Embodied Artificial Intelligence (AI) connects digital intelligence with physical action, so local faults, cyberattacks, or unsafe decisions can cause real-world harm.
This review presents a four-layer framework spanning physical interaction, system and middleware, algorithm and decision, and cloud-edge and data.
It reveals how risks propagate across layers and unifies functional, physical, and behavioral safety with defenses and closed-loop benchmarks.
| [1] | Duan J., Yu S., Tan H. L., et al. (2022). A survey of embodied AI: From simulators to research tasks. IEEE Trans. Emerg. Top. Comput. Intell. 6:230−244. DOI:10.1109/tetci.2022.3141105 |
| [2] | Liu Y., Chen W., Bai Y., et al. (2025). Aligning cyber space with physical world: A comprehensive survey on embodied AI. IEEE/ASME Trans. Mechatron. 30:7253−7274. DOI:10.1109/TMECH.2025.3574943 |
| [3] | Xing W., Li M., Li M., et al. (2026). Towards robust and secure embodied AI: A survey on vulnerabilities and attacks. ACM Comput. Surv. 58:312. DOI:10.1145/3806048 |
| [4] | Humayed A., Lin J., Li F., et al. (2017). Cyber-physical systems security—A survey. IEEE Internet Things J. 4:1802−1831. DOI:10.1109/jiot.2017.2703172 |
| [5] | Yaacoub J. P. A., Noura H. N., Salman O., et al. (2022). Robotics cyber security: vulnerabilities, attacks, countermeasures, and recommendations. Int. J. Inf. Secur. 21:115−158. DOI:10.1007/s10207-021-00545-8 |
| [6] | Ouyang L., Wu J., Jiang X., et al. (2022). Training language models to follow instructions with human feedback. Adv. Neural Inf. Process. Syst. 35:27730−27744. DOI:10.52202/068431-2011 |
| [7] | Rafailov R., Sharma A., Mitchell E., et al. (2023). Direct preference optimization: Your language model is secretly a reward model. Adv. Neural Inf. Process. Syst. 36:53728−53741. DOI:10.52202/075280-2338 |
| [8] | Robey A., Ravichandran Z., Kumar V., et al. (2025). Jailbreaking LLM-controlled robots. 2025 IEEE international conference on robotics and automation (ICRA) (IEEE): 11948–11956. DOI: 10.1109/ICRA55743.2025.11128119 |
| [9] | Ying Z., Wang L., Xiao Y., et al. (2026). Agentsafe: Benchmarking the safety of embodied agents on hazardous instructions. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition 37664−37673. |
| [10] | Yin S., Pang X., Ding Y., et al. (2024). SafeAgentBench: A benchmark for safe task planning of embodied LLM agents. arXiv. DOI: 10.48550/arXiv.2412.13178 |
| [11] | Xu Y., Han X., Deng G., et al. (2023). SoK: Rethinking sensor spoofing attacks against robotic vehicles from a systematic view. 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) 1082−1100. DOI:10.1109/eurosp57164.2023.00067 |
| [12] | Cao Y., Xiao C., Cyr B., et al. (2019). Adversarial Sensor Attack on LiDAR-based Perception in Autonomous Driving. Proceedings of the 2019 ACM SIGSAC conference on computer and communications security (CCS) 2267−2281. DOI:10.1145/3319535.3339815 |
| [13] | Botta A., Rotbei S., Zinno S., et al. (2023). Cyber security of robots: A comprehensive survey. Intell. Syst. Appl. 18:200237. DOI:10.1016/j.iswa.2023.200237 |
| [14] | Cárdenas A. A., Amin S. and Sastry S. (2008). Research challenges for the security of control systems. 3rd USENIX Workshop on Hot Topics in Security (HotSec 08) (USENIX Association). Available at: https://www.usenix.org/conference/hotsec-08/research-challenges-security-control-systems |
| [15] | Stellios I., Kotzanikolaou P. and Grigoriadis C. (2021). Assessing IoT enabled cyber-physical attack paths against critical systems. Comput. Secur. 107:102316. DOI:10.1016/j.cose.2021.102316 |
| [16] | Liu T., Tian J., Wang J., et al. (2019). Integrated security threats and defense of cyber-physical systems. Acta Autom. Sin. 45:5−24. |
| [17] | Kim J., Chen W., Soleymanzadeh D., et al. (2026). Modular safety guardrails are necessary for foundation-model-enabled robots in the real world. arXiv. DOI: 10.48550/arXiv.2602.04056 |
| [18] | Lasota P. A., Fong T. and Shah J. A. (2017). A survey of methods for safe human-robot interaction. Found. Trends Robot. 5:261−349. DOI:10.1561/2300000052 |
| [19] | Desai A., Ghosh S., Seshia S. A., et al. (2019). SOTER: A runtime assurance frame- work for programming safe robotics systems. 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks: 138–150. DOI: 10.1109/dsn.2019.00027 |
| [20] | Albus J. S., Huang H. M., Messina E., et al. (2002). 4D/RCS version 2.0: A reference model architecture for unmanned vehicle systems. (National Institute of Standards and Technology). |
| [21] | Ahmad A. and Babar M. A. (2016). Software architectures for robotic systems: A systematic mapping study. J. Syst. Softw. 122:16−39. DOI:10.1016/j.jss.2016.08.039 |
| [22] | Elkady A. and Sobh T. (2012). Robotics middleware: A comprehensive literature survey and attribute-based bibliography. J. Robot. 2012:959013. DOI:10.1155/2012/959013 |
| [23] | Kehoe B., Patil S., Abbeel P., et al. (2015). A survey of research on cloud robotics and automation. IEEE Trans. Autom. Sci. Eng. 12:398−409. DOI:10.1109/tase.2014.2376492 |
| [24] | Hu G., Tay W. P. and Wen Y. (2012). Cloud robotics: Architecture, challenges and applications. IEEE Network 26:21−28. DOI:10.1109/mnet.2012.6201212 |
| [25] | De Santis A., Siciliano B., De Luca A., et al. (2008). An atlas of physical human–robot interaction. Mech. Mach. Theory 43:253−270. DOI:10.1016/j.mechmachtheory.2007.03.003 |
| [26] | Quigley M., Gerkey B. P., Conley K., et al. (2009). ROS: An open-source robot operating system. Open-source software workshop of the international conference on robotics and automation (ICRA). |
| [27] | Dieber B., Breiling B., Taurer S., et al. (2017). Security for the robot operating system. Robot. Auton. Syst. 98:192−203. DOI:10.1016/j.robot.2017.09.017 |
| [28] | Ahn M., Brohan A., Brown N., et al. (2023). Do as I can, not as I say: Grounding language in robotic affordances. Proceedings of the 6th Conference on Robot Learning (CoRL) 287−318. |
| [29] | Driess D., Xia F., Sajjadi M. S. M., et al. (2023). PaLM-E: An embodied multimodal language model. Proceedings of the 40th International Conference on Machine Learning (PMLR), Proceedings of Machine Learning Research 202: 8469–8488. Available at: https://proceedings.mlr.press/v202/driess23a.html |
