Article Contents
REVIEW   Open Access     Cite

From bits to atoms: A survey of cross-layer safety in Embodied AI

    Show all affliationsShow less
More Information
  • DownLoad: Full size image
    1. Embodied Artificial Intelligence (AI) connects digital intelligence with physical action, so local faults, cyberattacks, or unsafe decisions can cause real-world harm.

      This review presents a four-layer framework spanning physical interaction, system and middleware, algorithm and decision, and cloud-edge and data.

      It reveals how risks propagate across layers and unifies functional, physical, and behavioral safety with defenses and closed-loop benchmarks.

  • Embodied Artificial Intelligence (AI) introduces cyber–physical risks because digital failures and attacks can cause physical harm. This survey organizes embodied AI safety through a four-layer reference architecture — comprising the physical interaction, system and middleware, algorithm and decision, and cloud–edge and data layers — and uses it to connect vulnerabilities, propagation paths, and safeguards across the system stack. It traces the evolution of safety paradigms and examines how faults and attacks cross architectural boundaries to produce physical consequences. Furthermore, the survey systematizes composite attack chains, outlines multi-layered defense strategies, and reviews representative embodied safety benchmarks. Ultimately, we advocate for unifying software alignment with rigorous hardware constraints to build trustworthy systems capable of operating safely within human-centric environments.
  • 加载中
  • [1] Duan J., Yu S., Tan H. L., et al. (2022). A survey of embodied AI: From simulators to research tasks. IEEE Trans. Emerg. Top. Comput. Intell. 6:230−244. DOI:10.1109/tetci.2022.3141105

    View in Article CrossRef Google Scholar

    [2] Liu Y., Chen W., Bai Y., et al. (2025). Aligning cyber space with physical world: A comprehensive survey on embodied AI. IEEE/ASME Trans. Mechatron. 30:7253−7274. DOI:10.1109/TMECH.2025.3574943

    View in Article CrossRef Google Scholar

    [3] Xing W., Li M., Li M., et al. (2026). Towards robust and secure embodied AI: A survey on vulnerabilities and attacks. ACM Comput. Surv. 58:312. DOI:10.1145/3806048

    View in Article CrossRef Google Scholar

    [4] Humayed A., Lin J., Li F., et al. (2017). Cyber-physical systems security—A survey. IEEE Internet Things J. 4:1802−1831. DOI:10.1109/jiot.2017.2703172

    View in Article CrossRef Google Scholar

    [5] Yaacoub J. P. A., Noura H. N., Salman O., et al. (2022). Robotics cyber security: vulnerabilities, attacks, countermeasures, and recommendations. Int. J. Inf. Secur. 21:115−158. DOI:10.1007/s10207-021-00545-8

    View in Article CrossRef Google Scholar

    [6] Ouyang L., Wu J., Jiang X., et al. (2022). Training language models to follow instructions with human feedback. Adv. Neural Inf. Process. Syst. 35:27730−27744. DOI:10.52202/068431-2011

    View in Article CrossRef Google Scholar

    [7] Rafailov R., Sharma A., Mitchell E., et al. (2023). Direct preference optimization: Your language model is secretly a reward model. Adv. Neural Inf. Process. Syst. 36:53728−53741. DOI:10.52202/075280-2338

    View in Article CrossRef Google Scholar

    [8] Robey A., Ravichandran Z., Kumar V., et al. (2025). Jailbreaking LLM-controlled robots. 2025 IEEE international conference on robotics and automation (ICRA) (IEEE): 11948–11956. DOI: 10.1109/ICRA55743.2025.11128119

    View in Article Google Scholar

    [9] Ying Z., Wang L., Xiao Y., et al. (2026). Agentsafe: Benchmarking the safety of embodied agents on hazardous instructions. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition 37664−37673.

    View in Article Google Scholar

    [10] Yin S., Pang X., Ding Y., et al. (2024). SafeAgentBench: A benchmark for safe task planning of embodied LLM agents. arXiv. DOI: 10.48550/arXiv.2412.13178

    View in Article Google Scholar

    [11] Xu Y., Han X., Deng G., et al. (2023). SoK: Rethinking sensor spoofing attacks against robotic vehicles from a systematic view. 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) 1082−1100. DOI:10.1109/eurosp57164.2023.00067

    View in Article CrossRef Google Scholar

    [12] Cao Y., Xiao C., Cyr B., et al. (2019). Adversarial Sensor Attack on LiDAR-based Perception in Autonomous Driving. Proceedings of the 2019 ACM SIGSAC conference on computer and communications security (CCS) 2267−2281. DOI:10.1145/3319535.3339815

    View in Article CrossRef Google Scholar

    [13] Botta A., Rotbei S., Zinno S., et al. (2023). Cyber security of robots: A comprehensive survey. Intell. Syst. Appl. 18:200237. DOI:10.1016/j.iswa.2023.200237

    View in Article CrossRef Google Scholar

    [14] Cárdenas A. A., Amin S. and Sastry S. (2008). Research challenges for the security of control systems. 3rd USENIX Workshop on Hot Topics in Security (HotSec 08) (USENIX Association). Available at: https://www.usenix.org/conference/hotsec-08/research-challenges-security-control-systems

    View in Article Google Scholar

    [15] Stellios I., Kotzanikolaou P. and Grigoriadis C. (2021). Assessing IoT enabled cyber-physical attack paths against critical systems. Comput. Secur. 107:102316. DOI:10.1016/j.cose.2021.102316

    View in Article CrossRef Google Scholar

    [16] Liu T., Tian J., Wang J., et al. (2019). Integrated security threats and defense of cyber-physical systems. Acta Autom. Sin. 45:5−24.

    View in Article Google Scholar

    [17] Kim J., Chen W., Soleymanzadeh D., et al. (2026). Modular safety guardrails are necessary for foundation-model-enabled robots in the real world. arXiv. DOI: 10.48550/arXiv.2602.04056

    View in Article Google Scholar

    [18] Lasota P. A., Fong T. and Shah J. A. (2017). A survey of methods for safe human-robot interaction. Found. Trends Robot. 5:261−349. DOI:10.1561/2300000052

    View in Article CrossRef Google Scholar

    [19] Desai A., Ghosh S., Seshia S. A., et al. (2019). SOTER: A runtime assurance frame- work for programming safe robotics systems. 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks: 138–150. DOI: 10.1109/dsn.2019.00027

    View in Article Google Scholar

    [20] Albus J. S., Huang H. M., Messina E., et al. (2002). 4D/RCS version 2.0: A reference model architecture for unmanned vehicle systems. (National Institute of Standards and Technology).

    View in Article Google Scholar

    [21] Ahmad A. and Babar M. A. (2016). Software architectures for robotic systems: A systematic mapping study. J. Syst. Softw. 122:16−39. DOI:10.1016/j.jss.2016.08.039

    View in Article CrossRef Google Scholar

    [22] Elkady A. and Sobh T. (2012). Robotics middleware: A comprehensive literature survey and attribute-based bibliography. J. Robot. 2012:959013. DOI:10.1155/2012/959013

    View in Article CrossRef Google Scholar

    [23] Kehoe B., Patil S., Abbeel P., et al. (2015). A survey of research on cloud robotics and automation. IEEE Trans. Autom. Sci. Eng. 12:398−409. DOI:10.1109/tase.2014.2376492

    View in Article CrossRef Google Scholar

    [24] Hu G., Tay W. P. and Wen Y. (2012). Cloud robotics: Architecture, challenges and applications. IEEE Network 26:21−28. DOI:10.1109/mnet.2012.6201212

    View in Article CrossRef Google Scholar

    [25] De Santis A., Siciliano B., De Luca A., et al. (2008). An atlas of physical human–robot interaction. Mech. Mach. Theory 43:253−270. DOI:10.1016/j.mechmachtheory.2007.03.003

    View in Article CrossRef Google Scholar

    [26] Quigley M., Gerkey B. P., Conley K., et al. (2009). ROS: An open-source robot operating system. Open-source software workshop of the international conference on robotics and automation (ICRA).

