{"id":"https://openalex.org/W7131258375","doi":"https://doi.org/10.1109/lra.2026.3667488","title":"Safety Guardrails for LLM-Enabled Robots","display_name":"Safety Guardrails for LLM-Enabled Robots","publication_year":2026,"publication_date":"2026-02-24","ids":{"openalex":"https://openalex.org/W7131258375","doi":"https://doi.org/10.1109/lra.2026.3667488"},"language":null,"primary_location":{"id":"doi:10.1109/lra.2026.3667488","is_oa":false,"landing_page_url":"https://doi.org/10.1109/lra.2026.3667488","pdf_url":null,"source":{"id":"https://openalex.org/S4210169774","display_name":"IEEE Robotics and Automation Letters","issn_l":"2377-3766","issn":["2377-3766"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Robotics and Automation Letters","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5050088824","display_name":"Zachary Ravichandran","orcid":null},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zachary Ravichandran","raw_affiliation_strings":["University of Pennsylvania, Philadelpha, PA, USA"],"raw_orcid":"https://orcid.org/0009-0001-4380-3212","affiliations":[{"raw_affiliation_string":"University of Pennsylvania, Philadelpha, PA, USA","institution_ids":["https://openalex.org/I79576946"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028501158","display_name":"Alexander Robey","orcid":"https://orcid.org/0009-0003-5693-2819"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alexander Robey","raw_affiliation_strings":["Carnegie Mellon University, Pittsburgh, PA, USA"],"raw_orcid":"https://orcid.org/0009-0003-5693-2819","affiliations":[{"raw_affiliation_string":"Carnegie Mellon University, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126666329","display_name":"Vijay Kumar","orcid":null},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Vijay Kumar","raw_affiliation_strings":["University of Pennsylvania, Philadelpha, PA, USA"],"raw_orcid":"https://orcid.org/0000-0002-3902-9391","affiliations":[{"raw_affiliation_string":"University of Pennsylvania, Philadelpha, PA, USA","institution_ids":["https://openalex.org/I79576946"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126694991","display_name":"George J. Pappas","orcid":null},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"George J. Pappas","raw_affiliation_strings":["University of Pennsylvania, Philadelpha, PA, USA"],"raw_orcid":"https://orcid.org/0000-0001-9081-0637","affiliations":[{"raw_affiliation_string":"University of Pennsylvania, Philadelpha, PA, USA","institution_ids":["https://openalex.org/I79576946"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5126724603","display_name":"Hamed Hassani","orcid":null},"institutions":[{"id":"https://openalex.org/I79576946","display_name":"University of Pennsylvania","ror":"https://ror.org/00b30xv10","country_code":"US","type":"education","lineage":["https://openalex.org/I79576946"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hamed Hassani","raw_affiliation_strings":["University of Pennsylvania, Philadelpha, PA, USA"],"raw_orcid":"https://orcid.org/0000-0002-9448-8750","affiliations":[{"raw_affiliation_string":"University of Pennsylvania, Philadelpha, PA, USA","institution_ids":["https://openalex.org/I79576946"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":41.8317,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.99785761,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":"11","issue":"4","first_page":"4649","last_page":"4656"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T14445","display_name":"Transportation Safety and Impact Analysis","score":0.8226000070571899,"subfield":{"id":"https://openalex.org/subfields/2205","display_name":"Civil and Structural Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T14445","display_name":"Transportation Safety and Impact Analysis","score":0.8226000070571899,"subfield":{"id":"https://openalex.org/subfields/2205","display_name":"Civil and Structural Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13295","display_name":"Safety Systems Engineering in Autonomy","score":0.014700000174343586,"subfield":{"id":"https://openalex.org/subfields/2213","display_name":"Safety, Risk, Reliability and Quality"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11099","display_name":"Autonomous Vehicle Technology and Safety","score":0.00839999970048666,"subfield":{"id":"https://openalex.org/subfields/2203","display_name":"Automotive Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robot","display_name":"Robot","score":0.6189000010490417},{"id":"https://openalex.org/keywords/robotics","display_name":"Robotics","score":0.5636000037193298},{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.4661000072956085},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.4235999882221222},{"id":"https://openalex.org/keywords/transformative-learning","display_name":"Transformative learning","score":0.4025999903678894},{"id":"https://openalex.org/keywords/ground","display_name":"Ground","score":0.3986000120639801},{"id":"https://openalex.org/keywords/system-safety","display_name":"System safety","score":0.366100013256073}],"concepts":[{"id":"https://openalex.org/C90509273","wikidata":"https://www.wikidata.org/wiki/Q11012","display_name":"Robot","level":2,"score":0.6189000010490417},{"id":"https://openalex.org/C34413123","wikidata":"https://www.wikidata.org/wiki/Q170978","display_name":"Robotics","level":3,"score":0.5636000037193298},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.48010000586509705},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.47110000252723694},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.4661000072956085},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.4235999882221222},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4203000068664551},{"id":"https://openalex.org/C70587473","wikidata":"https://www.wikidata.org/wiki/Q7834111","display_name":"Transformative