| [30] | Brohan A., Brown N., Carbajal J., et al. (2023). RT-2: Vision-language-action models transfer web knowledge to robotic control. Proceedings of the 7th Conference on Robot Learning (CoRL): 2165–2183. |
| [31] | Kim M. J., Pertsch K., Karamcheti S., et al. (2025). OpenVLA: An open-source vision-language-action model. Proceedings of the 8th Conference on Robot Learning (CoRL) (PMLR), Proceedings of Machine Learning Research 270: 2679–2713. |
| [32] | Black K., Brown N., Driess D., et al. (2024). π0: A vision-language-action flow model for general robot control. arXiv. DOI: 10.48550/arXiv.2410.24164 |
| [33] | NVIDIA, Bjorck J., Castañeda F., et al. (2025). GR00T N1: An open foundation model for generalist humanoid robots. arXiv. DOI: 10.48550/arXiv.2503.14734 |
| [34] | Open X-Embodiment Collaboration, O’Neill A., Rehman A., et al. (2024). Open X-Embodiment: Robotic learning datasets and RT-X models. 2024 IEEE international conference on robotics and automation (ICRA): 6892–6903. |
| [35] | Kim K., Kim J. S., Jeong S., et al. (2021). Cybersecurity for autonomous vehicles: Review of attacks and defense. Comput. Secur. 103:102150. DOI:10.1016/j.cose.2020.102150 |
| [36] | Sun X., Yu F. R. and Zhang P. (2022). A survey on cyber-security of connected and autonomous vehicles (CAVs). IEEE Trans. Intell. Transp. Syst. 23:6240−6259. DOI:10.1109/tits.2021.3085297 |
| [37] | Giraldo J., Urbina D., Cardenas A., et al. (2018). A survey of physics-based attack detection in cyber-physical systems. ACM Comput. Surv. 51:1−36. DOI:10.1145/3203245 |
| [38] | International Organization for Standardization (2024). ISO/IEC TR 5469: 2024 — Artificial intelligence — Functional safety and AI systems. (International Organization for Standardization). Available at: https://www.iso.org/standard/81283.html |
| [39] | Ames A. D., Xu X., Grizzle J. W., et al. (2017). Control barrier function based quadratic programs for safety critical systems. IEEE Trans. Autom. Control 62:3861−3876. DOI:10.1109/tac.2016.2638961 |
| [40] | Alshiekh M., Bloem R., Ehlers R., et al. (2018). Safe reinforcement learning via shielding. Proceedings of the 32nd AAAI Conference on Artificial Intelligence (AAAI) 32:2669−2678. DOI:10.1609/aaai.v32i1.11797 |
| [41] | Anjomshoae S., Najjar A., Calvaresi D., et al. (2019). Explainable agents and robots: Results from a systematic literature review. Proceedings of the 18th International Conference on Autonomous Agents and MultiAgent Systems (AAMAS) 1078−1088. DOI:10.65109/kczb5817 |
| [42] | Sakai T. and Nagai T. (2022). Explainable autonomous robots: A survey and perspective. Adv. Robot. 36:219−238. DOI:10.1080/01691864.2022.2029720 |
| [43] | Visinsky M. L., Cavallaro J. R. and Walker I. D. (1994). Robotic fault detection and fault tolerance: A survey. Reliab. Eng. Syst. Saf. 46:139−158. DOI:10.1016/0951-8320(94)90132-5 |
| [44] | Leucker M. and Schallhart C. (2009). A brief account of runtime verification. J. Log. Algebr. Program. 78:293−303. DOI:10.1016/j.jlap.2008.08.004 |
| [45] | Amodei D., Olah C., Steinhardt J., et al. (2016). Concrete problems in AI safety. arXiv. DOI: 10.48550/arXiv.1606.06565 |
| [46] | Ji J., Qiu T., Chen B., et al. (2023). AI alignment: A comprehensive survey. arXiv. DOI: 10.48550/arXiv.2310.19852 |
| [47] | International Electrotechnical Commission (2010). IEC 61508: Functional safety of electrical/electronic/programmable electronic safety-related systems, Edition 2.0. (International Electrotechnical Commission). Available at: https://webstore.iec.ch/en/publication/22273 |
| [48] | International Organization for Standardization (2011). ISO 10218-1: 2011 and ISO 10218-2: 2011 — Robots and robotic devices — Safety requirements for industrial robots. (International Organization for Standardization). |
| [49] | Leveson N. G. (2012). Engineering a safer world: Systems thinking applied to safety. (MIT Press). |
| [50] | International Organization for Standardization (2016). ISO/TS 15066: 2016 — Robots and robotic devices — Collaborative robots. (International Organization for Standardization). Available at: https://www.iso.org/standard/62996.html |
| [51] | Haddadin S., Albu-Schäffer A. and Hirzinger G. (2009). Requirements for safe robots: Measurements, analysis and new insights. Int. J. Robot. Res. 28:1507−1527. DOI:10.1177/0278364909343970 |
| [52] | Villani V., Pini F., Leali F., et al. (2018). Survey on human–robot collaboration in industrial settings: Safety, intuitive interfaces and applications. Mechatronics 55:248−266. DOI:10.1016/j.mechatronics.2018.02.009 |
| [53] | Underwriters Laboratories (2023). UL 4600: Standard for safety for the evaluation of autonomous products, edition 3. (Underwriters Laboratories). Available at: https://www.ul.com/news/ul-4600-edition-3-updates-incorporate-autonomous-trucking |
| [54] | Zhang H., Zhu C., Wang X., et al. (2025). BadRobot: Jailbreaking embodied LLM agents in the physical world. The thirteenth international conference on learning representations (ICLR). |
| [55] | Ruan Y., Dong H., Wang A., et al. (2024). Identifying the risks of LM agents with an LM-emulated sandbox. Proceedings of the 12th International Conference on Learning Representations (ICLR). |
| [56] | Li H., Wei M., Huang J., et al. (2019). Survey on cyber-physical system technologies. Acta Autom. Sin. 45: 37–50. |
| [57] | Buldyrev S. V., Parshani R., Paul G., et al. (2010). Catastrophic cascade of failures in interdependent networks. Nature 464:1025−1028. DOI:10.1038/nature08932 |
| [58] | Shin H., Kim D., Kwon Y., et al. (2017). Illusion and Dazzle: Adversarial Optical Channel Exploits against LiDARs for Automotive Applications. Cryptographic hardware and embedded systems (CHES) 445−467. DOI:10.1007/978-3-319-66787-4_22 |
| [59] | Son Y., Shin H., Kim D., et al. (2015). Rocking drones with intentional sound noise on gyroscopic sensors. Proceedings of the 24th USENIX Security Symposium 881−896. |
| [60] | Quarta D., Pogliani M., Polino M., et al. (2017). An experimental security analysis of an industrial robot controller. 2017 IEEE symposium on security and privacy (s&p) 268−286. DOI:10.1109/sp.2017.20 |
| [61] | Schneier B. (1999). Attack trees: Modeling security threats. Dr. Dobb’s J. 24:21−29. |
