Originally published by:The Robot Report
M4S Take

Live proof at a bug bounty: VicOne LAB R7 researchers injected a ROS 2/DDS message into a robot expected to remain still under a safe-control setting — the robot moved.

  • Manipulated inputs, real risk: Faults or deliberate manipulation can cause a mismatch between a robot's response and the actual situation, even when safety functions work as designed.
  • Demonstrated behavior changes: In a robot-dog test using Gemma 4 E4B, poster text was treated as an instruction and altered movement; crafted audio changed a hospital-service-robot simulation running Nemotron on NVIDIA Jetson AGX Orin.
  • Acoustic attack precedent: Researchers demonstrated acoustic attacks against drones with vulnerable gyroscopes; a humanoid's balance controller relying on such a sensor could correct for a tilt that never occurred, though that full chain was not demonstrated.
  • Guidance for safety teams: Safety and security teams must verify that protections detect danger independently, adversarially test redundant sensors, and revisit evidence as robots change — work supported by VicOne LAB R7 through the Robotic Hacking Community, Radeis, and Rthena.

A robot's safety functions can work exactly as designed — and still fail the people around them. That is the uncomfortable premise behind research from VicOne LAB R7, which examines how manipulated inputs can change robot behavior and what that means for the systems meant to keep people safe.

The scenario engineers already know

"A mobile robot slows for someone in a hallway. A collaborative arm eases its movement as a worker approaches. A humanoid pauses to let a person pass."

Each of these responses feels reassuring. But each one is only as trustworthy as the data behind it.

"Each response depends on information about the robot or its surroundings: a distance reading, a position estimate, or a stop signal."

So what if that data is wrong? A fault can cause a mismatch between the robot's response and the actual situation. So can deliberate manipulation. The robot behaves correctly according to its rules — it simply acts on a lie.

How untrusted inputs change behavior

"A robot does more than measure its surroundings. It may interpret what it sees and hears to decide what to do next."
"Information placed in its environment can therefore influence its actions."

Published research shows how this can happen. In a study of vision-language-action (VLA) models, a patch in a camera's view reduced task success in simulated robot tests. Separately, FreezeVLA found that an adversarial image could cause tested models to ignore later instructions. The methods differed; the lesson is the same. Visual input can interfere with a robot's intended task.

VicOne LAB R7 also tested how untrusted inputs could change robot behavior, with two telling demonstrations:

  • In a robot-dog test using Gemma 4 E4B, text on a poster was treated as an instruction and changed the robot's movement.
  • In a separate hospital-service-robot simulation using Nemotron on NVIDIA Jetson AGX Orin, crafted audio changed the robot's simulated behavior.
"The assigned tasks did not change; the inputs did."

A live demonstration: the robot that moved

The sharpest evidence came at a robotics bug bounty event, where VicOne LAB R7 researchers injected a ROS 2/DDS message into a robot that organizers expected to remain still under a safe-control setting.

"The robot moved."

A humanoid's balance controller offers another example. If it relies on a vulnerable gyroscope, sound at the sensor's resonant frequency could distort its reported rotation — and the controller might correct for a tilt that never occurred. Researchers demonstrated the underlying acoustic attack against drones with vulnerable gyroscopes. To be precise: the research did not demonstrate the same attack chain causing a humanoid to fall. Other protections could interrupt either chain.

That precision matters, and so does the follow-up question.

"The question for safety and security teams is whether those protections detect the danger independently or depend on the same manipulated information."

Testing the assumptions, not just the functions

For manufacturing and robotics professionals, the practical takeaway is not that safety functions are broken. It is that the evidence behind them needs an adversarial dimension. Safety and security teams need to assess whether protections detect the danger independently or depend on the same manipulated information. Redundant sensors, in particular, need an adversarial test to ensure their agreement offers genuine reassurance — if one action can mislead several inputs at once, their agreement may mean less than expected.

VicOne LAB R7 pursues this work with researchers through the Robotic Hacking Community, investigating how cyber threats can change robot behavior.

The engineering discipline here is familiar: trace every input behind a protective decision, challenge it, and revisit the evidence as the system changes. What is new is the adversary.

SM

Simon Morton

Editor, M4SNews

With a background in heavy engineering, process engineering, digital marketing & AI. My mission, to cut through the news and make it easy to digest.

M4SNews marks eighteen years of independent operation, connecting manufacturers and engineers with the intelligence that actually matters on the factory floor.

Is this your company?

This article features your business. Claim it to add your logo, contact details, and a link to your website — or upgrade to reach more buyers.

Did you know 80% of Press Releases trigger AI content warnings? Reach out and the M4S team can assist.