From Prompt to Physical Actuation: Holistic Threat Modeling of LLM-Enabled Robotic Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Nagaraja, Neha, Bahsi, Hayretdin, da Cunha, Carlo R.
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909011246317568
author Nagaraja, Neha
Bahsi, Hayretdin
da Cunha, Carlo R.
author_facet Nagaraja, Neha
Bahsi, Hayretdin
da Cunha, Carlo R.
contents As large language models are integrated into autonomous robotic systems for task planning and control, compromised inputs or unsafe model outputs can propagate through the planning pipeline to physical-world consequences. Although prior work has studied robotic cybersecurity, adversarial perception attacks, and LLM safety independently, no existing study traces how these threat categories interact and propagate across trust boundaries in a unified architectural model. We address this gap by modeling an LLM-enabled autonomous robot in an edge-cloud architecture as a hierarchical Data Flow Diagram and applying STRIDE-per-interaction analysis across six boundary-crossing interaction points using a three-category taxonomy of Conventional Cyber Threats, Adversarial Threats, and Conversational Threats. The analysis reveals that these categories converge at the same boundary crossings, and we trace three cross-boundary attack chains from external entry points to unsafe physical actuation, each exposing a distinct architectural property: the absence of independent semantic validation between user input and actuator dispatch, cross-modal translation from visual perception to language-model instruction, and unmediated boundary crossing through provider-side tool use. To our knowledge, this is the first DFD-based threat analysis integrating all three threat categories across the full perception-planning-actuation pipeline of an LLM-enabled robotic system.
format Preprint
id arxiv_https___arxiv_org_abs_2604_27267
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle From Prompt to Physical Actuation: Holistic Threat Modeling of LLM-Enabled Robotic Systems
Nagaraja, Neha
Bahsi, Hayretdin
da Cunha, Carlo R.
Cryptography and Security
Artificial Intelligence
Robotics
As large language models are integrated into autonomous robotic systems for task planning and control, compromised inputs or unsafe model outputs can propagate through the planning pipeline to physical-world consequences. Although prior work has studied robotic cybersecurity, adversarial perception attacks, and LLM safety independently, no existing study traces how these threat categories interact and propagate across trust boundaries in a unified architectural model. We address this gap by modeling an LLM-enabled autonomous robot in an edge-cloud architecture as a hierarchical Data Flow Diagram and applying STRIDE-per-interaction analysis across six boundary-crossing interaction points using a three-category taxonomy of Conventional Cyber Threats, Adversarial Threats, and Conversational Threats. The analysis reveals that these categories converge at the same boundary crossings, and we trace three cross-boundary attack chains from external entry points to unsafe physical actuation, each exposing a distinct architectural property: the absence of independent semantic validation between user input and actuator dispatch, cross-modal translation from visual perception to language-model instruction, and unmediated boundary crossing through provider-side tool use. To our knowledge, this is the first DFD-based threat analysis integrating all three threat categories across the full perception-planning-actuation pipeline of an LLM-enabled robotic system.
title From Prompt to Physical Actuation: Holistic Threat Modeling of LLM-Enabled Robotic Systems
topic Cryptography and Security
Artificial Intelligence
Robotics
url https://arxiv.org/abs/2604.27267