{"id":"https://openalex.org/W4416748835","doi":"https://doi.org/10.1109/iros60139.2025.11246863","title":"On the Vulnerability of LLM/VLM-Controlled Robotics","display_name":"On the Vulnerability of LLM/VLM-Controlled Robotics","publication_year":2025,"publication_date":"2025-10-19","ids":{"openalex":"https://openalex.org/W4416748835","doi":"https://doi.org/10.1109/iros60139.2025.11246863"},"language":null,"primary_location":{"id":"doi:10.1109/iros60139.2025.11246863","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iros60139.2025.11246863","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5078545561","display_name":"Xiyang Wu","orcid":"https://orcid.org/0000-0001-8538-8267"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Xiyang Wu","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052013511","display_name":"Souradip Chakraborty","orcid":null},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Souradip Chakraborty","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083695837","display_name":"Ruiqi Xian","orcid":null},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ruiqi Xian","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100676081","display_name":"Jing Liang","orcid":"https://orcid.org/0000-0003-0811-0223"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jing Liang","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014003390","display_name":"Tianrui Guan","orcid":"https://orcid.org/0000-0002-6892-9778"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tianrui Guan","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027505093","display_name":"Fuxiao Liu","orcid":"https://orcid.org/0000-0002-3078-0613"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fuxiao Liu","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053858045","display_name":"Brian M. Sadler","orcid":"https://orcid.org/0000-0002-9564-3812"},"institutions":[{"id":"https://openalex.org/I166416128","display_name":"DEVCOM Army Research Laboratory","ror":"https://ror.org/011hc8f90","country_code":"US","type":"government","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I166416128","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]},{"id":"https://openalex.org/I2802705668","display_name":"United States Army Combat Capabilities Development Command","ror":"https://ror.org/02rdkx920","country_code":"US","type":"other","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Brian M. Sadler","raw_affiliation_strings":["DEVCOM Army Research Laboratory,Adelphi,MD,USA"],"affiliations":[{"raw_affiliation_string":"DEVCOM Army Research Laboratory,Adelphi,MD,USA","institution_ids":["https://openalex.org/I166416128","https://openalex.org/I2802705668"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004194238","display_name":"Dinesh Manocha","orcid":"https://orcid.org/0000-0001-7047-9801"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dinesh Manocha","raw_affiliation_strings":["University of Maryland,College Park,MD,USA"],"affiliations":[{"raw_affiliation_string":"University of Maryland,College Park,MD,USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5039563144","display_name":"Amrit Singh Bedi","orcid":"https://orcid.org/0000-0002-8807-2695"},"institutions":[{"id":"https://openalex.org/I106165777","display_name":"University of Central Florida","ror":"https://ror.org/036nfer12","country_code":"US","type":"education","lineage":["https://openalex.org/I106165777"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Amrit Singh Bedi","raw_affiliation_strings":["University of Central Florida,Orlando,FL,USA"],"affiliations":[{"raw_affiliation_string":"University of Central Florida,Orlando,FL,USA","institution_ids":["https://openalex.org/I106165777"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5078545561"],"corresponding_institution_ids":["https://openalex.org/I66946132"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.20548357,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1914","last_page":"1921"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.4616999924182892,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.4616999924182892,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.1274999976158142,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.06859999895095825,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.6593000292778015},{"id":"https://openalex.org/keywords/robotics","display_name":"Robotics","score":0.6500999927520752},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6298999786376953},{"id":"https://openalex.org/keywords/robot","display_name":"Robot","score":0.5964999794960022},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5002999901771545},{"id":"https://openalex.org/keywords/modality","display_name":"Modality (human\u2013computer