Urgent.News

What's breaking now, across thousands of outlets.

AI

Rethinking Robot Safety in the Age of AI

This article is brought to you by VicOne . Robot safety has traditionally asked: Can a machine remain safe when something goes wrong? Physical AI raises a harder question: Can a machine remain safe when an attacker changes what it sees, decides, or does even when nothing appears to have failed? As AI and robotics continue to advance at an unprecedented pace, modern robots perceive through…

Rethinking Robot Safety in the Age of AI

This article, published by VicOne, examines the evolving challenges to robot safety in the era of artificial intelligence. Modern robots rely on multimodal sensors, AI models, and physical actions to navigate dynamic environments. However, the integrity of data guiding their decisions creates risks that traditional safety assessments may not fully address.

Researchers have discovered that manipulating what a robot perceives or interprets can alter its behavior without direct control. This manipulation can occur at various points in the system, from training pipelines to runtime perception. One such example is the BadVLA attack, which targets Vision-Language-Action models, causing conditional deviations in a robot's actions when a specific trigger is present.

Another concern is the potential for ordinary objects, such as a coffee mug, to serve as reliable triggers for manipulation. A study in 2025 demonstrated a 97 percent attack success rate using such objects, without degrading performance on clean inputs.

System vulnerabilities can also provide gateways for AI control. In September 2025, UniPwn, a Bluetooth exploit chain, affected quadruped and humanoid robots from a major manufacturer. Hardcoded cryptographic keys enabled traffic decryption, authentication bypasses, and command injection, allowing root-level execution. This exploit is described as "wormable," meaning it could potentially affect an entire fleet of robots.

Middleware vulnerabilities in ROS 2 and DDS-based systems can further compromise robot safety. Abuse of unauthenticated topics has been demonstrated, allowing attackers to deliver malicious commands and override motor controls or replace AI model weights. Even if components remain functional, the trustworthiness of commands flowing through the system can be compromised.

Runtime manipulation poses another threat. Manipulating inputs that shape perception or reasoning may not require firmware modification or network breaches. Structured prompts can redirect LLM-controlled robots into unsafe trajectories, as demonstrated by RoboPAIR. BadRobot exposed a deeper architectural weakness, where robots verbally refuse dangerous commands but still execute them through their motion controllers.

Vision-based manipulation using adversarial patches within the camera's view can reduce a VLA model's task success rate to zero. FreezeVLA showed that a single adversarial image could freeze a robot's decision-making loop, making it unresponsive to subsequent instructions. Runtime assurance must not only assess whether individual components remain available but also evaluate whether cyber events are affecting physical behavior.

To address these challenges, security event correlation, behavioral-impact assessment, and policy-bounded response supported by edge AI are essential. These measures can help contain affected paths without unnecessarily stopping the entire robot fleet. As robots continue to advance and integrate into dynamic environments, ensuring their safety throughout their lifecycle becomes a critical priority.

Written by urgent.news from IEEE Spectrum's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at spectrum.ieee.org →

More in AI

More from Wednesday 16 September →