Skip to content
Search
paperAugust 2026Unreviewed

Security of Foundation-Model-Powered Embodied Agents: Attack Surfaces, Attacks, Defenses, and Evaluation

Jiawei Liu, Jiacheng Guo, Tian Zhang, Yi-Wei Xu, Juan Wang, Jinlin Fan, Bowen Xiao

Abstract

Foundation models are increasingly used for perception, reasoning, planning, and action generation in embodied agents, creating security risks that can propagate from digital inputs to physical behavior. Existing surveys often organize threats by mechanisms such as jailbreaks, prompt injection, backdoors, poisoning, or adversarial examples, but these categories do not consistently identify where an adversary first enters the embodied control loop. We present a trust-boundary-centric survey of fo

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0043Craft Adversarial Data
  • AML.T0051LLM Prompt Injection
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{liu2026security,
  title = {{Security of Foundation-Model-Powered Embodied Agents: Attack Surfaces, Attacks, Defenses, and Evaluation}},
  author = {Jiawei Liu and Jiacheng Guo and Tian Zhang and Yi-Wei Xu and Juan Wang and Jinlin Fan and Bowen Xiao},
  year = {2026},
  month = aug,
  eprint = {2608.16843},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/06190ffa90147391f987fa830340186f54729f19}
}