    View in Article Google Scholar

    [27] Dieber B., Breiling B., Taurer S., et al. (2017). Security for the robot operating system. Robot. Auton. Syst. 98:192−203. DOI:10.1016/j.robot.2017.09.017

    View in Article CrossRef Google Scholar

    [28] Ahn M., Brohan A., Brown N., et al. (2023). Do as I can, not as I say: Grounding language in robotic affordances. Proceedings of the 6th Conference on Robot Learning (CoRL) 287−318.

    View in Article Google Scholar

    [29] Driess D., Xia F., Sajjadi M. S. M., et al. (2023). PaLM-E: An embodied multimodal language model. Proceedings of the 40th International Conference on Machine Learning (PMLR), Proceedings of Machine Learning Research 202: 8469–8488. Available at: https://proceedings.mlr.press/v202/driess23a.html

    View in Article Google Scholar

    [30] Brohan A., Brown N., Carbajal J., et al. (2023). RT-2: Vision-language-action models transfer web knowledge to robotic control. Proceedings of the 7th Conference on Robot Learning (CoRL): 2165–2183.

    View in Article Google Scholar

    [31] Kim M. J., Pertsch K., Karamcheti S., et al. (2025). OpenVLA: An open-source vision-language-action model. Proceedings of the 8th Conference on Robot Learning (CoRL) (PMLR), Proceedings of Machine Learning Research 270: 2679–2713.

    View in Article Google Scholar

    [32] Black K., Brown N., Driess D., et al. (2024). π0: A vision-language-action flow model for general robot control. arXiv. DOI: 10.48550/arXiv.2410.24164

    View in Article Google Scholar

    [33] NVIDIA, Bjorck J., Castañeda F., et al. (2025). GR00T N1: An open foundation model for generalist humanoid robots. arXiv. DOI: 10.48550/arXiv.2503.14734

    View in Article Google Scholar

    [34] Open X-Embodiment Collaboration, O’Neill A., Rehman A., et al. (2024). Open X-Embodiment: Robotic learning datasets and RT-X models. 2024 IEEE international conference on robotics and automation (ICRA): 6892–6903.

    View in Article Google Scholar

    [35] Kim K., Kim J. S., Jeong S., et al. (2021). Cybersecurity for autonomous vehicles: Review of attacks and defense. Comput. Secur. 103:102150. DOI:10.1016/j.cose.2020.102150

    View in Article CrossRef Google Scholar

    [36] Sun X., Yu F. R. and Zhang P. (2022). A survey on cyber-security of connected and autonomous vehicles (CAVs). IEEE Trans. Intell. Transp. Syst. 23:6240−6259. DOI:10.1109/tits.2021.3085297

    View in Article CrossRef Google Scholar

    [37] Giraldo J., Urbina D., Cardenas A., et al. (2018). A survey of physics-based attack detection in cyber-physical systems. ACM Comput. Surv. 51:1−36. DOI:10.1145/3203245

    View in Article CrossRef Google Scholar

    [38] International Organization for Standardization (2024). ISO/IEC TR 5469: 2024 — Artificial intelligence — Functional safety and AI systems. (International Organization for Standardization). Available at: https://www.iso.org/standard/81283.html

    View in Article Google Scholar

    [39] Ames A. D., Xu X., Grizzle J. W., et al. (2017). Control barrier function based quadratic programs for safety critical systems. IEEE Trans. Autom. Control 62:3861−3876. DOI:10.1109/tac.2016.2638961

    View in Article CrossRef Google Scholar

    [40] Alshiekh M., Bloem R., Ehlers R., et al. (2018). Safe reinforcement learning via shielding. Proceedings of the 32nd AAAI Conference on Artificial Intelligence (AAAI) 32:2669−2678. DOI:10.1609/aaai.v32i1.11797

    View in Article CrossRef Google Scholar

    [41] Anjomshoae S., Najjar A., Calvaresi D., et al. (2019). Explainable agents and robots: Results from a systematic literature review. Proceedings of the 18th International Conference on Autonomous Agents and MultiAgent Systems (AAMAS) 1078−1088. DOI:10.65109/kczb5817

    View in Article CrossRef Google Scholar

    [42] Sakai T. and Nagai T. (2022). Explainable autonomous robots: A survey and perspective. Adv. Robot. 36:219−238. DOI:10.1080/01691864.2022.2029720

    View in Article CrossRef Google Scholar

    [43] Visinsky M. L., Cavallaro J. R. and Walker I. D. (1994). Robotic fault detection and fault tolerance: A survey. Reliab. Eng. Syst. Saf. 46:139−158. DOI:10.1016/0951-8320(94)90132-5

    View in Article CrossRef Google Scholar

    [44] Leucker M. and Schallhart C. (2009). A brief account of runtime verification. J. Log. Algebr. Program. 78:293−303. DOI:10.1016/j.jlap.2008.08.004

    View in Article CrossRef Google Scholar

    [45] Amodei D., Olah C., Steinhardt J., et al. (2016). Concrete problems in AI safety. arXiv. DOI: 10.48550/arXiv.1606.06565

    View in Article Google Scholar

    [46] Ji J., Qiu T., Chen B., et al. (2023). AI alignment: A comprehensive survey. arXiv. DOI: 10.48550/arXiv.2310.19852

    View in Article Google Scholar

    [47] International Electrotechnical Commission (2010). IEC 61508: Functional safety of electrical/electronic/programmable electronic safety-related systems, Edition 2.0. (International Electrotechnical Commission). Available at: https://webstore.iec.ch/en/publication/22273

    View in Article Google Scholar

    [48] International Organization for Standardization (2011). ISO 10218-1: 2011 and ISO 10218-2: 2011 — Robots and robotic devices — Safety requirements for industrial robots. (International Organization for Standardization).

    View in Article Google Scholar

    [49] Leveson N. G. (2012). Engineering a safer world: Systems thinking applied to safety. (MIT Press).

    View in Article Google Scholar

    [50] International Organization for Standardization (2016). ISO/TS 15066: 2016 — Robots and robotic devices — Collaborative robots. (International Organization for Standardization). Available at: https://www.iso.org/standard/62996.html

    View in Article Google Scholar

    [51] Haddadin S., Albu-Schäffer A. and Hirzinger G. (2009). Requirements for safe robots: Measurements, analysis and new insights. Int. J. Robot. Res. 28:1507−1527. DOI:10.1177/0278364909343970

    View in Article CrossRef Google Scholar

    [52] Villani V., Pini F., Leali F., et al. (2018). Survey on human–robot collaboration in industrial settings: Safety, intuitive interfaces and applications. Mechatronics 55:248−266. DOI:10.1016/j.mechatronics.2018.02.009

    View in Article CrossRef Google Scholar

    [53] Underwriters Laboratories (2023). UL 4600: Standard for safety for the evaluation of autonomous products, edition 3. (Underwriters Laboratories). Available at: https://www.ul.com/news/ul-4600-edition-3-updates-incorporate-autonomous-trucking

    View in Article Google Scholar

    [54] Zhang H., Zhu C., Wang X., et al. (2025). BadRobot: Jailbreaking embodied LLM agents in the physical world. The thirteenth international conference on learning representations (ICLR).

    View in Article Google Scholar

    [55] Ruan Y., Dong H., Wang A., et al. (2024). Identifying the risks of LM agents with an LM-emulated sandbox. Proceedings of the 12th International Conference on Learning Representations (ICLR).

    View in Article Google Scholar

    [56] Li H., Wei M., Huang J., et al. (2019). Survey on cyber-physical system technologies. Acta Autom. Sin. 45: 37–50.

    View in Article Google Scholar

    [57] Buldyrev S. V., Parshani R., Paul G., et al. (2010). Catastrophic cascade of failures in interdependent networks. Nature 464:1025−1028. DOI:10.1038/nature08932

    View in Article CrossRef Google Scholar

    [58] Shin H., Kim D., Kwon Y., et al. (2017). Illusion and Dazzle: Adversarial Optical Channel Exploits against LiDARs for Automotive Applications. Cryptographic hardware and embedded systems (CHES) 445−467. DOI:10.1007/978-3-319-66787-4_22

    View in Article CrossRef Google Scholar

    [59] Son Y., Shin H., Kim D., et al. (2015). Rocking drones with intentional sound noise on gyroscopic sensors. Proceedings of the 24th USENIX Security Symposium 881−896.

