RoboTopo: Inferring Hidden Communication Topology in LLM-Controlled Multi-Robot Systems
Abstract
Communication topology carries critical security information in Large Language Model (LLM) controlled multi-robot systems. It reveals how information flows across the system and which nodes or paths may serve as effective targets for attack. Despite its security relevance, it remains largely unexplored whether ordinary task interactions can reveal hidden communication topology and enable more effective subsequent attacks. In response, we introduce RoboTopo to infer the hidden communication topology, including the number of robots and planners and their directed connections, without prior knowledge of participants or access to internal messages. It combines physical execution constraints and controlled task dependencies with probability updates and adaptive probing. We construct the RoboCoord dataset with five multi-robot system configurations to evaluate RoboTopo. Across all runs, robot and planner counts are correctly recovered, with each identified node assigned an existence probability above 0.7. Retaining edges with predicted probabilities of at least 0.5 yields an average F1 score of 0.9917, compared with 0.9519 when requiring at least 0.7. Robustness tests under node or edge removal further identify all tested structural changes, with an average F1 score of 0.9767 for edge reconstruction. Using the inferred topology, we rank capability critical nodes and paths to guide attack propagation, increasing mean unsafe action coverage from 65.9% to 98.1% across three attack settings. Finally, we introduce StageGate, which restricts public reports to selected task checkpoints and reduces the overall topology reconstruction score by 47.2% while preserving progress feedback for most requests.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.