April 2026Unreviewed
Semantic Denial of Service in LLM-controlled robots
Jonathan Steinberg, Oren Gal
Abstract
Safety-oriented instruction-following is supposed to keep LLM-controlled robots safe. We show it also creates an availability attack surface. By injecting short safety-plausible phrases (1-5 tokens) into a robots audio channel, an adversary can trigger the models safety reasoning to halt or disrupt execution without jailbreaking the model or overriding its policy. In the embodied setting, this is a semantic denial-of-service attack: the agent stops because the injected signal looks like a legiti
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{steinberg2026semantic,
title = {{Semantic Denial of Service in LLM-controlled robots}},
author = {Jonathan Steinberg and Oren Gal},
year = {2026},
month = apr,
eprint = {2604.24790},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.24790}
}