arXiv ScienceSearch

arXiv subjects

Jinlin Fan

Publications and source records attributed to Jinlin Fan.

5 recordsLinked to original sources

Breaking Planner Integrity Boundary: Enviroment State-Text Injection Attack on LLM-Driven Embodied Agents

Large language model (LLM)-driven embodied agents rely on environment states to interpret scenes, generate high-level plans, and drive physical execution, making planner-visible state representations a critical security boundary. Existing attacks primarily manipulate user instructions, prompt contexts, model behavior, or perceptual inputs, while paying limited attention to whether environment-state text itself can serve as deceptive task evidence and propagate beyond planning to affect execution outcomes. Because embodied tasks are constrained by entity grounding, action preconditions, spatial relations, and environmental constraints, planning deviation alone does not guarantee adversarial execution. To address this gap, we investigate environment-state text as an independent attack surface and present the first closed-loop Environment State-Text Injection (ESTI) attack for LLM-driven embodied agents. Without modifying the original user instruction, model parameters, or executor, ESTI reformulates an adversarial objective as false state evidence compatible with the current environment and influences planning and execution through object properties, spatial relations, affordances, task-stage rules, and execution feedback. We further develop ESTI-Bench to evaluate attack propagation across the planning-to-execution closed loop and compare ESTI with Vanilla IPI, EIRAD, and BADROBOT across ProgPrompt/VirtualHome, VoxPoser/RLBench, and AI2-THOR/iTHOR. ESTI consistently outperforms existing baselines, improving planning-level and execution-level attack success rates by up to 89.32\% and 43.69\%, respectively. Further analysis shows that grounding, consistency, and executability jointly determine whether manipulated state evidence can propagate through the embodied closed loop and produce verifiable environmental changes.

cs.RO

Security of Foundation-Model-Powered Embodied Agents: Attack Surfaces, Attacks, Defenses, and Evaluation

Foundation models are increasingly used for perception, reasoning, planning, and action generation in embodied agents, creating security risks that can propagate from digital inputs to physical behavior. Existing surveys often organize threats by mechanisms such as jailbreaks, prompt injection, backdoors, poisoning, or adversarial examples, but these categories do not consistently identify where an adversary first enters the embodied control loop. We present a trust-boundary-centric survey of foundation-model-powered embodied-agent security. Using a first-compromised-trust-boundary principle, we separate attack surface from attack mechanism and organize the system into five layers and twelve attack surfaces spanning the model supply chain, user instructions, context and memory, physical semantic environments, multimodal perception, world state, internal reasoning, task planning, action interfaces, middleware, multi-agent communication, and execution control. Based on 58 attack records and 61 defense records collected through August 15, 2026, we analyze representative attacks, cross-layer propagation, defense placement, and evaluation practices. Our quantitative analysis shows that attack research is concentrated on multimodal perception and action interfaces, while defenses are especially concentrated on action-level and runtime protection. Context and long-term memory, middleware and networking, world-state integrity, and multi-agent trust remain comparatively underexplored. We conclude with open challenges in state provenance, compositional defenses, long-horizon attack propagation, physical realizability, Byzantine multi-robot behavior, and unified closed-loop evaluation.

cs.RO

AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification

Large language model (LLM) agents increasingly rely on external tools and retrieval systems to autonomously complete complex tasks. However, this design exposes agents to indirect prompt injection (IPI), where attacker-controlled context embedded in tool outputs or retrieved content silently steers agent actions away from user intent. Unlike prompt-based attacks, IPI unfolds over multi-turn trajectories, making malicious control difficult to disentangle from legitimate task execution. Existing inference-time defenses primarily rely on heuristic detection and conservative blocking of high-risk actions, which can prematurely terminate workflows or broadly suppress tool usage under ambiguous multi-turn scenarios. We propose AgentSentry, a novel inference-time detection and mitigation framework for tool-augmented LLM agents. To the best of our knowledge, AgentSentry is the first inference-time defense to model multi-turn IPI as a temporal causal takeover. It localizes takeover points via controlled counterfactual re-executions at tool-return boundaries and enables safe continuation through causally guided context purification that removes attack-induced deviations while preserving task-relevant evidence. We evaluate AgentSentry on the \textsc{AgentDojo} benchmark across four task suites, three IPI attack families, and multiple black-box LLMs. AgentSentry eliminates successful attacks and maintains strong utility under attack, achieving an average Utility Under Attack (UA) of 74.55 %, improving UA by 20.8 to 33.6 percentage points over the strongest baselines without degrading benign performance.

cs.CR

Phase transitions and spectral singularities in a class of one-dimensional parity-time-symmetric complex potentials

We investigate a two-parametric family of one-dimensional non-Hermitian complex potentials with parity-time ($\mathcal{PT}$) symmetry. We find that there exist two distinct types of phase transitions, from an unbroken phase (characterized by a real spectrum) to a broken phase (where the spectrum becomes complex). The first type involves the emergence of a pair of complex eigenvalues bifurcating from the continuous spectrum. The second type is associated with the collision of such pairs at the bottom of the continuous spectrum. The first transition type is closely related to spectral singularities (SSs), at which point the transmission and reflection coefficients are divergent simultaneously. The second is associated with the emergence of bound states. In particular, under specific parameter conditions, we construct an exact bound state solution. By systematically exploring the parameter space, we establish a universal relationship governing the number of SSs in these potentials. These findings provide a fundamental theoretical framework for manipulating wave scattering in non-Hermitian systems, offering promising implications for designing advanced optical and quantum devices.

quant-ph

Bistability and Exact Reflectionless States in Nonlinear Scattering of a Bose--Einstein Condensate

We investigate the mean-field scattering dynamics of a quasi-one-dimensional Bose--Einstein condensate interacting with a Rosen--Morse potential. For specific potential and nonlinearity parameters, we derive analytically exact, degenerate scattering states (doubly or triply degenerate) exhibiting perfect transmission. Using the Bogoliubov--de Gennes approach, we analyze the stability of these reflectionless degenerate states, demonstrating that only one solution within each degenerate manifold is dynamically stable. Furthermore, we study a configuration with spatially localized nonlinearity, identifying an exact reflectionless state under specific conditions. Numerical analysis shows that this state marks the system's transition from monostability to bistability as the incident wave amplitude increases. Our work establishes an analytic framework for these multistable transmission phenomena, directly relevant to coherent matter-wave transport in ultracold atomic systems and optical propagation in engineered photonic lattices.

cond-mat.quant-gas