Skip to content
Search
paperApril 2026Unreviewed

Semantic Denial of Service in LLM-controlled robots

Jonathan Steinberg, Oren Gal

Abstract

Safety-oriented instruction-following is supposed to keep LLM-controlled robots safe. We show it also creates an availability attack surface. By injecting short safety-plausible phrases (1-5 tokens) into a robots audio channel, an adversary can trigger the models safety reasoning to halt or disrupt execution without jailbreaking the model or overriding its policy. In the embodied setting, this is a semantic denial-of-service attack: the agent stops because the injected signal looks like a legiti

Categories

Framework mappings

MITRE ATLAS
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{steinberg2026semantic,
  title = {{Semantic Denial of Service in LLM-controlled robots}},
  author = {Jonathan Steinberg and Oren Gal},
  year = {2026},
  month = apr,
  eprint = {2604.24790},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.24790}
}