
What happened
VicOne highlights NeurIPS 2025's BadVLA, which caused conditional deviations in a Vision-Language-Action robot's action trajectory when a hidden trigger appeared, plus 2025's GoBA, which used ordinary objects like a coffee mug as a trigger with a reported 97 percent attack success rate.
Why it matters
These results suggest a robot can pass testing and then behave abnormally when a hidden trigger shows up in operation, so conventional functional-safety checks may not catch deliberate manipulation, according to VicOne.
What to watch
VicOne says assurance needs to cover the robot's whole lifecycle, from design through deployment and operation, and points to tools like VicOne Radeis with NVIDIA Isaac Sim; the test is whether such validation catches real attacks before fleets are deployed.
WHO IT HITSRobotics and operational-safety teams at manufacturers deploying Vision-Language-Action robots, and the security engineers who validate them, are the ones who would need to add adversarial-input testing and continuous monitoring to their existing functional-safety processes.
Summaries like this, in your inbox every morning.
The article walks through three distinct attack layers that place robot safety in a different category from traditional functional safety. Layer one targets the model itself through hidden triggers, as seen in BadNets, BadVLA, and GoBA. Layer two exploits system-level vulnerabilities, illustrated by UniPwn's Bluetooth chain and weaknesses in ROS 2 and DDS middleware. Layer three manipulates perception and reasoning at runtime, with techniques like RoboPAIR, BadRobot, VLAttack, and FreezeVLA, where the camera and controller may function normally while the behavior becomes unsafe.
Across all three, the common thread is that components can appear to operate as designed while the resulting action is unsafe. VicOne argues this is exactly the gap that cybersecurity needs to fill alongside functional safety, because functional safety addresses failures and unexpected conditions but not deliberate manipulation. The proposed answer is assurance across the entire lifecycle: design, pre-deployment testing, and continuous monitoring.
Whether this approach takes hold may depend on how quickly robot makers adopt adversarial testing and whether tools like Radeis prove they can catch attacks before deployment. For teams already running or procuring robots in logistics, manufacturing, or service roles, the practical question is likely to be who owns the security of the perception-to-action path, not just the reliability of the hardware.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
In a post on X and other social platforms, Meta CEO Mark Zuckerberg said labs that fail to "focus on alignment…

Cisco President Jeetu Patel said on CNN that AI guardrails must progress at the same speed as AI itself

Nvidia CEO Jensen Huang told Salesforce's Dreamforce conference that AI is just hardware and software built by…

OpenAI says it is working with Anthropic and Google on AI safety, according to Bloomberg

In a "Mad Money" interview from Salesforce's Dreamforce event, CEO Marc Benioff said social media hurt compani…

CrowdStrike unveiled SafeMind, built with Nvidia, at its Fal.Con event
