Your robot’s safety features are already working. What happens if the input lies?
A robot can follow its safety rules and continue to act based on manipulated information. Find out what this means for robot safety and how teams can strengthen testing and trials.
A mobile robot slows down in front of someone in a hallway. A collaborative arm facilitates its movements when a worker approaches. A humanoid stops to let a person pass. Each response depends on information about the robot or its surroundings: a distance reading, a position estimate, or a stop signal.
But what happens when one of these inputs is wrong and the robot still responds exactly as expected? The mobile robot clearly reads the corridor while someone is still there. The arm estimates that the worker is further away. The humanoid does not receive a stop sign when a person crosses its path.
In any case, a fault could cause such a discrepancy. So it could be a deliberate manipulation.
At VicOne LAB R7, we examine how manipulated inputs can change the behavior of robots and what this means for systems intended to keep people safe.
How untrusted input can change a robot’s behavior
A robot does much more than measure its surroundings. It can interpret what it sees and hears to decide what to do next. Information placed in his environment can therefore influence his actions.
Published research shows how this can happen. In a study of vision-language-action (VLA) models, a patch in a camera’s view reduced task success in simulated robot tests. FreezeVLA found that an adversarial image could cause the tested models to ignore subsequent instructions. Although the studies used different methods, they both demonstrate how visual input can interfere with a robot’s intended task.
VicOne LAB R7 also tested how untrusted inputs could change the robot’s behavior. In a test with a robot dog using the Gemma 4 E4B, text on a poster was treated as an instruction and changed the robot’s movement. In a separate simulation of a hospital service robot using Nemotron on the NVIDIA Jetson AGX Orin, audio made inaudibly to humans changed the simulated behavior of the robot. The assigned tasks have not changed; inputs did.
An independent protection system can still stop a dangerous action. But that system also depends on information: readings, estimates and messages that tell it when to intervene. What happens if one of these inputs is manipulated?
During a robotics bug bounty event, researchers at VicOne LAB R7 injected a ROS 2/DDS message into a robot that organizers expected to remain stationary under safety watch. The robot moved.
A humanoid’s balance controller offers another example. If it relies on a vulnerable gyroscope, sound at the sensor’s resonant frequency could distort the reported rotation. The controller may correct a tilt that never occurred. Researchers demonstrated the underlying acoustic attack against drones with vulnerable gyroscopes. Research has not shown that the same attack chain causes a humanoid to fall.
Other protections could interrupt both chains. The question for security teams is whether such protections detect danger independently or depend on the manipulated information itself.
Figure 1. VicOne maps how accidental failures and deliberate cyber manipulation can lead to similar robot safety outcomes, from loss of control to physical damage.
Deliberate attacks test security assumptions
A safety assessment may consider a combination of accidental failures unlikely. Deliberate manipulation changes this assumption. An attacker can choose when to introduce a false input and repeat the same trigger. This doesn’t make the damage inevitable, but it could change how cyber risks should be assessed.
Even redundant sensors need adversarial testing. If an action can influence both inputs, their agreement may offer less reassurance than expected. In autonomous driving research, a handcrafted physical object fooled a system that combined camera and LiDAR perception. The study doesn’t establish a weakness in a particular robot, but it shows why teams should test whether one manipulation can affect multiple controls at once.
Cyber threats add intent to the security equation, so risk assessments based on accidental failures need to be revised to account for attacks that can be timed and repeated.
Safety tests strengthen the evidence on the safety of robots
Safety teams establish speed limits, protective distances and permitted operating areas. The evidence behind such limits should also show what happens when the information used to apply them is deliberately manipulated.
Such evidence can also support assessments against applicable requirements. China’s GB/T 45502-2025 covers information security for service robots. The IEC TS 63074 standard examines safety threats that could affect safety-related control systems. The EU Machinery Regulation, which applies from 20 January 2027, includes requirements to protect safety-relevant systems and data from corruption. Each has its own scope, and teams still need evidence of their robot’s design and operating conditions.
Figure 2. Cybersecurity strengthens robot safety evidence throughout the lifecycle. VicOne helps teams test tamper-safe limits before deployment and monitor conditions for safe behavior during operation.
Before implementation, safety and security engineers can compare normal and adversarial scenarios against the same security boundaries. During operation, they can monitor any changes to software, models, sensor signals or behavior that could challenge previous findings. Any response to suspicious behavior should follow policies approved by the security team.
VicOne supports this work throughout the robot’s entire lifecycle. Through the Robotic Hacking Community, VicOne LAB R7 collaborates with researchers to investigate how cyber threats can change the behavior of robots. VicOne’s Radeis helps teams validate potential effects before implementation, while Rthena provides visibility into risks and behavior during operation.
Five questions safety and security teams should answer together
The central test is whether a robot’s security measures continue to protect people when the information they rely on is manipulated. Safety and security teams can start by tracking the inputs behind each protective decision, challenging them, and revisiting the evidence as the robot changes. They can start with these five questions:
- What does each protective function read? Map readings, estimates, messages and confirmations. Identify which safeguards operate independently of the robot’s AI decisions.
- How does this information arrive? Control how inputs are produced, transmitted, authenticated where appropriate, and handled when missing or implausible.
- What happens if an input is manipulated? Test false distances, drift position estimates, and other relevant scenarios against the robot’s safety limits.
- Can one action mislead multiple inputs? Check whether sensor fusion or seemingly independent protections share a point of failure.
- When should evidence be reviewed? Reevaluate after changes to software, models, sensors, or operating conditions. Agree in advance with the security team on limited responses to suspicious behavior.
The goal is not just to demonstrate that a protective function works. Teams also need evidence that they remain protective when the information underlying their decision is wrong or deliberately manipulated – and that another safeguard can capture the resulting danger when necessary. As robots change, evidence must change with them.
For a more in-depth look at the cybersecurity risks and defense strategies shaping AI robotics, download our whitepaper “Securing the Rise of AI Robots: Cyber Risks, Real-World Threats, and Defense Strategies.”
Content sponsored by VicOne



Post Comment