AivexaNewsSearch
AI news for builders and product teamsChecked every hour

Rethinking Robot Safety in the Age of AI

Collected Oct 1, 2026

A sponsored article published by IEEE Spectrum and brought to you by VicOne argues that robot safety must add cybersecurity to conventional functional safety, because attacks can change what a robot sees, decides, or does even when the system appears to be functioning. The article describes a layered attack surface spanning training pipelines, system infrastructure, and runtime perception.

At the model layer, it cites BadNets (2017), in which a hidden trigger caused a stop sign to be misclassified as a speed limit sign without affecting other inputs. It says researchers at NeurIPS 2025 introduced BadVLA, a backdoor attack on Vision-Language-Action models that caused conditional deviations in a robot's action trajectory when a trigger was present, while largely preserving normal task performance without the trigger and remaining effective under task transfers and fine-tuning. A related 2025 study, GoBA, reported that ordinary objects such as a coffee mug could serve as a trigger, with a 97 percent attack success rate without degrading performance on clean inputs.

At the system layer, the article cites UniPwn, disclosed in September 2025 as a Bluetooth exploit chain affecting quadruped and humanoid robots from a major manufacturer. It says hardcoded cryptographic keys allowed traffic decryption, authentication checks were bypassed, and command injection enabled root-level execution, and that the exploit is described as wormable, with a compromised robot able to scan nearby units and potentially affect an entire fleet. It also cites vulnerabilities in ROS 2 and DDS-based systems that can enable arbitrary code execution or abuse unauthenticated topics, allowing an attacker with sufficient access to override motor commands or replace AI model weights.

At runtime, it cites RoboPAIR (2024), in which structured prompts redirected LLM-controlled robots into unsafe trajectories; BadRobot, where a robot verbally refused a dangerous command while its motion controller executed it; VLAttack, where an adversarial patch in the camera's view reduced a VLA model's task success rate to zero; and FreezeVLA, where a single adversarial image froze a robot's decision-making loop.

VicOne describes a lifecycle approach of AI model and vulnerability scanning, simulation-based validation using tools such as NVIDIA Isaac Sim with VicOne Radeis, and continuous monitoring.

Read at IEEE Spectrum · AI

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

This article is brought to you by VicOne . Robot safety has traditionally asked: Can a machine remain safe when something goes wrong? Physical AI raises a harder question: Can a machine remain safe when an attacker changes what it sees, decides, or does even when nothing appears to have failed? As AI and robotics continue to advance at an unprecedented pace, modern robots perceive through multimodal sensors, interpret context using AI models, and translate those interpretations into physical action. As they move in