    View in Article Google Scholar

    [60] Quarta D., Pogliani M., Polino M., et al. (2017). An experimental security analysis of an industrial robot controller. 2017 IEEE symposium on security and privacy (s&p) 268−286. DOI:10.1109/sp.2017.20

    View in Article CrossRef Google Scholar

    [61] Schneier B. (1999). Attack trees: Modeling security threats. Dr. Dobb’s J. 24:21−29.

    View in Article Google Scholar

    [62] Shostack A. (2014). Threat modeling: Designing for security. (Wiley).

    View in Article Google Scholar

    [63] UcedaVelez T. and Morana M. M. (2015). Risk centric threat modeling: Process for attack simulation and threat analysis. (Wiley).

    View in Article Google Scholar

    [64] International Organization for Standardization and Society of Automotive Engineers (2021). ISO/SAE 21434: 2021 — road vehicles — cybersecurity engineering. (International Organization for Standardization and SAE International). Available at: https://www.iso.org/standard/70918.html

    View in Article Google Scholar

    [65] National Institute of Standards and Technology (2024). The NIST Cybersecurity Framework (CSF) 2.0. (National Institute of Standards and Technology). Available at: https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20

    View in Article Google Scholar

    [66] Tabassi E. (2023). Artificial intelligence risk management framework (AI RMF 1.0). (National Institute of Standards and Technology). DOI: 10.6028/NIST.AI.100-1

    View in Article Google Scholar

    [67] El-Rewini Z., Sadatsharan K., Selvaraj D. F., et al. (2020). Cybersecurity challenges in vehicular communications. Veh. Commun. 23:100214. DOI:10.1016/j.vehcom.2019.100214

    View in Article CrossRef Google Scholar

    [68] Haskard A. and Herath D. (2025). Secure robotics: Navigating challenges at the nexus of safety, trust, and cybersecurity in cyber-physical systems. ACM Comput. Surv. 57:1−48. DOI:10.1145/3723050

    View in Article CrossRef Google Scholar

    [69] Zacharaki A., Kostavelis I., Gasteratos A., et al. (2020). Safety bounds in human–robot interaction: A survey. Saf. Sci. 127:104667. DOI:10.1016/j.ssci.2020.104667

    View in Article CrossRef Google Scholar

    [70] Dibaji S. M., Pirani M., Flamholz D. B., et al. (2019). A systems and control perspective of CPS security. Annu. Rev. Control 47:394−411. DOI:10.1016/j.arcontrol.2019.04.011

    View in Article CrossRef Google Scholar

    [71] Petit J. and Shladover S. E. (2015). Potential cyberattacks on automated vehicles. IEEE Trans. Intell. Transp. Syst. 16:546−556. DOI:10.1109/tits.2014.2342271

    View in Article CrossRef Google Scholar

    [72] Guesmi A., Hanif M. A., Ouni B., et al. (2024). Physical adversarial attacks for camera-based smart systems: Current trends, categorization, applications, research challenges, and future outlook. IEEE Access 12:14150−14174. DOI:10.1109/access.2023.3321118

    View in Article CrossRef Google Scholar

    [73] Girdhar M., Hong J. and Moore J. (2023). Cybersecurity of autonomous vehicles: A systematic literature review of adversarial attacks and defense models. IEEE Open J. Veh. Technol. 4:417−437. DOI:10.1109/ojvt.2023.3265363

    View in Article CrossRef Google Scholar

    [74] Deng Z., Guo Y., Han C., et al. (2025). AI agents under threat: A survey of key security challenges and future pathways. ACM Comput. Surv. 57:182. DOI:10.1145/3716628

    View in Article CrossRef Google Scholar

    [75] He F., Zhu T., Ye D., et al. (2025). The emerged security and privacy of LLM agent: A survey with case studies. ACM Comput. Surv. 58:1−36. DOI:10.1145/3773080

    View in Article CrossRef Google Scholar

    [76] Liu Y., Yao Y., Ton J. F., et al. (2023). Trustworthy LLMs: A survey and guideline for evaluating large language models’ alignment. NeurIPS 2023 workshop on socially responsible language modelling research (SoLaR).

    View in Article Google Scholar

    [77] Neupane S., Mitra S., Fernandez I. A., et al. (2024). Security considerations in AI-robotics: A survey of current methods, challenges, and opportunities. IEEE Access 12:22072−22097. DOI:10.1109/access.2024.3363657

    View in Article CrossRef Google Scholar

    [78] Wang Z., Hu J. and Mu R. (2025). Safety of embodied navigation: A survey. Proceedings of the 34th International Joint Conference on Artificial Intelligence (IJCAI) — Survey Track 10714−10722. DOI:10.24963/ijcai.2025/1189

    View in Article CrossRef Google Scholar

    [79] Xu W., Ji X., Yan C., et al. (2025). Embodied artificial intelligence security and governance. Bull. Chin. Acad. Sci. 40:429−439. DOI:10.16418/j.issn.1000-3045.20250218002

    View in Article CrossRef Google Scholar

    [80] Lu X., Huang Z., Li X., et al. (2024). POEX: Towards policy executable jailbreak attacks against the LLM-based robots. arXiv. DOI: 10.48550/arXiv.2412.16633

    View in Article Google Scholar

    [81] Tang L., Wang R., Liu Z., et al. (2024). Scenario-based accelerated testing for SOTIF in autonomous driving: a review. IEEE Internet Things J. 12:1453−1470. DOI:10.1109/jiot.2024.3490598

    View in Article CrossRef Google Scholar

    [82] Zhang X., Dong H., Zhang H., et al. (2025). A real-time, robust and versatile visual-SLAM framework based on deep learning networks. IEEE Trans. Instrum. Meas. 74:1−13. DOI:10.1109/tim.2025.3527618

    View in Article CrossRef Google Scholar

    [83] Chakraborty A., Alam M., Dey V., et al. (2021). A survey on adversarial attacks and defences. CAAI Trans. Intell. Technol. 6:25−45. DOI:10.1049/cit2.12028

    View in Article CrossRef Google Scholar

    [84] Liu J., Levine A., Lau C. P., et al. (2022). Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition 14973−14982. DOI:10.1109/cvpr52688.2022.01455

    View in Article CrossRef Google Scholar

    [85] Nassi B., Mirsky Y., Nassi D., et al. (2020). Phantom of the ADAS: Securing advanced driver-assistance systems from split-second phantom attacks. ACM conference on computer and communications security (CCS) 293−308. DOI:10.1145/3372297.3423359

    View in Article CrossRef Google Scholar

    [86] Li Y., Yang F., Liu Q., et al. (2023). Light can be dangerous: Stealthy and effective physical-world adversarial attack by spot light. Comput. Secur. 132:103345. DOI:10.1016/j.cose.2023.103345

    View in Article CrossRef Google Scholar

    [87] Cheng Y., Ji X., Zhu W., et al. (2023). Adversarial computer vision via acoustic manipulation of camera sensors. IEEE Trans. Dependable Secure Comput. 21:3734−3750. DOI:10.1109/tdsc.2023.3334618

    View in Article CrossRef Google Scholar

    [88] Duan R., Mao X., Qin A. K., et al. (2021). Adversarial laser beam: Effective physical-world attack to DNNs in a blink. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition (CVPR) 16057−16066. DOI:10.1109/cvpr46437.2021.01580

    View in Article CrossRef Google Scholar

    [89] Yan C., Xu Z., Yin Z., et al. (2022). Rolling colors: Adversarial laser exploits against traffic light recognition. arXiv. DOI: 10.48550/arXiv.2204.02675

    View in Article Google Scholar

    [90] Cheng Z., Liang J., Choi H., et al. (2022). Physical attack on monocular depth estimation with optimal adversarial patches. Computer vision – ECCV 2022 (Springer), Lecture Notes in Computer Science 13698: 514–532. DOI: 10.1007/978-3-031-19839-7_30

    View in Article Google Scholar

    [91] Jing P., Tang Q., Du Y., et al. (2021). Too good to be safe: Tricking lane detection in autonomous driving with crafted perturbations. 30th USENIX Security Symposium (USENIX Security 21) 3237−3254.

