When Coordination Becomes a Threat: Communication Attacks in LLM-Controlled Multi-Robot Systems
arXiv SecurityArchived Aug 10, 2026✓ Full text saved
arXiv:2608.06830v1 Announce Type: cross Abstract: Large Language Models (LLMs) are increasingly used as high-level planners in embodied multi-robot systems, enabling robots to interpret natural language instructions and coordinate executable actions. Yet, this growing reliance on LLM planners also raises security concerns. Prior work has focused mainly on individual robots, while communication risks in multi-robot collaboration remain insufficiently understood. Existing multi-robot studies are f
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Robotics
[Submitted on 7 Aug 2026]
When Coordination Becomes a Threat: Communication Attacks in LLM-Controlled Multi-Robot Systems
Zhen Huang, Zhihuang Liu, Weijia Shi, Yifan Yang, Weishang Wu, Zhiping Cai
Large Language Models (LLMs) are increasingly used as high-level planners in embodied multi-robot systems, enabling robots to interpret natural language instructions and coordinate executable actions. Yet, this growing reliance on LLM planners also raises security concerns. Prior work has focused mainly on individual robots, while communication risks in multi-robot collaboration remain insufficiently understood. Existing multi-robot studies are further limited to preliminary analysis under the Decentralized Multi-agent System (DMAS) architecture, so it remains unclear whether these risks persist across other common communication architectures and how attacker access settings shape their propagation. To fill this gap, we formulate two communication attacks corresponding to distinct attacker access settings: the External Entry Point Attack and the Privileged In-System Attack. We evaluate both attacks across DMAS, HMAS-1, and HMAS-2 using three LLMs and five embodied multi-robot tasks. Results show that unsafe information can turn into unsafe actions across all three architectures: DMAS reaches a 96.7\% entry endorsement rate and a 100\% post endorsement activation rate, HMAS-1 reaches a 97.8\% unsafe action success rate, and HMAS-2 triggers 88.3\% of task defined unsafe action slots. To mitigate risks from trusted information flow, we introduce the Claim Provenance and Verification (CPV) Gate, which verifies communicated claims before downstream reuse and reduces the violation rate from 70.0\% to 36.6\%.
Comments: 17 pages, 8 figures, 4 tables
Subjects: Robotics (cs.RO); Cryptography and Security (cs.CR)
Cite as: arXiv:2608.06830 [cs.RO]
(or arXiv:2608.06830v1 [cs.RO] for this version)
https://doi.org/10.48550/arXiv.2608.06830
Focus to learn more
Submission history
From: Zhen Huang [view email]
[v1] Fri, 7 Aug 2026 05:39:27 UTC (11,816 KB)
Access Paper:
HTML (experimental)
view license
Current browse context:
cs.RO
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
cs.CR
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)