":[136],"equipped":[137],"with":[138],"GPT-40":[140],"planner,":[141],"(iii)":[143],"black-box":[145],"only":[151],"query":[152],"GPT-3.5-integrated":[156],"Unitree":[157],"Go2robot":[159],"dog.":[160],"In":[161],"each":[162],"scenario":[163],"across":[165],"new":[167],"datasets":[168],"robotic":[171,244],"actions,":[172],"that":[175,202,217],"well":[178],"several":[180],"static":[181],"baselines,":[182],"finds":[183],"jailbreaks":[184],"quickly":[185],"effectively,":[187],"often":[188],"achieving":[189],"100":[190],"%":[191],"attack":[192],"success":[193],"rates.":[194],"Our":[195],"results":[196,230],"reveal,":[197],"for":[198,252],"time,":[201],"jailbroken":[206,218],"extend":[208],"far":[209],"beyond":[210],"generation,":[212],"given":[213],"distinct":[215],"possibility":[216],"robots":[219],"could":[220],"cause":[221],"damage":[223],"real":[226],"world.":[227],"Indeed,":[228],"our":[229],"U":[233],"nitree":[234],"G02represent":[235],"successful":[238],"deployed":[242],"commercial":[243],"system.":[245],"Addressing":[246],"emerging":[248],"vulnerability":[249],"is":[250,263],"critical":[251],"ensuring":[253],"safe":[255],"deployment":[256],"robotics.":[260],"Additional":[261],"media":[262],"available":[264],"at:":[265],"https://robopair.org.":[266]},"counts_by_year":[{"year":2026,"cited_by_count":5},{"year":2025,"cited_by_count":4}],"updated_date":"2026-06-26T08:34:08.712188","created_date":"2025-10-10T00:00:00"}