    View in Article Google Scholar

    [92] Jia Y., Lu Y., Shen J., et al. (2020). Fooling Detection Alone is Not Enough: Adversarial Attack against Multiple Object Tracking. International conference on learning representations (ICLR).

    View in Article Google Scholar

    [93] Davidson D., Wu H., Jellinek R., et al. (2016). Controlling UAVs with sensor input spoofing attacks. Workshop on offensive technologies (WOOT).

    View in Article Google Scholar

    [94] Burrus N., Abderrahim M., Garcia J., et al. (2011). Object Reconstruction and Recognition leveraging an RGB-D camera. Proceedings of the 12th IAPR Conference on Machine Vision Applications: 3–6.

    View in Article Google Scholar

    [95] Li Y. and Ibanez-Guzman J. (2020). LiDAR for autonomous driving: The principles, challenges, and trends for automotive LiDAR and perception systems. IEEE Signal Process. Mag. 37:50−61. DOI:10.1109/msp.2020.2973615

    View in Article CrossRef Google Scholar

    [96] Kim B. K. and Sumi Y. (2020). Vision-based safety-related sensors in low visibility by fog. Sensors 20(10): 2812. DOI: 10.3390/s20102812

    View in Article Google Scholar

    [97] Petit J., Stottelaar B., Feiri M., et al. (2015). Remote attacks on automated vehicles sensors: Experiments on camera and LiDAR. Black hat europe.

    View in Article Google Scholar

    [98] Jin Z., Ji X., Cheng Y., et al. (2023). PLA-LiDAR: Physical laser attacks against LiDAR-based 3D object detection in autonomous vehicle. IEEE symposium on security and privacy (s&p) 1822−1839. DOI:10.1109/sp46215.2023.10179458

    View in Article CrossRef Google Scholar

    [99] Ahmad N., Ghazilla R. A. R., Khairi N. M., et al. (2013). Reviews on various inertial measurement unit (IMU) sensor applications. IJSPS 1:256−262. DOI:10.12720/ijsps.1.2.256-262

    View in Article CrossRef Google Scholar

    [100] Burnett K., Schoellig A. P. and Barfoot T. D. (2025). IMU as an input versus a measurement of the state in inertial-aided state estimation. Robotica 43:1−21. DOI:10.1017/s0263574724002121

    View in Article CrossRef Google Scholar

    [101] Wu Y., Kuang J., Niu X., et al. (2025). Wheel-GINS: A GNSS/INS integrated navigation system with a wheel-mounted IMU. IEEE Trans. Intell. Transp. Syst. 26:6891−6903. DOI:10.1109/tits.2025.3527815

    View in Article CrossRef Google Scholar

    [102] Gao M., Zhang L., Shen L., et al. (2023). Exploring practical acoustic transduction attacks on inertial sensors in MDOF systems. IEEE Trans. Mob. Comput. 23:3539−3557. DOI:10.1109/tmc.2023.3277287

    View in Article CrossRef Google Scholar

    [103] Wang Z., Wang K., Yang B., et al. (2017). Sonic gun to smart devices. Black hat USA.

    View in Article Google Scholar

    [104] Ji X., Cheng Y., Zhang Y., et al. (2021). Poltergeist: Acoustic adversarial machine learning against cameras and computer vision. IEEE symposium on security and privacy (s&p) 160−175. DOI:10.1109/sp40001.2021.00091

    View in Article CrossRef Google Scholar

    [105] Dey V., Pudi V., Chattopadhyay A., et al. (2018). Security vulnerabilities of unmanned aerial vehicles and countermeasures: An experimental study. International conference on VLSI design 398−403. DOI:10.1109/vlsid.2018.97

    View in Article CrossRef Google Scholar

    [106] John A. Volpe National Transportation Systems Center (2001). Vulnerability assessment of the transportation infrastructure relying on the Global Positioning System. (U.S. Department of Transportation, Office of the Assistant Secretary for Transportation Policy). Available at: https://rosap.ntl.bts.gov/view/dot/8435

    View in Article Google Scholar

    [107] Tippenhauer N. O., Pöpper C., Rasmussen K. B., et al. (2011). On the requirements for successful GPS spoofing attacks. Proceedings of the 18th ACM Conference on Computer and Communications Security 75−86. DOI:10.1145/2046707.2046719

    View in Article CrossRef Google Scholar

    [108] Zeng K., Liu S., Shu Y., et al. (2018). All your GPS are belong to us: Towards stealthy manipulation of road navigation systems. 27th USENIX Security Symposium (USENIX Security 18): 1527–1544.

    View in Article Google Scholar

    [109] Nighswander T., Ledvina B. M., Diamond J., et al. (2012). GPS software attacks. ACM conference on computer and communications security (CCS) 450−461. DOI:10.1145/2382196.2382245

    View in Article CrossRef Google Scholar

    [110] Shen J., Won J. Y., Chen Z., et al. (2020). Drift with devil: Security of Multi-Sensor fusion based localization in High-Level autonomous driving under GPS spoofing. 29th USENIX Security Symposium (USENIX Security 20) (USENIX Association): 931–948.

    View in Article Google Scholar

    [111] Li Y., Wen C., Juefei-Xu F., et al. (2021). Fooling LiDAR perception via adversarial trajectory perturbation. IEEE international conference on computer vision 7898−7907. DOI:10.1109/iccv48922.2021.00780

    View in Article CrossRef Google Scholar

    [112] Tang K., Shen J. and Chen Q. A. (2021). Fooling perception via location: A case of region-of-interest attacks on traffic light detection in autonomous driving. NDSS workshop on automotive and autonomous vehicle security (AutoSec). DOI: 10.14722/autosec.2021.23029

    View in Article Google Scholar

    [113] Dahiya R. S., Metta G., Valle M., et al. (2009). Tactile sensing—from humans to humanoids. IEEE Trans. Robot. 26(1): 1–20. DOI: 10.1109/tro.2009.2033627

    View in Article Google Scholar

    [114] Jiang J. and Luo S. (2022). Robotic perception of object properties using tactile sensing. Tactile sensing, skill learning, and robotic dexterous manipulation (Elsevier), pp. 23–44. DOI: 10.1016/b978-0-32-390445-2.00009-x

    View in Article Google Scholar

    [115] Mittendorfer P. and Cheng G. (2011). Humanoid multimodal tactile-sensing modules. IEEE Trans. Robot. 27(3): 401–410. DOI: 10.1109/tro.2011.2106330

    View in Article Google Scholar

    [116] Tu Y., Rampazzi S. and Hei X. (2022). Towards adversarial control loops in sensor attacks: a case study to control the kinematics and actuation of embedded systems. arXiv. DOI: 10.48550/arXiv.2203.07670

    View in Article Google Scholar

    [117] Shi J., Dai Y., Cheng Y., et al. (2023). Embedment of sensing elements for robust, highly sensitive, and cross-talk–free iontronic skins for robotics applications. Sci. Adv. 9:eadf8831. DOI:10.1126/sciadv.adf8831

    View in Article CrossRef Google Scholar

    [118] Regenscheid A. (2018). Platform firmware resiliency guidelines. (National Institute of Standards and Technology (NIST)). DOI: 10.6028/nist.sp.800-193

    View in Article Google Scholar

    [119] Gandolfi K., Mourtel C. and Olivier F. (2001). Electromagnetic analysis: Concrete results. Cryptographic hardware and embedded systems—CHES 2001: Third international workshop paris, france, may 14–16, 2001 proceedings 3: 251–261. DOI: 10.1007/3-540-44709-1_21

    View in Article Google Scholar

    [120] Kocher P., Jaffe J. and Jun B. (1999). Differential power analysis. Annual international cryptology conference (CRYPTO’99) 388−397. DOI:10.1007/3-540-48405-1_25

    View in Article CrossRef Google Scholar

    [121] Mangard S., Oswald E. and Popp T. (2008). Power analysis attacks: Revealing the secrets of smart cards. (Springer).

