VicOne Tackles Stealthy Backdoor Attacks on AI Robots
Cybersecurity firm VicOne has warned that stealthy backdoor attacks can manipulate physical AI systems, requiring a shift from traditional safety testing to continuous threat monitoring.

As artificial intelligence drives robotic decision-making, cybersecurity firm VicOne warns that traditional functional safety is no longer sufficient. Modern robots operating on Vision-Language-Action (VLA) models face stealthy exploits that alter physical behavior without triggering obvious system failures. To address this, the company advocates for a lifecycle-based security approach combining simulation-based validation, vulnerability scanning, and runtime monitoring.
Recent research highlights the severity of these threats. At NeurIPS 2025, researchers introduced BadVLA, a backdoor attack manipulating a robot's physical trajectory via specific triggers. Another 2025 study, GoBA, demonstrated a 97 percent attack success rate using everyday objects like a coffee mug as triggers, without degrading normal performance. Beyond models, system-level exploits like the September 2025 UniPwn Bluetooth exploit chain bypass authentication on quadruped and humanoid robots. Vulnerabilities in ROS 2 and DDS-based middleware also allow attackers to inject malicious commands. In demonstrations by VicOne LAB R7, chaining three wireless exploits triggered uncontrolled robot behavior within 60 seconds.
Runtime perception is also vulnerable. The RoboPAIR exploit in 2024 showed that structured prompts could redirect LLM-controlled robots, while the BadRobot vulnerability caused machines to execute dangerous actions even after verbally refusing them. Additionally, VLAttack uses adversarial patches to reduce VLA task success rates to zero, and FreezeVLA freezes decision-making loops with a single image. To counter these risks, practitioners can use simulation tools like NVIDIA Isaac Sim paired with VicOne Radeis, a physical AI safety validator designed to test how adversarial visual inputs impact robot behavior.
For robotics practitioners, these developments redefine safety. Engineers can no longer assume a robot is safe simply because its hardware is functioning. Instead, they must implement continuous monitoring to detect when cyber events degrade physical behavior. By integrating security event correlation and policy-bounded responses, developers can isolate compromised pathways and maintain fleet-wide safety without halting operations entirely.
This is our own summary of reporting by IEEE Spectrum AI