| [62] | Shostack A. (2014). Threat modeling: Designing for security. (Wiley). |
| [63] | UcedaVelez T. and Morana M. M. (2015). Risk centric threat modeling: Process for attack simulation and threat analysis. (Wiley). |
| [64] | International Organization for Standardization and Society of Automotive Engineers (2021). ISO/SAE 21434: 2021 — road vehicles — cybersecurity engineering. (International Organization for Standardization and SAE International). Available at: https://www.iso.org/standard/70918.html |
| [65] | National Institute of Standards and Technology (2024). The NIST Cybersecurity Framework (CSF) 2.0. (National Institute of Standards and Technology). Available at: https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20 |
| [66] | Tabassi E. (2023). Artificial intelligence risk management framework (AI RMF 1.0). (National Institute of Standards and Technology). DOI: 10.6028/NIST.AI.100-1 |
| [67] | El-Rewini Z., Sadatsharan K., Selvaraj D. F., et al. (2020). Cybersecurity challenges in vehicular communications. Veh. Commun. 23:100214. DOI:10.1016/j.vehcom.2019.100214 |
| [68] | Haskard A. and Herath D. (2025). Secure robotics: Navigating challenges at the nexus of safety, trust, and cybersecurity in cyber-physical systems. ACM Comput. Surv. 57:1−48. DOI:10.1145/3723050 |
| [69] | Zacharaki A., Kostavelis I., Gasteratos A., et al. (2020). Safety bounds in human–robot interaction: A survey. Saf. Sci. 127:104667. DOI:10.1016/j.ssci.2020.104667 |
| [70] | Dibaji S. M., Pirani M., Flamholz D. B., et al. (2019). A systems and control perspective of CPS security. Annu. Rev. Control 47:394−411. DOI:10.1016/j.arcontrol.2019.04.011 |
| [71] | Petit J. and Shladover S. E. (2015). Potential cyberattacks on automated vehicles. IEEE Trans. Intell. Transp. Syst. 16:546−556. DOI:10.1109/tits.2014.2342271 |
| [72] | Guesmi A., Hanif M. A., Ouni B., et al. (2024). Physical adversarial attacks for camera-based smart systems: Current trends, categorization, applications, research challenges, and future outlook. IEEE Access 12:14150−14174. DOI:10.1109/access.2023.3321118 |
| [73] | Girdhar M., Hong J. and Moore J. (2023). Cybersecurity of autonomous vehicles: A systematic literature review of adversarial attacks and defense models. IEEE Open J. Veh. Technol. 4:417−437. DOI:10.1109/ojvt.2023.3265363 |
| [74] | Deng Z., Guo Y., Han C., et al. (2025). AI agents under threat: A survey of key security challenges and future pathways. ACM Comput. Surv. 57:182. DOI:10.1145/3716628 |
| [75] | He F., Zhu T., Ye D., et al. (2025). The emerged security and privacy of LLM agent: A survey with case studies. ACM Comput. Surv. 58:1−36. DOI:10.1145/3773080 |
| [76] | Liu Y., Yao Y., Ton J. F., et al. (2023). Trustworthy LLMs: A survey and guideline for evaluating large language models’ alignment. NeurIPS 2023 workshop on socially responsible language modelling research (SoLaR). |
| [77] | Neupane S., Mitra S., Fernandez I. A., et al. (2024). Security considerations in AI-robotics: A survey of current methods, challenges, and opportunities. IEEE Access 12:22072−22097. DOI:10.1109/access.2024.3363657 |
| [78] | Wang Z., Hu J. and Mu R. (2025). Safety of embodied navigation: A survey. Proceedings of the 34th International Joint Conference on Artificial Intelligence (IJCAI) — Survey Track 10714−10722. DOI:10.24963/ijcai.2025/1189 |
| [79] | Xu W., Ji X., Yan C., et al. (2025). Embodied artificial intelligence security and governance. Bull. Chin. Acad. Sci. 40:429−439. DOI:10.16418/j.issn.1000-3045.20250218002 |
| [80] | Lu X., Huang Z., Li X., et al. (2024). POEX: Towards policy executable jailbreak attacks against the LLM-based robots. arXiv. DOI: 10.48550/arXiv.2412.16633 |
| [81] | Tang L., Wang R., Liu Z., et al. (2024). Scenario-based accelerated testing for SOTIF in autonomous driving: a review. IEEE Internet Things J. 12:1453−1470. DOI:10.1109/jiot.2024.3490598 |
| [82] | Zhang X., Dong H., Zhang H., et al. (2025). A real-time, robust and versatile visual-SLAM framework based on deep learning networks. IEEE Trans. Instrum. Meas. 74:1−13. DOI:10.1109/tim.2025.3527618 |
| [83] | Chakraborty A., Alam M., Dey V., et al. (2021). A survey on adversarial attacks and defences. CAAI Trans. Intell. Technol. 6:25−45. DOI:10.1049/cit2.12028 |
| [84] | Liu J., Levine A., Lau C. P., et al. (2022). Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition 14973−14982. DOI:10.1109/cvpr52688.2022.01455 |
| [85] | Nassi B., Mirsky Y., Nassi D., et al. (2020). Phantom of the ADAS: Securing advanced driver-assistance systems from split-second phantom attacks. ACM conference on computer and communications security (CCS) 293−308. DOI:10.1145/3372297.3423359 |
| [86] | Li Y., Yang F., Liu Q., et al. (2023). Light can be dangerous: Stealthy and effective physical-world adversarial attack by spot light. Comput. Secur. 132:103345. DOI:10.1016/j.cose.2023.103345 |
| [87] | Cheng Y., Ji X., Zhu W., et al. (2023). Adversarial computer vision via acoustic manipulation of camera sensors. IEEE Trans. Dependable Secure Comput. 21:3734−3750. DOI:10.1109/tdsc.2023.3334618 |
| [88] | Duan R., Mao X., Qin A. K., et al. (2021). Adversarial laser beam: Effective physical-world attack to DNNs in a blink. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition (CVPR) 16057−16066. DOI:10.1109/cvpr46437.2021.01580 |
| [89] | Yan C., Xu Z., Yin Z., et al. (2022). Rolling colors: Adversarial laser exploits against traffic light recognition. arXiv. DOI: 10.48550/arXiv.2204.02675 |
| [90] | Cheng Z., Liang J., Choi H., et al. (2022). Physical attack on monocular depth estimation with optimal adversarial patches. Computer vision – ECCV 2022 (Springer), Lecture Notes in Computer Science 13698: 514–532. DOI: 10.1007/978-3-031-19839-7_30 |
| [91] | Jing P., Tang Q., Du Y., et al. (2021). Too good to be safe: Tricking lane detection in autonomous driving with crafted perturbations. 30th USENIX Security Symposium (USENIX Security 21) 3237−3254. |
| [92] | Jia Y., Lu Y., Shen J., et al. (2020). Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object Tracking. International conference on learning representations (ICLR). |