    View in Article Google Scholar

    [122] Khuat V., Danger J. L. and Dutertre J. M. (2021). Laser fault injection in a 32-bit micro-controller: from the flash interface to the execution pipeline. 2021 Workshop on fault detection and tolerance in cryptography (FDTC): 74–85. DOI: 10.1109/fdtc53659.2021.00020

    View in Article Google Scholar

    [123] Bhunia S., Hsiao M. S., Banga M., et al. (2014). Hardware Trojan attacks: Threat analysis and countermeasures. Proc. IEEE 102:1229−1247. DOI:10.1109/jproc.2014.2334493

    View in Article CrossRef Google Scholar

    [124] Tehranipoor M. and Koushanfar F. (2010). A survey of hardware trojan taxonomy and detection. IEEE Des. Test. Comput. 27:10−25. DOI:10.1109/mdt.2010.7

    View in Article CrossRef Google Scholar

    [125] Xiao K., Forte D., Jin Y., et al. (2016). Hardware trojans: Lessons learned after one decade of research. ACM Trans. Des. Autom. Electron. Syst. 22:1−23.

    View in Article Google Scholar

    [126] Barenghi A., Breveglieri L., Koren I., et al. (2012). Fault injection attacks on crypto-graphic devices: Theory, practice, and countermeasures. Proc. IEEE 100:3056−3076. DOI:10.1109/jproc.2012.2188769

    View in Article CrossRef Google Scholar

    [127] Qiu P., Wang D., Lyu Y., et al. (2019). Voltjockey: Breaching TrustZone by software-controlled voltage manipulation over multi-core frequencies. ACM SIGSAC conference on computer and communications security (CCS): 195–209.

    View in Article Google Scholar

    [128] Moro N., Dehbaoui A., Heydemann K., et al. (2013). Electromagnetic fault injection: towards a fault model on a 32-bit microcontroller. 2013 Workshop on fault diagnosis and tolerance in cryptography: 77–88. DOI: 10.1109/fdtc.2013.9

    View in Article Google Scholar

    [129] Maggi F., Quarta D., Pogliani M., et al. (2017). Rogue robots: Testing the limits of an industrial robot’s security. (Trend Micro and Politecnico di Milano). Available at: https://documents.trendmicro.com/assets/wp/wp-industrial-robot-security.pdf

    View in Article Google Scholar

    [130] Kasprzyczak L., Manowska A. and Dźwiarek M. (2025). Cybersecurity requirements for industrial machine control systems. Appl. Sci. 15:1267. DOI:10.3390/app15031267

    View in Article CrossRef Google Scholar

    [131] Jiménez Naharro R., Gómez-Bravo F. and López de Ahumada Gutiérrez R. (2025). Exploring hardware vulnerabilities in robotic actuators: A case of man-in-the-middle attacks. Electronics 14:4909. DOI:10.3390/electronics14244909

    View in Article CrossRef Google Scholar

    [132] Sabt M., Achemlal M. and Bouabdallah A. (2015). Trusted execution environment: What it is, and what it is not. 2015 IEEE trustcom/BigDataSE/ispa 1:57−64. DOI:10.1109/trustcom.2015.357

    View in Article CrossRef Google Scholar

    [133] Arbaugh W. A., Farber D. J. and Smith J. M. (1997). A secure and reliable bootstrap architecture. Proceedings. 1997 IEEE symposium on security and privacy (cat. no. 97CB36097) 65−71. DOI:10.1109/secpri.1997.601317

    View in Article CrossRef Google Scholar

    [134] Suh G. E. and Devadas S. (2007). Physical unclonable functions for device authentication and secret key generation. Proceedings of the 44th annual design automation conference 9−14. DOI:10.1145/1278480.1278484

    View in Article CrossRef Google Scholar

    [135] Haldar V., Chandra D. and Franz M. (2004). Semantic remote attestation: A virtual machine directed approach to trusted computing. USENIX virtual machine research and technology symposium 2004.

    View in Article Google Scholar

    [136] Ivanov R., Pajic M. and Lee I. (2016). Attack-resilient sensor fusion for safety-critical cyber-physical systems. ACM Trans. Embed. Comput. Syst. 15:1−24. DOI:10.1145/2847418

    View in Article CrossRef Google Scholar

    [137] Clark S. S., Ransford B., Rahmati A., et al. (2013). WattsUpDoc: Power side channels to nonintrusively discover untargeted malware on embedded medical devices. 2013 USENIX workshop on health information technologies (HealthTech 13).

    View in Article Google Scholar

    [138] Bao C., Forte D. and Srivastava A. (2015). Temperature tracking: Toward robust run-time detection of hardware Trojans. IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst. 34:1577−1585. DOI:10.1109/tcad.2015.2424929

    View in Article CrossRef Google Scholar

    [139] Pan M. C., Van Brussel H. and Sas P. (1998). Intelligent joint fault diagnosis of industrial robots. Mech. Syst. Signal Process. 12:571−588. DOI:10.1006/mssp.1997.0124

    View in Article CrossRef Google Scholar

    [140] Guin U., Huang K., DiMase D., et al. (2014). Counterfeit integrated circuits: A rising threat in the global semiconductor supply chain. Proc. IEEE 102:1207−1228. DOI:10.1109/jproc.2014.2332291

    View in Article CrossRef Google Scholar

    [141] Sun J., Cao Y., Chen Q. A., et al. (2020). Towards robust LiDAR-based perception in autonomous driving: General black-box adversarial sensor attack and countermeasures. 29th USENIX Security Symposium: 877–894.

    View in Article Google Scholar

    [142] Szegedy C., Zaremba W., Sutskever I., et al. (2014). Intriguing properties of neural networks. International conference on learning representations (ICLR) 1−10.

    View in Article Google Scholar

    [143] Goodfellow I. J., Shlens J. and Szegedy C. (2015). Explaining and harnessing adversarial examples. International conference on learning representations (ICLR) 1−11.

    View in Article Google Scholar

    [144] Brown T. B., Mané D., Roy A., et al. (2017). Adversarial patch. arXiv. DOI: 10.48550/arXiv.1712.09665

    View in Article Google Scholar

    [145] Eykholt K., Evtimov I., Fernandes E., et al. (2018). Robust physical-world attacks on deep learning visual classification. Proceedings of the IEEE/CVF conference on computer vision and pattern recognition 1625−1634. DOI:10.1109/cvpr.2018.00175

    View in Article CrossRef Google Scholar

    [146] Eykholt K., Evtimov I., Fernandes E., et al. (2018). Physical adversarial examples for object detectors. 12th USENIX Workshop on Offensive Technologies.

    View in Article Google Scholar

    [147] Mehmood U., Sheikhi S., Bak S., et al. (2022). The black-box simplex architecture for runtime assurance of autonomous CPS. NASA formal methods 231−250. DOI:10.1007/978-3-031-06773-0_12

    View in Article CrossRef Google Scholar

    [148] García J. and Fernández F. (2015). A comprehensive survey on safe reinforcement learning. J. Mach. Learn. Res. 16:1437−1480.

    View in Article Google Scholar

    [149] Achiam J., Held D., Tamar A., et al. (2017). Constrained policy optimization. Proceedings of the 34th International Conference on Machine Learning: 22–31.

