Cybersecurity key to robot safety
A report says robot safety must include cybersecurity, as hackers can manipulate a robot's perception and actions without triggering a system failure.

A new report sponsored by VicOne argues that modern robot safety assurance must account for cybersecurity threats. These threats can manipulate how a machine sees, decides, and acts, even when no component appears to have failed.
Modern robots rely on multimodal sensors and AI models to interpret their environment and act. This dependence on data integrity creates risks that conventional safety assessments may miss. Recent research shows that manipulating what a robot sees or hears can redirect its behavior without requiring direct control of its systems.
Corrupting Intelligence at the Source
Attacks can begin by corrupting the AI model during its training. A 2017 demonstration called BadNets showed a model could be made to misclassify a stop sign as a speed limit sign when a specific hidden trigger was present. This concept has evolved to affect physical actions.
At the NeurIPS 2025 conference, researchers introduced BadVLA, a backdoor attack targeting Vision-Language-Action models. This attack caused conditional deviations in a robot's action trajectory when a trigger was present. A related 2025 study, GoBA, used ordinary objects like a coffee mug as triggers, achieving a reported 97% attack success rate without degrading performance on normal inputs.
These studies reveal a blind spot. A model may pass all standard testing yet produce unsafe behavior when a hidden trigger appears in operation. The safety question becomes whether the robot remains within its task and safety boundaries under such adversarial conditions. Simulation tools like NVIDIA Isaac Sim, when paired with VicOne's Radeis, can test the effects of manipulated inputs before a robot is deployed.
System Vulnerabilities as Gateways
Even a securely trained model can be subverted if the surrounding system software is vulnerable. In September 2025, researchers disclosed UniPwn, a Bluetooth exploit chain affecting robots from a major manufacturer. The exploit used hardcoded cryptographic keys, bypassed authentication checks, and enabled command injection for root-level access. It was also described as "wormable," meaning a compromised robot could scan and potentially affect an entire fleet.
Middleware like ROS 2 creates another exposure point. Vulnerabilities here can enable arbitrary code execution or allow malicious commands to be delivered. With sufficient access, an attacker could override motor commands or replace AI model weights. In these cases, the components may function as designed, but the trustworthiness of the commands flowing through the system has changed.
Manipulating Perception at Runtime
At runtime, manipulation may require neither a firmware change nor a network breach. In 2024, a study called RoboPAIR showed how structured prompts could redirect LLM-controlled robots into unsafe paths. Another, called BadRobot, exposed an architectural weakness where a robot verbally refused a dangerous command while its motion controller executed the action anyway.
Vision-based manipulation is equally potent. VLAttack demonstrated that an adversarial patch within a camera's view could reduce a VLA model's task success rate to zero. FreezeVLA showed a single adversarial image could freeze a robot's decision-making loop. In each case, the camera and model may still run, but the robot acts on manipulated perception.
Runtime assurance must therefore look beyond component availability. It must assess whether cyber events are affecting physical behavior. Security event correlation and behavioral-impact assessment can help contain an affected system without unnecessarily stopping an entire fleet.
From Point-in-Time to Lifecycle Assurance
The report concludes that cybersecurity is the missing layer in robot safety assurance. While functional safety addresses failures and unexpected conditions, cybersecurity extends that assurance to deliberate manipulation. This requires assurance across the robot's entire lifecycle.
During design, teams must understand which cyber risks could invalidate behavioral assumptions. Before deployment, they should test if realistic attacks can cause a robot to deviate from its safety boundaries. In operation, monitoring should identify when cyber events begin to affect behavior, contain the affected path, and preserve safe operation where possible. Cybersecurity does not replace functional safety, but it helps ensure Physical AI remains within acceptable boundaries even under attack.