| [93] | Davidson D., Wu H., Jellinek R., et al. (2016). Controlling UAVs with sensor input spoofing attacks. Workshop on offensive technologies (WOOT). |
| [94] | Burrus N., Abderrahim M., Garcia J., et al. (2011). Object Reconstruction and Recognition leveraging an RGB-D camera. Proceedings of the 12th IAPR Conference on Machine Vision Applications: 3–6. |
| [95] | Li Y. and Ibanez-Guzman J. (2020). LiDAR for autonomous driving: The principles, challenges, and trends for automotive LiDAR and perception systems. IEEE Signal Process. Mag. 37:50−61. DOI:10.1109/msp.2020.2973615 |
| [96] | Kim B. K. and Sumi Y. (2020). Vision-based safety-related sensors in low visibility by fog. Sensors 20(10): 2812. DOI: 10.3390/s20102812 |
| [97] | Petit J., Stottelaar B., Feiri M., et al. (2015). Remote attacks on automated vehicles sensors: Experiments on camera and LiDAR. Black hat europe. |
| [98] | Jin Z., Ji X., Cheng Y., et al. (2023). PLA-LiDAR: Physical laser attacks against LiDAR-based 3D object detection in autonomous vehicle. IEEE symposium on security and privacy (s&p) 1822−1839. DOI:10.1109/sp46215.2023.10179458 |
| [99] | Ahmad N., Ghazilla R. A. R., Khairi N. M., et al. (2013). Reviews on various inertial measurement unit (IMU) sensor applications. IJSPS 1:256−262. DOI:10.12720/ijsps.1.2.256-262 |
| [100] | Burnett K., Schoellig A. P. and Barfoot T. D. (2025). IMU as an input versus a measurement of the state in inertial-aided state estimation. Robotica 43:1−21. DOI:10.1017/s0263574724002121 |
| [101] | Wu Y., Kuang J., Niu X., et al. (2025). Wheel-GINS: A GNSS/INS integrated navigation system with a wheel-mounted IMU. IEEE Trans. Intell. Transp. Syst. 26:6891−6903. DOI:10.1109/tits.2025.3527815 |
| [102] | Gao M., Zhang L., Shen L., et al. (2023). Exploring practical acoustic transduction attacks on inertial sensors in MDOF systems. IEEE Trans. Mob. Comput. 23:3539−3557. DOI:10.1109/tmc.2023.3277287 |
| [103] | Wang Z., Wang K., Yang B., et al. (2017). Sonic gun to smart devices. Black hat USA. |
| [104] | Ji X., Cheng Y., Zhang Y., et al. (2021). Poltergeist: Acoustic adversarial machine learning against cameras and computer vision. IEEE symposium on security and privacy (s&p) 160−175. DOI:10.1109/sp40001.2021.00091 |
| [105] | Dey V., Pudi V., Chattopadhyay A., et al. (2018). Security vulnerabilities of unmanned aerial vehicles and countermeasures: An experimental study. International conference on VLSI design 398−403. DOI:10.1109/vlsid.2018.97 |
| [106] | John A. Volpe National Transportation Systems Center (2001). Vulnerability assessment of the transportation infrastructure relying on the Global Positioning System. (U.S. Department of Transportation, Office of the Assistant Secretary for Transportation Policy). Available at: https://rosap.ntl.bts.gov/view/dot/8435 |
| [107] | Tippenhauer N. O., Pöpper C., Rasmussen K. B., et al. (2011). On the requirements for successful GPS spoofing attacks. Proceedings of the 18th ACM Conference on Computer and Communications Security 75−86. DOI:10.1145/2046707.2046719 |
| [108] | Zeng K., Liu S., Shu Y., et al. (2018). All your GPS are belong to us: Towards stealthy manipulation of road navigation systems. 27th USENIX Security Symposium (USENIX Security 18): 1527–1544. |
| [109] | Nighswander T., Ledvina B. M., Diamond J., et al. (2012). GPS software attacks. ACM conference on computer and communications security (CCS) 450−461. DOI:10.1145/2382196.2382245 |
| [110] | Shen J., Won J. Y., Chen Z., et al. (2020). Drift with devil: Security of Multi-Sensor fusion based localization in High-Level autonomous driving under GPS spoofing. 29th USENIX Security Symposium (USENIX Security 20) (USENIX Association): 931–948. |
| [111] | Li Y., Wen C., Juefei-Xu F., et al. (2021). Fooling LiDAR perception via adversarial trajectory perturbation. IEEE international conference on computer vision 7898−7907. DOI:10.1109/iccv48922.2021.00780 |
| [112] | Tang K., Shen J. and Chen Q. A. (2021). Fooling perception via location: A case of region-of-interest attacks on traffic light detection in autonomous driving. NDSS workshop on automotive and autonomous vehicle security (AutoSec). DOI: 10.14722/autosec.2021.23029 |
| [113] | Dahiya R. S., Metta G., Valle M., et al. (2009). Tactile sensing—from humans to humanoids. IEEE Trans. Robot. 26(1): 1–20. DOI: 10.1109/tro.2009.2033627 |
| [114] | Jiang J. and Luo S. (2022). Robotic perception of object properties using tactile sensing. Tactile sensing, skill learning, and robotic dexterous manipulation (Elsevier), pp. 23–44. DOI: 10.1016/b978-0-32-390445-2.00009-x |
| [115] | Mittendorfer P. and Cheng G. (2011). Humanoid multimodal tactile-sensing modules. IEEE Trans. Robot. 27(3): 401–410. DOI: 10.1109/tro.2011.2106330 |
| [116] | Tu Y., Rampazzi S. and Hei X. (2022). Towards adversarial control loops in sensor attacks: a case study to control the kinematics and actuation of embedded systems. arXiv. DOI: 10.48550/arXiv.2203.07670 |
| [117] | Shi J., Dai Y., Cheng Y., et al. (2023). Embedment of sensing elements for robust, highly sensitive, and cross-talk–free iontronic skins for robotics applications. Sci. Adv. 9:eadf8831. DOI:10.1126/sciadv.adf8831 |
| [118] | Regenscheid A. (2018). Platform firmware resiliency guidelines. (National Institute of Standards and Technology (NIST)). DOI: 10.6028/nist.sp.800-193 |
| [119] | Gandolfi K., Mourtel C. and Olivier F. (2001). Electromagnetic analysis: Concrete results. Cryptographic hardware and embedded systems—CHES 2001: Third international workshop paris, france, may 14–16, 2001 proceedings 3: 251–261. DOI: 10.1007/3-540-44709-1_21 |
| [120] | Kocher P., Jaffe J. and Jun B. (1999). Differential power analysis. Annual international cryptology conference (CRYPTO’99) 388−397. DOI:10.1007/3-540-48405-1_25 |
| [121] | Mangard S., Oswald E. and Popp T. (2008). Power analysis attacks: Revealing the secrets of smart cards. (Springer). |
| [122] | Khuat V., Danger J. L. and Dutertre J. M. (2021). Laser fault injection in a 32-bit micro-controller: from the flash interface to the execution pipeline. 2021 Workshop on fault detection and tolerance in cryptography (FDTC): 74–85. DOI: 10.1109/fdtc53659.2021.00020 |