    View in Article Google Scholar

    [150] Dalal G., Dvijotham K., Vecerik M., et al. (2018). Safe exploration in continuous action spaces. arXiv. DOI: 10.48550/arXiv.1801.08757

    View in Article Google Scholar

    [151] Ames A. D., Coogan S., Egerstedt M., et al. (2019). Control barrier functions: Theory and applications. 2019 18th European Control Conference 3420−3431. DOI:10.23919/ecc.2019.8796030

    View in Article CrossRef Google Scholar

    [152] Moulard T., Hortala J., Perez X., et al. (2019). ROS 2 Robotic Systems Threat Model. Available at: https://design.ros2.org/articles/ros2_threat_model.html

    View in Article Google Scholar

    [153] Open Robotics (2020). ROS 2 security enclaves. (Open Robotics). Available at: https://design.ros2.org/articles/ros2_security_enclaves.html

    View in Article Google Scholar

    [154] DiLuoffo V., Michalson W. R. and Sunar B. (2018). Robot operating system 2: The need for a holistic security approach to robotic architectures. Int. J. Adv. Robot. Syst. 15:1−15. DOI:10.1177/1729881418770011

    View in Article CrossRef Google Scholar

    [155] Deng G., Xu G., Zhou Y., et al. (2022). On the (In)Security of secure ROS2. Proceedings of the 2022 ACM SIGSAC conference on computer and communications security 739−753. DOI:10.1145/3548606.3560681

    View in Article CrossRef Google Scholar

    [156] Pandya N. V., Kumar H., Pillai G. M., et al. (2024). Decentralized information-flow control for ROS2. 31st Annual Network and Distributed System Security Symposium (NDSS 2024) (Internet Society): 1–18. DOI: 10.14722/ndss.2024.24101

    View in Article Google Scholar

    [157] Jiao R., Xie S., Yue J., et al. (2025). Can we trust embodied agents? Exploring back-door attacks against embodied LLM-based decision-making systems. The thirteenth international conference on learning representations (ICLR 2025) (ICLR). DOI: 10.48550/arXiv.2405.20774

    View in Article Google Scholar

    [158] OWASP Foundation (2025). OWASP top 10 for large language model applications. (OWASP Foundation). Available at: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/

    View in Article Google Scholar

    [159] MITRE (2026). MITRE ATLAS: Adversarial threat landscape for artificial-intelligence systems. (MITRE). Available at: https://atlas.mitre.org/

    View in Article Google Scholar

    [160] European Parliament and Council of the European Union (2024). Regulation (EU) 2024/1689: Artificial intelligence act. (Publications Office of the European Union). Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

    View in Article Google Scholar

    [161] International Society of Automation (2026). ISA/IEC 62443 series of standards: Security for industrial automation and control systems. (International Society of Automation). Available at: https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards

    View in Article Google Scholar

    [162] Hu H., Salcic Z., Sun L., et al. (2022). Membership inference attacks on machine learning: A survey. ACM Comput. Surv. 54:1−37. DOI:10.1145/3523273

    View in Article CrossRef Google Scholar

    [163] Li M., Ding W. and Zhao D. (2024). Privacy risks in reinforcement learning for house-hold robots. IEEE international conference on robotics and automation (ICRA) 5148−5154. DOI:10.1109/icra57147.2024.10610832

    View in Article CrossRef Google Scholar

    [164] Dietrich M., Krüger M. and Weisswange T. H. (2023). What should a robot disclose about me? A study about privacy-appropriate behaviors for social robots. Front. Robot. AI 10:1236733. DOI:10.3389/frobt.2023.1236733

    View in Article CrossRef Google Scholar

    [165] Stapels J. G., Penner A., Diekmann N., et al. (2023). Never trust anything that can think for itself if you can’t control its privacy settings: The influence of a robot’s privacy settings on users’ attitudes and willingness to self-disclose. Int. J. Soc. Robot. 15:1487−1505. DOI:10.1007/s12369-023-01043-8

    View in Article CrossRef Google Scholar

    [166] Su H., Cui Y., Santina C. D., et al. (2026). Embodied AI: Bridging robotics and AI toward real-world applications [from the guest editors]. IEEE Robot. Autom. Mag. 33:6−7. DOI:10.1109/mra.2026.3653534

    View in Article CrossRef Google Scholar

    [167] Nazarczuk M., Behrens J. K., Stepanova K., et al. (2025). Closed loop interactive embodied reasoning for robot manipulation. 2025 IEEE international conference on robotics and automation (ICRA) 13722−13729. DOI:10.1109/icra55743.2025.11127480

    View in Article CrossRef Google Scholar

    [168] Gurdur Broo D. (2026). Physical AI in cyber-physical systems: from digital to embodied industrial agents. J. Ind. Inf. Integr. 49:101038. DOI:10.1016/j.jii.2025.101038

    View in Article CrossRef Google Scholar

    [169] Firoozi R., Tucker J., Tian S., et al. (2025). Foundation models in robotics: Applications, challenges, and the future. Int. J. Robot. Res. 44:701−739. DOI:10.1177/02783649241281508

    View in Article CrossRef Google Scholar

    [170] Hu T., Gong Z., Kong L., et al. (2026). NavThinker: Action-conditioned world models for coupled prediction and planning in social navigation. arXiv. DOI: 10.48550/arXiv.2603.15359

    View in Article Google Scholar

    [171] Gemini Robotics Team, Abeyruwan S., Ainslie J., et al. (2025). Gemini robotics: Bringing AI into the physical world. arXiv. DOI: 10.48550/arXiv.2503.20020

    View in Article Google Scholar

    [172] Ma Y., Song Z., Zhuang Y., et al. (2024). A survey on vision-language-action models for embodied AI. arXiv. DOI: 10.48550/arXiv.2405.14093

    View in Article Google Scholar

    [173] Kojima T., Zhu Y., Iwasawa Y., et al. (2025). A comprehensive survey on physical risk control in the era of foundation model-enabled robotics. arXiv. DOI: 10.48550/arXiv.2505.12583

    View in Article Google Scholar

    [174] Xing W. and Shen J. (2024). Security control of cyber–physical systems under cyber attacks: A survey. Sensors 24:3815. DOI:10.3390/s24123815

    View in Article CrossRef Google Scholar

    [175] Deng Y., Wu T., Wu D., et al. (2026). Efficient coordination with the system-level shared state: An embodied-AI native modular framework. arXiv. DOI: 10.48550/arXiv.2601.13945

    View in Article Google Scholar

    [176] Xie M. and Wei-Kocsis J. (2026). From prompt to physical action: Structured backdoor attacks on LLM-mediated robotic control systems. arXiv. DOI: 10.48550/arXiv.2604.03890

    View in Article Google Scholar

    [177] Li A., Wang J., Baruah S., et al. (2024). An empirical study of performance interference: Timing violation patterns and impacts. 2024 IEEE 30th Real-Time and Embedded Technology and Applications Symposium (RTAS) 320−333. DOI:10.1109/rtas61025.2024.00033

    View in Article CrossRef Google Scholar

    [178] Hsiao Y. P., Li Y., Gamal Y., et al. (2026). Glitch in the sky: Exploiting voltage fault injection in UAV flight controllers. arXiv. DOI: 10.48550/arXiv.2604.16699

    View in Article Google Scholar

    [179] Banerjee D., Tan C. M. and Baruah N. A. (2024). Application of component failure physics for the reliability assessment of an autonomous braking system. Sci. Rep. 14:28835. DOI:10.1038/s41598-024-80476-1

    View in Article CrossRef Google Scholar

    [180] Liu Z., Shanmugam D. and Schaumont P. (2024). FaultDetective: Explainable to a fault, from the design layout to the software. IACR Trans. Cryptogr. Hardw. Embed. Syst. 2024:610−632.

    View in Article Google Scholar

    [181] Liu J., Li H., Wang H., et al. (2025). TimeTravel: Real-time timing drift attack on system time using acoustic waves. 34th USENIX Security Symposium (USENIX Security 25) 3885−3902.

    View in Article Google Scholar

    [182] Fan W., Lane J., Liu Q., et al. (2024). Incorporating System-level Safety Requirements in Perception Models via Reinforcement Learning. arXiv. DOI: 10.48550/arXiv.2412.02951

    View in Article Google Scholar

    [183] Huang Y., Hao Y., Yu B., et al. (2025). DaDu-Corki: Algorithm-architecture co-design for embodied AI-powered robotic manipulation. Proceedings of the 52nd Annual International Symposium on Computer Architecture (ISCA ’25) (ACM): 327–343. DOI: 10.1145/3695053.3731099

    View in Article Google Scholar

    [184] Xie T., Qi Y., Wen J., et al. (2026). CREATE: Cross-layer resilience characterization and optimization for efficient yet reliable embodied AI systems. Proceedings of the 31st ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2: 493–510.

