Search papers, labs, and topics across Lattice.
This paper conducts a comprehensive survey of security risks associated with foundation-model-powered embodied agents, emphasizing the importance of understanding attack surfaces in relation to trust boundaries. By categorizing threats into five layers and twelve attack surfaces, the authors highlight how vulnerabilities can propagate from digital inputs to physical actions, revealing significant gaps in current defense strategies. Their analysis of 58 attack records and 61 defense records indicates a disproportionate focus on multimodal perception and action interfaces, while critical areas like context integrity and multi-agent trust remain underexplored.
Security vulnerabilities in embodied agents are more complex than previously understood, with critical gaps in defenses against long-term attack propagation and multi-agent interactions.
Foundation models are increasingly used for perception, reasoning, planning, and action generation in embodied agents, creating security risks that can propagate from digital inputs to physical behavior. Existing surveys often organize threats by mechanisms such as jailbreaks, prompt injection, backdoors, poisoning, or adversarial examples, but these categories do not consistently identify where an adversary first enters the embodied control loop. We present a trust-boundary-centric survey of foundation-model-powered embodied-agent security. Using a first-compromised-trust-boundary principle, we separate attack surface from attack mechanism and organize the system into five layers and twelve attack surfaces spanning the model supply chain, user instructions, context and memory, physical semantic environments, multimodal perception, world state, internal reasoning, task planning, action interfaces, middleware, multi-agent communication, and execution control. Based on 58 attack records and 61 defense records collected through August 15, 2026, we analyze representative attacks, cross-layer propagation, defense placement, and evaluation practices. Our quantitative analysis shows that attack research is concentrated on multimodal perception and action interfaces, while defenses are especially concentrated on action-level and runtime protection. Context and long-term memory, middleware and networking, world-state integrity, and multi-agent trust remain comparatively underexplored. We conclude with open challenges in state provenance, compositional defenses, long-horizon attack propagation, physical realizability, Byzantine multi-robot behavior, and unified closed-loop evaluation.