Prompt Injection Via Road Signs
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读用户提供的文章内容,理解其主要观点。 这篇文章介绍了一种名为CHAI的攻击方法,全称是Command Hijacking Against Embodied AI。它针对的是具身AI系统,利用大型视觉语言模型的多模态语言解释能力。攻击者通过在视觉输入中嵌入误导性的自然语言指令,如误导标志,然后系统性地搜索token空间,构建提示词字典,并引导攻击模型生成视觉攻击提示。 文章还提到他们在四个LVLM代理和一个真实机器人车辆上进行了评估,结果显示CHAI的表现优于现有的攻击方法。这表明具身AI系统虽然在处理边缘案例方面表现出色,但也带来了新的安全风险。 接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:CHAI是什么、它的机制、评估结果以及安全风险。同时,避免使用“文章内容总结”之类的开头语。 可能会这样组织:介绍CHAI是一种针对具身AI的攻击方法,利用视觉语言模型的多模态能力,在视觉输入中嵌入误导指令,生成攻击提示,并在多个场景中有效。这突显了具身AI的安全隐患。 最后检查字数是否符合要求,并确保信息准确无误。 </think> 研究介绍了一种针对具身人工智能的新攻击方法CHAI(Command Hijacking Against Embodied AI),通过利用大型视觉语言模型的多模态能力,在视觉输入中嵌入误导性指令生成攻击提示,并在无人机、自动驾驶等场景中有效测试,突显了具身AI系统的潜在安全风险。 2026-2-11 12:3:22 Author: www.schneier.com(查看原文) 阅读量:1 收藏

Interesting research: “CHAI: Command Hijacking Against Embodied AI.”

Abstract: Embodied Artificial Intelligence (AI) promises to handle edge cases in robotic vehicle systems where data is scarce by using common-sense reasoning grounded in perception and action to generalize beyond training distributions and adapt to novel real-world situations. These capabilities, however, also create new security risks. In this paper, we introduce CHAI (Command Hijacking against embodied AI), a new class of prompt-based attacks that exploit the multimodal language interpretation abilities of Large Visual-Language Models (LVLMs). CHAI embeds deceptive natural language instructions, such as misleading signs, in visual input, systematically searches the token space, builds a dictionary of prompts, and guides an attacker model to generate Visual Attack Prompts. We evaluate CHAI on four LVLM agents; drone emergency landing, autonomous driving, and aerial object tracking, and on a real robotic vehicle. Our experiments show that CHAI consistently outperforms state-of-the-art attacks. By exploiting the semantic and multimodal reasoning strengths of next-generation embodied AI systems, CHAI underscores the urgent need for defenses that extend beyond traditional adversarial robustness.

News article.

Tags: , , ,

Posted on February 11, 2026 at 7:03 AM1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2026/02/prompt-injection-via-road-signs.html
如有侵权请联系:admin#unsafe.sh