日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
マルチロボット/セキュリティarXiv:2610.04744

稀に大きく嘘をつく:LLMロボットチームへのステルス内部攻撃

Lie Rarely, Lie Big: Stealthy Insider Attacks on LLM Robot Teams

シェア:XThreadsFacebookLINEはてブBluesky

LLMエージェントに計画と信頼を委ねたマルチロボットチームにおいて、1台の侵害ロボットが検証予算を考慮しつつ検証されにくい記録に稀で大きな嘘をつくステルス攻撃を定式化し、検証確率の下限と地図誤差の上限を導出した。

詳しい要約

1. どんなもの?

- LLMエージェントに計画と相互信頼を委任したロボットチームにおいて、1台の侵害されたロボットが共有成果を破壊し得る脅威を研究。 - 物理世界で検証可能な測定を行うマルチロボット調査タスクを対象。 - 検証にはミッション進行に使える予算を消費する。 - 侵害ロボットをシステム理論的なステルス敵対者として扱い、エネルギー制約ではなくチームの検出器によって制限される。

2. 先行研究と比べてどこがすごい?

- 従来の敵対者モデルはエネルギー制約を仮定することが多いが、本研究はチームの検証予算と検出器を制約とする点が新しい。 - LLMロボットチームにおける内部脅威を、物理世界で検証可能なタスクで定量的に分析。 - 検証確率の下限とマップ誤差の上限を導出し、ステルス予算と損害の交換レートを明らかにした。

3. 技術・手法の肝は?

- 敵対者の報告が検証される確率を、通信グラフの次数と検証予算で下限評価。 - 任意のステルス敵対者によるマップ誤差を、バイアス分布上の線形計画問題の値で上限評価。 - 解はステルス予算と損害の交換レートを与える。 - 臨界検証レベル以下では、検証されにくい記録に稀に完全な嘘をつくのが最悪の攻撃。 - 臨界レベル以上では、ノイズに隠れた小さなバイアスが有効。

4. どうやって有効だと検証した?

- 正直なロボットがLLMエージェントである実験を実施。 - 攻撃が実際に消費した予算において、両方の境界が成立することを確認。 - LLMロボットがどの記録を再確認するかは偏りがないが、再確認の量は予測不能であることも示した。

5. 議論はある?

- 検証予算が限られる状況で、ステルス攻撃の戦略が予算レベルによって変化することを理論と実験で示唆。 - LLMロボットの再確認行動の偏りと予測不能性が防御設計に影響を与える可能性。 - 要旨からは、他のタスクや攻撃モデルへの一般化可能性や具体的な防御策については不明。

6. 次に読むべき論文は?

- 要旨で参照/比較されている研究は明示されていない。 - 関連手法として、マルチロボットシステムにおける敵対的攻撃、LLMエージェントの信頼性、システム理論的ステルス攻撃、線形計画法を用いた攻撃分析などが考えられる。 - 同分野の定番として、Byzantine fault toleranceやsecure multi-robot planningの文献を参照するのが良い。

※ AIが要旨から生成した要約です。正確性は原文をご確認ください。

著者: Sribalaji C. Anand, George J. Pappas

分類: cs.RO, cs.MA

原文アブストラクト

When a team of robots delegates planning and mutual trust to LLM agents, a single compromised robot can corrupt the shared outcome. We study this threat in a grounded task: a multi-robot survey in which measurements can be verified against the physical world, but every verification costs budget that would otherwise advance the mission. We treat the compromised robot as a stealthy adversary in the system-theoretic sense: it is limited not by an energy bound but by the team's own detectors. We then derive two bounds. First, the probability that the adversary's reports are verified is bounded below in terms of the degrees in the communication graph and the verification budget. Second, the map error caused by any stealthy adversary is bounded above by the value of a linear program over the adversary's bias distributions; its solution is an exchange rate between stealth budget and damage: below a critical verification level the worst stealthy attack tells rare, full-magnitude lies on the records least likely to be verified, and above it the better purchase is small biases hidden in the noise. In experiments where the honest robots are LLM agents, both bounds hold at the budget the attack actually spent. The experiments also show that which records an LLM robot re-checks is unbiased, but how much it re-checks is unpredictable.

PR本紙発行元 EmplifAI