    View in Article Google Scholar

    [185] Sato T., Suzuki R., Hayakawa Y., et al. (2025). On the realism of LiDAR spoofing attacks against autonomous driving vehicle at high speed and long distance. Network and distributed system security symposium (NDSS). DOI: 10.14722/ndss.2025.230628

    View in Article Google Scholar

    [186] Sadeghi J., Lord N. A., Redford J., et al. (2023). Attacking motion planners using adversarial perception errors. arXiv. DOI: 10.48550/arXiv.2311.12722

    View in Article Google Scholar

    [187] Wu W., Pierazzi F., Du Y., et al. (2024). Characterizing physical adversarial attacks on robot motion planners. 2024 IEEE international conference on robotics and automation (ICRA) 14319−14325. DOI:10.1109/icra57147.2024.10610344

    View in Article CrossRef Google Scholar

    [188] Mayoral-Vilches V., Carbajo U. A. and Gil-Uriarte E. (2020). Industrial robot ransomware: Akerbeltz. 2020 Fourth IEEE international conference on robotic computing (IRC) 432−435. DOI:10.1109/irc.2020.00080

    View in Article CrossRef Google Scholar

    [189] Pu H., He L., Cheng P., et al. (2024). CORMAND2: A deception attack against industrial robots. Engineering 32:186−201. DOI:10.1016/j.eng.2023.01.013

    View in Article CrossRef Google Scholar

    [190] Dieber B., Kacianka S., Rass S., et al. (2016). Application-level security for ROS-based applications. 2016 IEEE/RSJ international conference on intelligent robots and systems (IROS) 4477−4482. DOI:10.1109/iros.2016.7759659

    View in Article CrossRef Google Scholar

    [191] DeMarinis N., Tellex S., Kemerlis V. P., et al. (2019). Scanning the internet for ros: A view of security in robotics research. 2019 International conference on robotics and automation (ICRA) 8514−8521. DOI:10.1109/icra.2019.8794451

    View in Article CrossRef Google Scholar

    [192] Chung K., Li X., Tang P., et al. (2019). Smart Malware that Uses Leaked Control Data of Robotic Applications: The Case of Raven-Ⅱ Surgical Robots. 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019) (USENIX Association): 337–351. Available at: https://www.usenix.org/conference/raid2019/presentation/chung

    View in Article Google Scholar

    [193] Puccetti T., Nardi S., Cinquilli C., et al. (2024). ROSPaCe: Intrusion detection dataset for a ROS2-based cyber-physical system and IoT networks. Sci. Data 11:481. DOI:10.1038/s41597-024-03311-2

    View in Article CrossRef Google Scholar

    [194] Mayoral-Vilches V., Pinzger M., Rass S., et al. (2020). Can ROS be used securely in industry? Red teaming ROS-industrial. arXiv. DOI: 10.48550/arXiv.2009.08211

    View in Article Google Scholar

    [195] Qureshi A., Marvi M., Shamsi J. A., et al. (2022). eUF: A framework for detecting over-the-air malicious updates in autonomous vehicles. J. King Saud Univ. Comput. Inf. Sci. 34:5456−5467. DOI:10.1016/j.jksuci.2021.05.005

    View in Article CrossRef Google Scholar

    [196] Mocnik R., Fowler D. S. and Maple C. (2023). Vehicular over-the-air software upgrade threat modelling. Cenex-LCV and cenex-CAM 2023. Available at: https://wrap.warwick.ac.uk/179188/

    View in Article Google Scholar

    [197] Mayoral-Vilches V., Ayucar-Carbajo U., Laflamme O., et al. (2026). Cybersecurity AI: Hacking consumer robots in the AI era. arXiv. DOI: 10.48550/arXiv.2603.08665

    View in Article Google Scholar

    [198] Wang X., Pan H., Zhang H., et al. (2024). Robot Collapse: Supply Chain Backdoor Attacks Against VLM-based Robotic Manipulation. arXiv. DOI: 10.48550/arXiv.2411.11683

    View in Article Google Scholar

    [199] Zhou X., Tie G., Zhang G., et al. (2025). BadVLA: Towards backdoor attacks on vision-language-action models via objective-decoupled optimization. arXiv. DOI: 10.48550/arXiv.2505.16640

    View in Article Google Scholar

    [200] Burbano L., Ortiz D., Sun Q., et al. (2025). CHAI: Command Hijacking against embodied AI. arXiv. DOI: 10.48550/arXiv.2510.00181

    View in Article Google Scholar

    [201] Geng T., Qu Y. and Wong W. E. (2026). A white-box prompt injection attack on embodied AI agents driven by large language models. J. Syst. Softw. 235:112782. DOI:10.1016/j.jss.2026.112782

    View in Article CrossRef Google Scholar

    [202] Qin X., Luan S., See J., et al. (2026). Harnessing embodied agents: Runtime governance for policy-constrained execution. arXiv. DOI: 10.48550/arXiv.2604.07833

    View in Article Google Scholar

    [203] Onik A. R., Alsmadi R., Baggili I., et al. (2024). So fresh, so clean: Cloud forensic analysis of the Amazon iRobot Roomba vacuum. Forensic Sci. Int. Digit. Investig. 48:301686. DOI:10.1016/j.fsidi.2023.301686

    View in Article CrossRef Google Scholar

    [204] Ulsmg B., Lin J. C. and Lee M. C. (2024). Investigating the privacy risk of using robot vacuum cleaners in smart environments. International conference on information and communications security 312−330. DOI:10.1007/978-981-97-8798-2_16

    View in Article CrossRef Google Scholar

    [205] Yang M., Huang C., Huang X., et al. (2025). Privacy-preserved visual simultaneous localization and mapping based on a dual-component approach. Appl. Sci. 15:2583. DOI:10.3390/app15052583

    View in Article CrossRef Google Scholar

    [206] Ravichandran Z., Robey A., Kumar V., et al. (2026). Safety guardrails for LLM-enabled robots. IEEE Robot. Autom. Lett. 11:4649−4656. DOI:10.1109/lra.2026.3667488

    View in Article CrossRef Google Scholar

    [207] Huang X., Zhang R., Cheng L., et al. (2026). LLM-guided safety agent for edge robotics with an ISO-compliant perception-compute-control architecture. arXiv. DOI: 10.48550/arXiv.2604.20193

    View in Article Google Scholar

    [208] Obi I., Venkatesh V. L., Wang W., et al. (2026). Pre-execution safety gate & task safety contracts for LLM-controlled robot systems. arXiv. DOI: 10.48550/arXiv.2604.05427

    View in Article Google Scholar

    [209] Liu J., Corbett-Davies J., Ferraiuolo A., et al. (2018). Secure autonomous cyber-physical systems through verifiable information flow control. Proceedings of the 2018 workshop on cyber-physical systems security and PrivaCy 48−59. DOI:10.1145/3264888.3264889

    View in Article CrossRef Google Scholar

    [210] Astorga A., Hsieh C., Madhusudan P., et al. (2023). Perception contracts for safety of ML-enabled systems. Proc. ACM Program. Lang. 7:2196−2223. DOI:10.1145/3622875

    View in Article CrossRef Google Scholar

    [211] Zhan S. S., Wang P., Liu Y., et al. (2025). SENTINEL: A Multi-Level Formal Framework for Safety Evaluation of Foundation Model-based Embodied Agents. arXiv. DOI: 10.48550/arXiv.2510.12985

    View in Article Google Scholar

    [212] Yu D., Shi J., Ren J., et al. (2025). Enhancing security in embodied intelligence: Attack detection via constraint functions. International conference on algorithms and architectures for parallel processing 96−110. DOI:10.1007/978-981-95-8417-8_8

    View in Article CrossRef Google Scholar

    [213] Choi H., Lee W. C., Aafer Y., et al. (2018). Detecting attacks against robotic vehicles: A control invariant approach. Proceedings of the 2018 ACM SIGSAC conference on computer and communications security 801−816. DOI:10.1145/3243734.3243752