| [123] | Bhunia S., Hsiao M. S., Banga M., et al. (2014). Hardware Trojan attacks: Threat analysis and countermeasures. Proc. IEEE 102:1229−1247. DOI:10.1109/jproc.2014.2334493 |
| [124] | Tehranipoor M. and Koushanfar F. (2010). A survey of hardware trojan taxonomy and detection. IEEE Des. Test. Comput. 27:10−25. DOI:10.1109/mdt.2010.7 |
| [125] | Xiao K., Forte D., Jin Y., et al. (2016). Hardware trojans: Lessons learned after one decade of research. ACM Trans. Des. Autom. Electron. Syst. 22:1−23. |
| [126] | Barenghi A., Breveglieri L., Koren I., et al. (2012). Fault injection attacks on crypto-graphic devices: Theory, practice, and countermeasures. Proc. IEEE 100:3056−3076. DOI:10.1109/jproc.2012.2188769 |
| [127] | Qiu P., Wang D., Lyu Y., et al. (2019). Voltjockey: Breaching TrustZone by software-controlled voltage manipulation over multi-core frequencies. ACM SIGSAC conference on computer and communications security (CCS): 195–209. |
| [128] | Moro N., Dehbaoui A., Heydemann K., et al. (2013). Electromagnetic fault injection: towards a fault model on a 32-bit microcontroller. 2013 Workshop on fault diagnosis and tolerance in cryptography: 77–88. DOI: 10.1109/fdtc.2013.9 |
| [129] | Maggi F., Quarta D., Pogliani M., et al. (2017). Rogue robots: Testing the limits of an industrial robot’s security. (Trend Micro and Politecnico di Milano). Available at: https://documents.trendmicro.com/assets/wp/wp-industrial-robot-security.pdf |
| [130] | Kasprzyczak L., Manowska A. and Dźwiarek M. (2025). Cybersecurity requirements for industrial machine control systems. Appl. Sci. 15:1267. DOI:10.3390/app15031267 |
| [131] | Jiménez Naharro R., Gómez-Bravo F. and López de Ahumada Gutiérrez R. (2025). Exploring hardware vulnerabilities in robotic actuators: A case of man-in-the-middle attacks. Electronics 14:4909. DOI:10.3390/electronics14244909 |
| [132] | Sabt M., Achemlal M. and Bouabdallah A. (2015). Trusted execution environment: What it is, and what it is not. 2015 IEEE trustcom/BigDataSE/ispa 1:57−64. DOI:10.1109/trustcom.2015.357 |
| [133] | Arbaugh W. A., Farber D. J. and Smith J. M. (1997). A secure and reliable bootstrap architecture. Proceedings. 1997 IEEE symposium on security and privacy (cat. no. 97CB36097) 65−71. DOI:10.1109/secpri.1997.601317 |
| [134] | Suh G. E. and Devadas S. (2007). Physical unclonable functions for device authentication and secret key generation. Proceedings of the 44th annual design automation conference 9−14. DOI:10.1145/1278480.1278484 |
| [135] | Haldar V., Chandra D. and Franz M. (2004). Semantic remote attestation: A virtual machine directed approach to trusted computing. USENIX virtual machine research and technology symposium 2004. |
| [136] | Ivanov R., Pajic M. and Lee I. (2016). Attack-resilient sensor fusion for safety-critical cyber-physical systems. ACM Trans. Embed. Comput. Syst. 15:1−24. DOI:10.1145/2847418 |
| [137] | Clark S. S., Ransford B., Rahmati A., et al. (2013). WattsUpDoc: Power side channels to nonintrusively discover untargeted malware on embedded medical devices. 2013 USENIX workshop on health information technologies (HealthTech 13). |
| [138] | Bao C., Forte D. and Srivastava A. (2015). Temperature tracking: Toward robust run-time detection of hardware Trojans. IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst. 34:1577−1585. DOI:10.1109/tcad.2015.2424929 |
| [139] | Pan M. C., Van Brussel H. and Sas P. (1998). Intelligent joint fault diagnosis of industrial robots. Mech. Syst. Signal Process. 12:571−588. DOI:10.1006/mssp.1997.0124 |
| [140] | Guin U., Huang K., DiMase D., et al. (2014). Counterfeit integrated circuits: A rising threat in the global semiconductor supply chain. Proc. IEEE 102:1207−1228. DOI:10.1109/jproc.2014.2332291 |
| [141] | Sun J., Cao Y., Chen Q. A., et al. (2020). Towards robust LiDAR-based perception in autonomous driving: General black-box adversarial sensor attack and countermeasures. 29th USENIX Security Symposium: 877–894. |
| [142] | Szegedy C., Zaremba W., Sutskever I., et al. (2014). Intriguing properties of neural networks. International conference on learning representations (ICLR) 1−10. |
| [143] | Goodfellow I. J., Shlens J. and Szegedy C. (2015). Explaining and harnessing adversarial examples. International conference on learning representations (ICLR) 1−11. |
| [144] | Brown T. B., Mané D., Roy A., et al. (2017). Adversarial patch. arXiv. DOI: 10.48550/arXiv.1712.09665 |
| [145] | Eykholt K., Evtimov I., Fernandes E., et al. (2018). Robust physical-world attacks on deep learning visual classification. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition 1625−1634. DOI:10.1109/cvpr.2018.00175 |
| [146] | Eykholt K., Evtimov I., Fernandes E., et al. (2018). Physical adversarial examples for object detectors. 12th USENIX Workshop on Offensive Technologies. |
| [147] | Mehmood U., Sheikhi S., Bak S., et al. (2022). The black-box simplex architecture for runtime assurance of autonomous CPS. NASA formal methods 231−250. DOI:10.1007/978-3-031-06773-0_12 |
| [148] | García J. and Fernández F. (2015). A comprehensive survey on safe reinforcement learning. J. Mach. Learn. Res. 16:1437−1480. |
| [149] | Achiam J., Held D., Tamar A., et al. (2017). Constrained policy optimization. Proceedings of the 34th International Conference on Machine Learning: 22–31. |
| [150] | Dalal G., Dvijotham K., Vecerik M., et al. (2018). Safe exploration in continuous action spaces. arXiv. DOI: 10.48550/arXiv.1801.08757 |
| [151] | Ames A. D., Coogan S., Egerstedt M., et al. (2019). Control barrier functions: Theory and applications. 2019 18th European Control Conference 3420−3431. DOI:10.23919/ecc.2019.8796030 |
| [152] | Moulard T., Hortala J., Perez X., et al. (2019). ROS 2 Robotic Systems Threat Model. Available at: https://design.ros2.org/articles/ros2_threat_model.html |
| [153] | Open Robotics (2020). ROS 2 security enclaves. (Open Robotics). Available at: https://design.ros2.org/articles/ros2_security_enclaves.html |
| [154] | DiLuoffo V., Michalson W. R. and Sunar B. (2018). Robot operating system 2: The need for a holistic security approach to robotic architectures. Int. J. Adv. Robot. Syst. 15:1−15. DOI:10.1177/1729881418770011 |
