ARTFEED — Contemporary Art Intelligence

Physical Prompt Injection Attacks on VLM-Controlled Robots: A Systematic Study

ai-technology · 2026-08-07

A recent preprint on arXiv (2608.05715) details a comprehensive examination of physical prompt injection attacks targeting robots managed by Vision-Language Models (VLMs). The study categorizes attacks into four types: indirect signage, authority impersonation, task redefinition, and conflict injection, supported by a benchmark of 20 distinct attack prompts. These prompts were tested across three different physical scene setups and three variations of command phrasing, differing in specificity and clarity of rules. In over 5,670 trials involving three leading VLMs (GPT-4o, Gemini 2.5 Flash, Qwen3-VL-32B), the success rates of attacks were recorded at 27.0% and 29.4%, with a third rate unspecified. This research reveals a new vulnerability where adversarial text in a robot's visual range may serve as an indirect prompt injection into the VLM's reasoning, raising concerns about the safety and reliability of autonomous systems. The results emphasize the urgent need for strong defenses in VLM-driven robotic planning, especially as these technologies are increasingly utilized in practical scenarios. This paper is accessible on arXiv and was noted as a cross-type submission.

Key facts

  • arXiv preprint 2608.05715 presents a systematic study of physical prompt injection attacks on VLM-controlled robots.
  • The study introduces a four-category taxonomy: indirect signage, task redefinition, authority impersonation, and conflict injection.
  • A benchmark of 20 attack prompts was evaluated across three physical scene layouts and three command formulations.
  • 5,670 trials were conducted on three frontier VLMs: GPT-4o, Gemini 2.5 Flash, and Qwen3-VL-32B.
  • Attack success rates were 27.0% for GPT-4o, 29.4% for Gemini 2.5 Flash, and an unspecified third rate.
  • The attack surface involves adversarial text in the robot's visual field acting as indirect prompt injection.
  • The study emphasizes the vulnerability of VLM-based robotic planning systems.
  • The paper was announced as a cross-type submission on arXiv.

Entities

Institutions

  • arXiv

Sources