    View in Article CrossRef Google Scholar

    [214] Hobbs K. L., Mote M. L., Abate M. C., et al. (2023). Runtime assurance for safety-critical systems: An introduction to safety filtering approaches for complex control systems. IEEE Control Syst. 43:28−65. DOI:10.1109/mcs.2023.3234380

    View in Article CrossRef Google Scholar

    [215] Hsu K. C., Hu H. and Fisac J. F. (2024). The safety filter: A unified view of safety-critical control in autonomous systems. Annu. Rev. Control Robot. Auton. Syst. 7:47−72. DOI:10.1146/annurev-control-071723-102940

    View in Article CrossRef Google Scholar

    [216] Schilliger J., Lew T., Richards S. M., et al. (2021). Control barrier functions for cyber-physical systems and applications to NMPC. IEEE Robot. Autom. Lett. 6:8623−8630. DOI:10.1109/lra.2021.3111010

    View in Article CrossRef Google Scholar

    [217] Knoedler L., So O., Yin J., et al. (2025). Safety on the fly: Constructing robust safety filters via policy control barrier functions at runtime. IEEE Robot. Autom. Lett. 10:10058−10065. DOI:10.1109/lra.2025.3597847

    View in Article CrossRef Google Scholar

    [218] Zhang Z., Lei L., Wu L., et al. (2024). SafetyBench: Evaluating the safety of large language models. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) 15537−15553. DOI:10.18653/v1/2024.acl-long.830

    View in Article CrossRef Google Scholar

    [219] Zhu Z., Wu B., Zhang Z., et al. (2024). EARBench: Towards evaluating physical risk awareness for task planning of foundation model-based embodied AI agents. arXiv. DOI: 10.48550/arXiv.2408.04449

    View in Article Google Scholar

    [220] Sun Q., Chi X., Rui Y., et al. (2026). LABSHIELD: A multimodal benchmark for safety-critical reasoning and planning in scientific laboratories. arXiv. DOI: 10.48550/arXiv.2603.11987

    View in Article Google Scholar

    [221] Lu X., Chen Z., Hu X., et al. (2026). IS-Bench: Evaluating interactive safety of VLM-driven embodied agents in daily household tasks. Proceedings of the AAAI conference on artificial intelligence 40:35680−35688. DOI:10.1609/aaai.v40i42.40880

    View in Article CrossRef Google Scholar

    [222] Tomilin T., Fang M. and Pechenizkiy M. (2025). HASARD: A benchmark for vision-based safe reinforcement learning in embodied agents. The thirteenth international conference on learning representations.

    View in Article Google Scholar

    [223] Fei S., Wang S., Shi J., et al. (2025). Libero-Plus: In-depth robustness analysis of vision-language-action models. arXiv. DOI: 10.48550/arXiv.2510.13626

    View in Article Google Scholar

    [224] Huang Y., Wang Z., Wan Z., et al. (2025). Annie: Be careful of your robots. arXiv. DOI: 10.48550/arXiv.2509.03383

    View in Article Google Scholar

    [225] Huang Y., Ding L., Tang Z., et al. (2025). A framework for benchmarking and aligning task-planning safety in LLM-based embodied agents. arXiv. DOI: 10.48550/arXiv.2504.14650

    View in Article Google Scholar

    [226] Advanced Technology Exploration Community (2026). ATEC2026: The real-world ex-treme challenge competition for embodied intelligence. (Advanced Technology Exploration Community). Available at: https://www.atecup.com/competitions/ATEC2026

    View in Article Google Scholar

    [227] DARKNAVY (2026). Embodied AI security technology white paper: Robotics chapter. (DARKNAVY). Available at: https://www.darknavy.org/zh/blog/embodied-ai-security-humanoid-robots/

    View in Article Google Scholar

    [228] Man Y., Muller R., Li M., et al. (2023). That person moves like a car: Misclassification attack detection for autonomous systems using spatiotemporal consistency. 32nd USENIX Security Symposium (USENIX Security 23) (USENIX Association): 6929–6946. Available at: https://www.usenix.org/conference/usenixsecurity23/presentation/man

    View in Article Google Scholar

    [229] Cao Y., Bhupathiraju S. H., Naghavi P., et al. (2023). You Can’t See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks. 32nd USENIX Security Symposium (USENIX Security 23) (USENIX Association): 2993–3010. Available at: https://www.usenix.org/conference/usenixsecurity23/presentation/cao .

    View in Article Google Scholar

    [230] Xiao Q., Pan X., Lu Y., et al. (2023). Exorcising “Wraith”: Protecting LiDAR-based Object Detector in Automated Driving System from Appearing Attacks. 32nd USENIX Security Symposium (USENIX Security 23) (USENIX Association): 2939–2956. Available at: https://www.usenix.org/conference/usenixsecurity23/presentation/xiao-qifan .

    View in Article Google Scholar

    [231] Sathaye H., LaMountain G., Closas P., et al. (2022). SemperFi: Anti-spoofing GPS receiver for UAVs. Network and distributed system security symposium (NDSS 2022) (Internet Society). DOI: 10.14722/ndss.2022.23071

    View in Article Google Scholar

    [232] Jeong J., Kim D., Jang J. H., et al. (2023). Un-Rocking Drones: Foundations of acoustic injection attacks and recovery thereof. Network and distributed system security symposium (NDSS 2023) (Internet Society). DOI: 10.14722/ndss.2023.24112

    View in Article Google Scholar

    [233] Ding A., Murthy P., Garcia L., et al. (2021). Mini-Me, You Complete Me! Data-Driven Drone Security via DNN-based Approximate Computing. Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses (RAID) (Association for Computing Machinery): 428–441. DOI: 10.1145/3471621.3471869

    View in Article Google Scholar

    [234] Sciangula G., Casini D., Biondi A., et al. (2023). Bounding the Data-Delivery Latency of DDS Messages in Real-Time Applications. Papadopoulos A. V. (ed). 35th Euromicro Conference on Real-Time Systems (ECRTS 2023) (Schloss Dagstuhl – Leibniz-Zentrum für Informatik), Leibniz International Proceedings in Informatics (LIPIcs) 262: 9: 1-9: 26. DOI: 10.4230/LIPIcs.ECRTS.2023.9

    View in Article Google Scholar

    [235] Gu Q., Ju Y., Sun S., et al. (2025). SAFE: Multitask failure detection for vision-language-action models. Adv. Neural Inf. Process. Syst. 38. DOI:10.48550/arXiv.2506.09937

    View in Article Google Scholar

    [236] Zhang B., Zhang Y., Ji J., et al. (2025). SafeVLA: Towards safety alignment of vision-language-action model via constrained learning. Adv. Neural Inf. Process. Syst. 38. Available at: https://neurips.cc/virtual/2025/loc/san-diego/poster/116975

    View in Article Google Scholar

    [237] Ichnowski J., Chen K., Dharmarajan K., et al. (2023). FogROS2: An adaptive platform for cloud and fog robotics using ROS 2. IEEE international conference on robotics and automation, ICRA 2023, London, UK, May 29 - June 2, 2023 (IEEE): 5493–5500. DOI: 10.1109/ICRA48891.2023.10161307

    View in Article Google Scholar

  • Cite this article:

    Feng T., Zhang Y., Zhou S., et al. (2026). From bits to atoms: A survey of cross-layer safety in Embodied AI. AI Plus 1:100013. https://doi.org/10.59717/ipj.aiplus.2026.100013
    Feng T., Zhang Y., Zhou S., et al. (2026). From bits to atoms: A survey of cross-layer safety in Embodied AI. AI Plus 1:100013. https://doi.org/10.59717/ipj.aiplus.2026.100013

Welcome!

To request copyright permission to republish or share portions of our works, please visit Copyright Clearance Center's (CCC) Marketplace website at marketplace.copyright.com.

Figures(5)     Tables(4)

Supplementary Information

Share

  • Share the QR code with wechat scanning code to friends and circle of friends.

Article Metrics

Article views(152) PDF downloads(28)

Relative Articles

Cited by

Catalog

    /

    DownLoad:  Full-Size Img  PowerPoint