| [155] | Deng G., Xu G., Zhou Y., et al. (2022). On the (In)Security of secure ROS2. Proceedings of the 2022 ACM SIGSAC conference on computer and communications security 739−753. DOI:10.1145/3548606.3560681 |
| [156] | Pandya N. V., Kumar H., Pillai G. M., et al. (2024). Decentralized information-flow control for ROS2. 31st Annual Network and Distributed System Security Symposium (NDSS 2024) (Internet Society): 1–18. DOI: 10.14722/ndss.2024.24101 |
| [157] | Jiao R., Xie S., Yue J., et al. (2025). Can we trust embodied agents? Exploring back-door attacks against embodied LLM-based decision-making systems. The thirteenth international conference on learning representations (ICLR 2025) (ICLR). DOI: 10.48550/arXiv.2405.20774 |
| [158] | OWASP Foundation (2025). OWASP top 10 for large language model applications. (OWASP Foundation). Available at: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/ |
| [159] | MITRE (2026). MITRE ATLAS: Adversarial threat landscape for artificial-intelligence systems. (MITRE). Available at: https://atlas.mitre.org/ |
| [160] | European Parliament and Council of the European Union (2024). Regulation (EU) 2024/1689: Artificial intelligence act. (Publications Office of the European Union). Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj |
| [161] | International Society of Automation (2026). ISA/IEC 62443 series of standards: Security for industrial automation and control systems. (International Society of Automation). Available at: https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards |
| [162] | Hu H., Salcic Z., Sun L., et al. (2022). Membership inference attacks on machine learning: A survey. ACM Comput. Surv. 54:1−37. DOI:10.1145/3523273 |
| [163] | Li M., Ding W. and Zhao D. (2024). Privacy risks in reinforcement learning for house-hold robots. IEEE international conference on robotics and automation (ICRA) 5148−5154. DOI:10.1109/icra57147.2024.10610832 |
| [164] | Dietrich M., Krüger M. and Weisswange T. H. (2023). What should a robot disclose about me? A study about privacy-appropriate behaviors for social robots. Front. Robot. AI 10:1236733. DOI:10.3389/frobt.2023.1236733 |
| [165] | Stapels J. G., Penner A., Diekmann N., et al. (2023). Never trust anything that can think for itself if you can’t control its privacy settings: The influence of a robot’s privacy settings on users’ attitudes and willingness to self-disclose. Int. J. Soc. Robot. 15:1487−1505. DOI:10.1007/s12369-023-01043-8 |
| [166] | Su H., Cui Y., Santina C. D., et al. (2026). Embodied AI: Bridging robotics and AI toward real-world applications [from the guest editors]. IEEE Robot. Autom. Mag. 33:6−7. DOI:10.1109/mra.2026.3653534 |
| [167] | Nazarczuk M., Behrens J. K., Stepanova K., et al. (2025). Closed loop interactive embodied reasoning for robot manipulation. 2025 IEEE international conference on robotics and automation (ICRA) 13722−13729. DOI:10.1109/icra55743.2025.11127480 |
| [168] | Gurdur Broo D. (2026). Physical AI in cyber-physical systems: from digital to embodied industrial agents. J. Ind. Inf. Integr. 49:101038. DOI:10.1016/j.jii.2025.101038 |
| [169] | Firoozi R., Tucker J., Tian S., et al. (2025). Foundation models in robotics: Applications, challenges, and the future. Int. J. Robot. Res. 44:701−739. DOI:10.1177/02783649241281508 |
| [170] | Hu T., Gong Z., Kong L., et al. (2026). NavThinker: Action-conditioned world models for coupled prediction and planning in social navigation. arXiv. DOI: 10.48550/arXiv.2603.15359 |
| [171] | Gemini Robotics Team, Abeyruwan S., Ainslie J., et al. (2025). Gemini robotics: Bringing AI into the physical world. arXiv. DOI: 10.48550/arXiv.2503.20020 |
| [172] | Ma Y., Song Z., Zhuang Y., et al. (2024). A survey on vision-language-action models for embodied AI. arXiv. DOI: 10.48550/arXiv.2405.14093 |
| [173] | Kojima T., Zhu Y., Iwasawa Y., et al. (2025). A comprehensive survey on physical risk control in the era of foundation model-enabled robotics. arXiv. DOI: 10.48550/arXiv.2505.12583 |
| [174] | Xing W. and Shen J. (2024). Security control of cyber–physical systems under cyber attacks: A survey. Sensors 24:3815. DOI:10.3390/s24123815 |
| [175] | Deng Y., Wu T., Wu D., et al. (2026). Efficient coordination with the system-level shared state: An embodied-AI native modular framework. arXiv. DOI: 10.48550/arXiv.2601.13945 |
| [176] | Xie M. and Wei-Kocsis J. (2026). From prompt to physical action: Structured backdoor attacks on LLM-mediated robotic control systems. arXiv. DOI: 10.48550/arXiv.2604.03890 |
| [177] | Li A., Wang J., Baruah S., et al. (2024). An empirical study of performance interference: Timing violation patterns and impacts. 2024 IEEE 30th Real-Time and Embedded Technology and Applications Symposium (RTAS) 320−333. DOI:10.1109/rtas61025.2024.00033 |
| [178] | Hsiao Y. P., Li Y., Gamal Y., et al. (2026). Glitch in the sky: Exploiting voltage fault injection in UAV flight controllers. arXiv. DOI: 10.48550/arXiv.2604.16699 |
| [179] | Banerjee D., Tan C. M. and Baruah N. A. (2024). Application of component failure physics for the reliability assessment of an autonomous braking system. Sci. Rep. 14:28835. DOI:10.1038/s41598-024-80476-1 |
| [180] | Liu Z., Shanmugam D. and Schaumont P. (2024). FaultDetective: Explainable to a fault, from the design layout to the software. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024:610−632. |
| [181] | Liu J., Li H., Wang H., et al. (2025). TimeTravel: Real-time timing drift attack on system time using acoustic waves. 34th USENIX Security Symposium (USENIX Security 25) 3885−3902. |
| [182] | Fan W., Lane J., Liu Q., et al. (2024). Incorporating System-level Safety Requirements in Perception Models via Reinforcement Learning. arXiv. DOI: 10.48550/arXiv.2412.02951 |
| [183] | Huang Y., Hao Y., Yu B., et al. (2025). DaDu-Corki: Algorithm-architecture co-design for embodied AI-powered robotic manipulation. Proceedings of the 52nd Annual International Symposium on Computer Architecture (ISCA ’25) (ACM): 327–343. DOI: 10.1145/3695053.3731099 |
| [184] | Xie T., Qi Y., Wen J., et al. (2026). CREATE: Cross-layer resilience characterization and optimization for efficient yet reliable embodied AI systems. Proceedings of the 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2: 493–510. |