learning","level":2,"score":0.4025999903678894},{"id":"https://openalex.org/C168993435","wikidata":"https://www.wikidata.org/wiki/Q6501125","display_name":"Ground","level":2,"score":0.3986000120639801},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37940001487731934},{"id":"https://openalex.org/C132835097","wikidata":"https://www.wikidata.org/wiki/Q7663745","display_name":"System safety","level":2,"score":0.366100013256073},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.36390000581741333},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3580999970436096},{"id":"https://openalex.org/C2776350369","wikidata":"https://www.wikidata.org/wiki/Q843479","display_name":"Control logic","level":2,"score":0.2863999903202057},{"id":"https://openalex.org/C2776505523","wikidata":"https://www.wikidata.org/wiki/Q4785468","display_name":"Plan (archaeology)","level":2,"score":0.28220000863075256},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.2809999883174896},{"id":"https://openalex.org/C557691694","wikidata":"https://www.wikidata.org/wiki/Q185091","display_name":"Remote control","level":2,"score":0.2768999934196472},{"id":"https://openalex.org/C2775941552","wikidata":"https://www.wikidata.org/wiki/Q25212305","display_name":"Isolation (microbiology)","level":2,"score":0.2678000032901764},{"id":"https://openalex.org/C145460709","wikidata":"https://www.wikidata.org/wiki/Q859951","display_name":"Human\u2013robot interaction","level":3,"score":0.25920000672340393},{"id":"https://openalex.org/C2777877512","wikidata":"https://www.wikidata.org/wiki/Q1116097","display_name":"Common ground","level":2,"score":0.2508000135421753}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/lra.2026.3667488","is_oa":false,"landing_page_url":"https://doi.org/10.1109/lra.2026.3667488","pdf_url":null,"source":{"id":"https://openalex.org/S4210169774","display_name":"IEEE Robotics and Automation Letters","issn_l":"2377-3766","issn":["2377-3766"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Robotics and Automation Letters","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/7","display_name":"Affordable and clean energy","score":0.5304310321807861}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Although":[0],"the":[1,50,61,73,99,169,210,218,223],"integration":[2],"of":[3,53,75,171,212,225],"large":[4],"language":[5],"models":[6],"(LLMs)":[7],"into":[8],"robotics":[9],"has":[10,15],"unlocked":[11],"transformative":[12],"capabilities,":[13],"it":[14],"also":[16,187],"introduced":[17],"significant":[18],"safety":[19,45,58,74,93,121,137,219],"concerns,":[20],"ranging":[21],"from":[22,110,174],"average-case":[23],"LLM":[24,57,107],"errors":[25],"(<italic":[26],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[27,81,88,129,166,191,214],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">e.g.,</i>":[28],"hallucinations)":[29],"to":[30,118,177,216],"adversarial":[31],"jailbreaking":[32,163],"attacks,":[33,164,198],"which":[34],"can":[35],"produce":[36],"harmful":[37],"robot":[38,44],"behavior":[39],"in":[40,68,98],"real-world":[41,69,158],"settings.":[42],"Traditional":[43],"approaches":[46,59],"do":[47],"not":[48],"address":[49],"contextual":[51,136],"vulnerabilities":[52],"LLMs,":[54],"and":[55,113,139,157,199,221],"current":[56],"overlook":[60],"physical":[62],"risks":[63,220],"posed":[64],"by":[65,95,201],"robots":[66],"operating":[67],"environments.":[70],"To":[71],"ensure":[72],"LLM-enabled":[76,226],"robots,":[77],"we":[78],"propose":[79],"<sc":[80,87,128,165,190,213],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">RoboGuard</small>,":[82],"a":[83,103],"two-stage":[84],"guardrail":[85],"architecture.":[86],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">RoboGuard</small>":[89,130,167,192,215],"first":[90],"contextualizes":[91],"pre-defined":[92],"rules":[94],"grounding":[96],"them":[97],"robot's":[100],"environment":[101],"using":[102,143],"root-of-trust":[104,203],"LLM.":[105],"This":[106],"is":[108,193],"shielded":[109],"malicious":[111],"prompts":[112],"employs":[114],"chain-of-thought":[115],"(CoT)":[116],"reasoning":[117],"generate":[119],"context-dependent":[120],"specifications,":[122],"such":[123],"as":[124],"temporal":[125,144],"logic":[126,145],"constraints.":[127],"then":[131],"resolves":[132],"conflicts":[133],"between":[134],"these":[135],"specifications":[138],"potentially":[140],"unsafe":[141,172],"plans":[142,173],"control":[146],"synthesis,":[147],"ensuring":[148],"compliance":[149],"while":[150],"minimally":[151],"violating":[152],"user":[153],"preferences.":[154],"In":[155],"simulation":[156],"experiments":[159],"that":[160,189],"consider":[161],"worst-case":[162],"reduces":[168],"execution":[170],"over":[175],"92%":[176],"below":[178],"3%":[179],"without":[180],"compromising":[181],"performance":[182],"on":[183],"safe":[184],"plans.":[185],"We":[186],"demonstrate":[188,209],"resource-efficient,":[194],"robust":[195],"against":[196],"adaptive":[197],"enhanced":[200],"its":[202],"LLM's":[204],"CoT":[205],"reasoning.":[206],"These":[207],"results":[208],"potential":[211],"mitigate":[217],"enhance":[222],"reliability":[224],"robots.":[227]},"counts_by_year":[{"year":2026,"cited_by_count":6}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-02-25T00:00:00"}
