Security Researchers Demonstrate How Manipulated Inputs Can Compromise Robot Safety Systems

Research from VicOne LAB R7 reveals that robots can follow their safety protocols while acting on falsified sensor data or crafted inputs, potentially creating safety vulnerabilities. Tests showed that adversarial visual inputs and inaudible audio could alter robot behavior in tasks ranging from mobile robots to service robots without triggering safety interventions. The findings highlight that protective systems relying on potentially compromised inputs may fail to prevent dangerous actions, requiring stronger validation methods.
Researchers at VicOne LAB R7 tested how robots interpret their sensory inputs to make decisions. In multiple experiments, they showed that false information—whether visual elements in a camera's field of view, inaudible audio frequencies, or text in the robot's environment—could redirect a robot toward unintended actions. Crucially, the robots continued operating within their programmed safety guidelines even while responding to these manipulated signals.
The core vulnerability lies in how protective systems are designed. Safety mechanisms typically monitor the same sensor data that guides a robot's primary tasks. If an attacker can compromise that shared information source, both the robot's behavior and its safety interventions respond to the falsehood. This differs from accidental sensor failures, which safety teams often treat as rare events; deliberate manipulation can be repeated reliably, transforming low-probability risks into reproducible attack scenarios.
These findings could reshape how robotics teams evaluate safety systems, particularly as robots move into shared human spaces like hospitals, factories, and service environments. Manufacturers and deployers may need to reconsider whether current testing standards adequately address adversarial input scenarios alongside traditional fault analysis. The implications extend to sectors relying on autonomous systems for critical tasks, potentially prompting stricter validation requirements before deployment in safety-sensitive applications.