| [185] | Sato T., Suzuki R., Hayakawa Y., et al. (2025). On the realism of LiDAR spoofing attacks against autonomous driving vehicle at high speed and long distance. Network and distributed system security symposium (NDSS). DOI: 10.14722/ndss.2025.230628 |
| [186] | Sadeghi J., Lord N. A., Redford J., et al. (2023). Attacking motion planners using adversarial perception errors. arXiv. DOI: 10.48550/arXiv.2311.12722 |
| [187] | Wu W., Pierazzi F., Du Y., et al. (2024). Characterizing physical adversarial attacks on robot motion planners. 2024 IEEE international conference on robotics and automation (ICRA) 14319−14325. DOI:10.1109/icra57147.2024.10610344 |
| [188] | Mayoral-Vilches V., Carbajo U. A. and Gil-Uriarte E. (2020). Industrial robot ransomware: Akerbeltz. 2020 Fourth IEEE international conference on robotic computing (IRC) 432−435. DOI:10.1109/irc.2020.00080 |
| [189] | Pu H., He L., Cheng P., et al. (2024). CORMAND2: A deception attack against industrial robots. Engineering 32:186−201. DOI:10.1016/j.eng.2023.01.013 |
| [190] | Dieber B., Kacianka S., Rass S., et al. (2016). Application-level security for ROS-based applications. 2016 IEEE/RSJ international conference on intelligent robots and systems (IROS) 4477−4482. DOI:10.1109/iros.2016.7759659 |
| [191] | DeMarinis N., Tellex S., Kemerlis V. P., et al. (2019). Scanning the internet for ros: A view of security in robotics research. 2019 International conference on robotics and automation (ICRA) 8514−8521. DOI:10.1109/icra.2019.8794451 |
| [192] | Chung K., Li X., Tang P., et al. (2019). Smart Malware that Uses Leaked Control Data of Robotic Applications: The Case of Raven-Ⅱ Surgical Robots. 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019) (USENIX Association): 337–351. Available at: https://www.usenix.org/conference/raid2019/presentation/chung |
| [193] | Puccetti T., Nardi S., Cinquilli C., et al. (2024). ROSPaCe: Intrusion detection dataset for a ROS2-based cyber-physical system and IoT networks. Sci. Data 11:481. DOI:10.1038/s41597-024-03311-2 |
| [194] | Mayoral-Vilches V., Pinzger M., Rass S., et al. (2020). Can ROS be used securely in industry? Red teaming ROS-industrial. arXiv. DOI: 10.48550/arXiv.2009.08211 |
| [195] | Qureshi A., Marvi M., Shamsi J. A., et al. (2022). eUF: A framework for detecting over-the-air malicious updates in autonomous vehicles. J. King Saud Univ. Comput. Inf. Sci. 34:5456−5467. DOI:10.1016/j.jksuci.2021.05.005 |
| [196] | Mocnik R., Fowler D. S. and Maple C. (2023). Vehicular over-the-air software upgrade threat modelling. Cenex-LCV and cenex-CAM 2023. Available at: https://wrap.warwick.ac.uk/179188/ |
| [197] | Mayoral-Vilches V., Ayucar-Carbajo U., Laflamme O., et al. (2026). Cybersecurity AI: Hacking consumer robots in the AI era. arXiv. DOI: 10.48550/arXiv.2603.08665 |
| [198] | Wang X., Pan H., Zhang H., et al. (2024). Robot Collapse: Supply Chain Backdoor Attacks Against VLM-based Robotic Manipulation. arXiv. DOI: 10.48550/arXiv.2411.11683 |
| [199] | Zhou X., Tie G., Zhang G., et al. (2025). BadVLA: Towards backdoor attacks on vision-language-action models via objective-decoupled optimization. arXiv. DOI: 10.48550/arXiv.2505.16640 |
| [200] | Burbano L., Ortiz D., Sun Q., et al. (2025). CHAI: Command Hijacking against embodied AI. arXiv. DOI: 10.48550/arXiv.2510.00181 |
| [201] | Geng T., Qu Y. and Wong W. E. (2026). A white-box prompt injection attack on embodied AI agents driven by large language models. J. Syst. Softw. 235:112782. DOI:10.1016/j.jss.2026.112782 |
| [202] | Qin X., Luan S., See J., et al. (2026). Harnessing embodied agents: Runtime governance for policy-constrained execution. arXiv. DOI: 10.48550/arXiv.2604.07833 |
| [203] | Onik A. R., Alsmadi R., Baggili I., et al. (2024). So fresh, so clean: Cloud forensic analysis of the Amazon iRobot Roomba vacuum. Forensic Sci. Int. Digit. Investig. 48:301686. DOI:10.1016/j.fsidi.2023.301686 |
| [204] | Ulsmg B., Lin J. C. and Lee M. C. (2024). Investigating the privacy risk of using robot vacuum cleaners in smart environments. International conference on information and communications security 312−330. DOI:10.1007/978-981-97-8798-2_16 |
| [205] | Yang M., Huang C., Huang X., et al. (2025). Privacy-preserved visual simultaneous localization and mapping based on a dual-component approach. Appl. Sci. 15:2583. DOI:10.3390/app15052583 |
| [206] | Ravichandran Z., Robey A., Kumar V., et al. (2026). Safety guardrails for LLM-enabled robots. IEEE Robot. Autom. Lett. 11:4649−4656. DOI:10.1109/lra.2026.3667488 |
| [207] | Huang X., Zhang R., Cheng L., et al. (2026). LLM-guided safety agent for edge robotics with an ISO-compliant perception-compute-control architecture. arXiv. DOI: 10.48550/arXiv.2604.20193 |
| [208] | Obi I., Venkatesh V. L., Wang W., et al. (2026). Pre-execution safety gate & task safety contracts for LLM-controlled robot systems. arXiv. DOI: 10.48550/arXiv.2604.05427 |
| [209] | Liu J., Corbett-Davies J., Ferraiuolo A., et al. (2018). Secure autonomous cyber-physical systems through verifiable information flow control. Proceedings of the 2018 workshop on cyber-physical systems security and PrivaCy 48−59. DOI:10.1145/3264888.3264889 |
| [210] | Astorga A., Hsieh C., Madhusudan P., et al. (2023). Perception contracts for safety of ML-enabled systems. Proc. ACM Program. Lang. 7:2196−2223. DOI:10.1145/3622875 |
| [211] | Zhan S. S., Wang P., Liu Y., et al. (2025). SENTINEL: A Multi-Level Formal Framework for Safety Evaluation of Foundation Model-based Embodied Agents. arXiv. DOI: 10.48550/arXiv.2510.12985 |
| [212] | Yu D., Shi J., Ren J., et al. (2025). Enhancing security in embodied intelligence: Attack detection via constraint functions. International conference on algorithms and architectures for parallel processing 96−110. DOI:10.1007/978-981-95-8417-8_8 |
| [213] | Choi H., Lee W. C., Aafer Y., et al. (2018). Detecting attacks against robotic vehicles: A control invariant approach. Proceedings of the 2018 ACM SIGSAC conference on computer and communications security 801−816. DOI:10.1145/3243734.3243752 |
| [214] | Hobbs K. L., Mote M. L., Abate M. C., et al. (2023). Runtime assurance for safety-critical systems: An introduction to safety filtering approaches for complex control systems. IEEE Control Syst. 43:28−65. DOI:10.1109/mcs.2023.3234380 |
