Research
LLM-Coordinated Robot Teams Endorse Injected Instructions 96.7% of the Time; A Provenance Gate Cuts Violations From 70.0% to 36.6%
Testing External Entry Point and Privileged In-System attacks across three communication architectures (DMAS, HMAS-1, HMAS-2), three LLMs, and five embodied multi-robot tasks, researchers found unsafe information converts to unsafe physical action in all three topologies. DMAS showed a 96.7% entry endorsement rate with 100% post-endorsement activation, HMAS-1 a 97.8% unsafe action success rate, and HMAS-2 triggered 88.3% of task-defined unsafe action slots. A Claim Provenance and Verification gate cut the violation rate from 70.0% to 36.6% — meaningful mitigation, but far from closure.
↳ Follow the thread