interaction)","score":0.46810001134872437},{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.39500001072883606}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6970000267028809},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.6593000292778015},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6516000032424927},{"id":"https://openalex.org/C34413123","wikidata":"https://www.wikidata.org/wiki/Q170978","display_name":"Robotics","level":3,"score":0.6500999927520752},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6298999786376953},{"id":"https://openalex.org/C90509273","wikidata":"https://www.wikidata.org/wiki/Q11012","display_name":"Robot","level":2,"score":0.5964999794960022},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5002999901771545},{"id":"https://openalex.org/C2780226545","wikidata":"https://www.wikidata.org/wiki/Q6888030","display_name":"Modality (human\u2013computer interaction)","level":2,"score":0.46810001134872437},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.39500001072883606},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.3896999955177307},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3619999885559082},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.3582000136375427},{"id":"https://openalex.org/C120936955","wikidata":"https://www.wikidata.org/wiki/Q2155640","display_name":"Empirical research","level":2,"score":0.35569998621940613},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.3116999864578247},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.2766000032424927},{"id":"https://openalex.org/C2776544517","wikidata":"https://www.wikidata.org/wiki/Q189447","display_name":"Unexpected events","level":2,"score":0.2662000060081482},{"id":"https://openalex.org/C115901376","wikidata":"https://www.wikidata.org/wiki/Q184199","display_name":"Automation","level":2,"score":0.251800000667572}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/iros60139.2025.11246863","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iros60139.2025.11246863","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":27,"referenced_works":["https://openalex.org/W3109097593","https://openalex.org/W4323345726","https://openalex.org/W4383066231","https://openalex.org/W4383097638","https://openalex.org/W4383108296","https://openalex.org/W4383648142","https://openalex.org/W4386566886","https://openalex.org/W4387819628","https://openalex.org/W4388182168","https://openalex.org/W4388886073","https://openalex.org/W4390771941","https://openalex.org/W4401042875","https://openalex.org/W4401415303","https://openalex.org/W4402671834","https://openalex.org/W4402726948","https://openalex.org/W4404781801","https://openalex.org/W4405022833","https://openalex.org/W4405785079","https://openalex.org/W4405910844","https://openalex.org/W4406602253","https://openalex.org/W4407341646","https://openalex.org/W4409326453","https://openalex.org/W4412945537","https://openalex.org/W4413917742","https://openalex.org/W4413924978","https://openalex.org/W4413925879","https://openalex.org/W4414050442"],"related_works":[],"abstract_inverted_index":{"In":[0],"this":[1,68],"work,":[2],"we":[3,70],"highlight":[4],"vulnerabilities":[5,74,101],"in":[6,90,129],"robotic":[7,77,133,158],"systems":[8,78],"integrating":[9],"large":[10],"language":[11],"models":[12,16,43],"(LLMs)":[13],"and":[14,79,102,127,144,152],"vision-language":[15],"(VLMs)":[17],"due":[18],"to":[19,47,59,98,148],"input":[20,36,51,91,118,141],"modality":[21,142],"sensitivities.":[22],"While":[23],"LLM/VLM-controlled":[24,76,132,157],"robots":[25],"show":[26,115],"impressive":[27],"performance":[28],"across":[29],"various":[30],"tasks,":[31],"their":[32,104],"reliability":[33],"under":[34],"slight":[35],"variations":[37,89],"remains":[38],"underexplored":[39],"yet":[40],"critical.":[41],"These":[42,135],"are":[44],"highly":[45],"sensitive":[46],"instruction":[48],"or":[49],"perceptual":[50],"changes,":[52],"which":[53],"can":[54],"trigger":[55],"misalignment":[56],"issues,":[57],"leading":[58],"execution":[60,122],"failures":[61],"with":[62],"severe":[63],"real-world":[64],"consequences.":[65],"To":[66],"study":[67],"issue,":[69],"analyze":[71],"the":[72,138,150],"misalignment-induced":[73],"within":[75],"present":[80],"a":[81],"mathematical":[82],"formulation":[83],"for":[84],"failure":[85],"modes":[86],"arising":[87],"from":[88],"modalities.":[92],"We":[93],"propose":[94],"empirical":[95],"perturbation":[96],"strategies":[97],"expose":[99],"these":[100],"validate":[103],"effectiveness":[105],"through":[106],"experiments":[107],"on":[108],"multiple":[109],"robot":[110],"manipulation":[111],"tasks.":[112],"Our":[113],"results":[114],"that":[116],"simple":[117],"perturbations":[119],"reduce":[120],"task":[121],"success":[123],"rates":[124],"by":[125],"22.2%":[126],"14.6%":[128],"two":[130],"representative":[131],"systems.":[134,159],"findings":[136],"underscore":[137],"importance":[139],"of":[140,155],"robustness":[143],"motivate":[145],"further":[146],"research":[147],"ensure":[149],"safe":[151],"reliable":[153],"deployment":[154],"advanced":[156]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-28T00:00:00"}