| [215] | Hsu K. C., Hu H. and Fisac J. F. (2024). The safety filter: A unified view of safety-critical control in autonomous systems. Annu. Rev. Control Robot. Auton. Syst. 7:47−72. DOI:10.1146/annurev-control-071723-102940 |
| [216] | Schilliger J., Lew T., Richards S. M., et al. (2021). Control barrier functions for cyber-physical systems and applications to NMPC. IEEE Robot. Autom. Lett. 6:8623−8630. DOI:10.1109/lra.2021.3111010 |
| [217] | Knoedler L., So O., Yin J., et al. (2025). Safety on the fly: Constructing robust safety filters via policy control barrier functions at runtime. IEEE Robot. Autom. Lett. 10:10058−10065. DOI:10.1109/lra.2025.3597847 |
| [218] | Zhang Z., Lei L., Wu L., et al. (2024). SafetyBench: Evaluating the safety of large language models. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) 15537−15553. DOI:10.18653/v1/2024.acl-long.830 |
| [219] | Zhu Z., Wu B., Zhang Z., et al. (2024). EARBench: Towards evaluating physical risk awareness for task planning of foundation model-based embodied AI agents. arXiv. DOI: 10.48550/arXiv.2408.04449 |
| [220] | Sun Q., Chi X., Rui Y., et al. (2026). LABSHIELD: A multimodal benchmark for safety-critical reasoning and planning in scientific laboratories. arXiv. DOI: 10.48550/arXiv.2603.11987 |
| [221] | Lu X., Chen Z., Hu X., et al. (2026). IS-Bench: Evaluating interactive safety of VLM-driven embodied agents in daily household tasks. Proceedings of the AAAI conference on artificial intelligence 40:35680−35688. DOI:10.1609/aaai.v40i42.40880 |
| [222] | Tomilin T., Fang M. and Pechenizkiy M. (2025). HASARD: A benchmark for vision-based safe reinforcement learning in embodied agents. The thirteenth international conference on learning representations. |
| [223] | Fei S., Wang S., Shi J., et al. (2025). Libero-Plus: In-depth robustness analysis of vision-language-action models. arXiv. DOI: 10.48550/arXiv.2510.13626 |
| [224] | Huang Y., Wang Z., Wan Z., et al. (2025). Annie: Be careful of your robots. arXiv. DOI: 10.48550/arXiv.2509.03383 |
| [225] | Huang Y., Ding L., Tang Z., et al. (2025). A framework for benchmarking and aligning task-planning safety in LLM-based embodied agents. arXiv. DOI: 10.48550/arXiv.2504.14650 |
| [226] | Advanced Technology Exploration Community (2026). ATEC2026: The real-world ex-treme challenge competition for embodied intelligence. (Advanced Technology Exploration Community). Available at: https://www.atecup.com/competitions/ATEC2026 |
| [227] | DARKNAVY (2026). Embodied AI security technology white paper: Robotics chapter. (DARKNAVY). Available at: https://www.darknavy.org/zh/blog/embodied-ai-security-humanoid-robots/ |
| [228] | Man Y., Muller R., Li M., et al. (2023). That person moves like a car: Misclassification attack detection for autonomous systems using spatiotemporal consistency. 32nd USENIX Security Symposium (USENIX Security 23) (USENIX Association): 6929–6946. Available at: https://www.usenix.org/conference/usenixsecurity23/presentation/man |
| [229] | Cao Y., Bhupathiraju S. H., Naghavi P., et al. (2023). You Can’t See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks. 32nd USENIX Security Symposium (USENIX Security 23) (USENIX Association): 2993–3010. Available at: https://www.usenix.org/conference/usenixsecurity23/presentation/cao . |
| [230] | Xiao Q., Pan X., Lu Y., et al. (2023). Exorcising “Wraith”: Protecting LiDAR-based Object Detector in Automated Driving System from Appearing Attacks. 32nd USENIX Security Symposium (USENIX Security 23) (USENIX Association): 2939–2956. Available at: https://www.usenix.org/conference/usenixsecurity23/presentation/xiao-qifan . |
| [231] | Sathaye H., LaMountain G., Closas P., et al. (2022). SemperFi: Anti-spoofing GPS receiver for UAVs. Network and distributed system security symposium (NDSS 2022) (Internet Society). DOI: 10.14722/ndss.2022.23071 |
| [232] | Jeong J., Kim D., Jang J. H., et al. (2023). Un-Rocking Drones: Foundations of acoustic injection attacks and recovery thereof. Network and distributed system security symposium (NDSS 2023) (Internet Society). DOI: 10.14722/ndss.2023.24112 |
| [233] | Ding A., Murthy P., Garcia L., et al. (2021). Mini-Me, You Complete Me! Data-Driven Drone Security via DNN-based Approximate Computing. Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses (RAID) (Association for Computing Machinery): 428–441. DOI: 10.1145/3471621.3471869 |
| [234] | Sciangula G., Casini D., Biondi A., et al. (2023). Bounding the Data-Delivery Latency of DDS Messages in Real-Time Applications. Papadopoulos A. V. (ed). 35th Euromicro Conference on Real-Time Systems (ECRTS 2023) (Schloss Dagstuhl – Leibniz-Zentrum für Informatik), Leibniz International Proceedings in Informatics (LIPIcs) 262: 9: 1-9: 26. DOI: 10.4230/LIPIcs.ECRTS.2023.9 |
| [235] | Gu Q., Ju Y., Sun S., et al. (2025). SAFE: Multitask failure detection for vision-language-action models. Adv. Neural Inf. Process. Syst. 38. DOI:10.48550/arXiv.2506.09937 |
| [236] | Zhang B., Zhang Y., Ji J., et al. (2025). SafeVLA: Towards safety alignment of vision-language-action model via constrained learning. Adv. Neural Inf. Process. Syst. 38. Available at: https://neurips.cc/virtual/2025/loc/san-diego/poster/116975 |
| [237] | Ichnowski J., Chen K., Dharmarajan K., et al. (2023). FogROS2: An adaptive platform for cloud and fog robotics using ROS 2. IEEE international conference on robotics and automation, ICRA 2023, London, UK, May 29 - June 2, 2023 (IEEE): 5493–5500. DOI: 10.1109/ICRA48891.2023.10161307 |
| Feng T., Zhang Y., Zhou S., et al. (2026). From bits to atoms: A survey of cross-layer safety in Embodied AI. AI Plus 1:100013. https://doi.org/10.59717/ipj.aiplus.2026.100013 |
To request copyright permission to republish or share portions of our works, please visit Copyright Clearance Center's (CCC) Marketplace website at marketplace.copyright.com.
Four-layer reference architecture for embodied AI systems
Evolution of safety paradigms in robotic and embodied AI systems
Cross-layer risk propagation in embodied AI
Overview of hardware safety and security in Embodied AI
Overview of software safety and security in Embodied AI