Cybersecurity RoboticsRobot cybersecurity research lab

Publications & research notes

The lab's research on robot cybersecurity — foundational papers transcribed in full, each linking to the original, plus field notes from the lab's disclosure work.

Robot security is not one problem but a stack of them. Every layer — from the senses, up through the ROS graph, the AI reasoning loop and the fleet cloud — is its own attack surface, and each ends in the same place: actuation, and physical harm. This map indexes the lab's research by layer.

Paper · 2026

Certifying Ghosts: How Cybersecurity AI Agents Break the EU Cyber Resilience Act

The EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) makes a smart bet: it does not demand that products be free of vulnerabilities, a promise no software can keep, but only that manufacturers run a process — assess risk,…
CYBERSECURITY AI AGENTS load the four premises the CRA rests onP1discovery is human-scarceP2posture knowable at shipP3exploitation is rareP4fixes keep paceBENDSunder volume · P1re-centres on documented prioritisationstrained, but it holdsBREAKSunder speed & economics · P2 P3 P4a conformant product turns exploitable, untouchedthe certificate is false
Visual summaryThe CRA process bends under vulnerability volume but breaks when AI collapses the speed and economics of the vulnerability lifecycle.
Paper · 2026

Cybersecurity AI: Hacking Consumer Robots in the AI Era

Is robot cybersecurity broken by AI? Consumer robots -- from autonomous lawnmowers to powered exoskeletons and window cleaners -- are rapidly entering homes and workplaces, yet their security remains rooted in assumptions of…
Consumer Robot Security AI · months compressed into hoursspecialist researchmonths of expert workCAI3 consumer robots1.5–3 hours each38 vulnerabilitiesautomated discovery
Visual summaryConsumer Robot Security AI assessed three consumer platforms in 1.5 to 3 hours each and identified 38 vulnerabilities—work that previously required months of specialist research.
Thesis · 2025

Offensive Robot Cybersecurity: Cyber-protecting robots by hacking-them-first with Game Theory and Machine Learning

Robots, integral to modern automation and services, encounter formidable cybersecurity challenges, primarily due to their inherent complexity and the lack of vendor accountability for security, shifting the burden to end-users.…
Automationhack-first & autonomous — game theory · ML · the Malism engineCyber-attacking robotsproving it — DDS software · hardware teardown · AkerbeltzBlueprintsthe tools — SROS2 · RobotPerf benchmarking · RobotCore accelerationEthics & landscapethe foundation — the state of the field, surveys & disclosure
Visual summaryThe thesis moves from ethics and defensive blueprints through offensive validation to autonomous robot-security testing.
Paper · 2025

The cybersecurity of a humanoid robot

As humanoids move from demos to deployments, we assess the cybersecurity of a commercial humanoid robot and find encryption flaws and unauthorized telemetry — showing that the newest, most capable robots inherit the field's…
The cybersecurity of a humanoid · encryption and telemetryUnitree G1humanoidFMX protectionstatic Blowfish key exposes one layerPersistent telemetryrobot and sensor state leaves deviceprivacyand trust
Visual summaryThe G1 assessment found a static-key weakness in one layer of its proprietary FMX protection and persistent external telemetry carrying robot and sensor state without explicit consent.
Paper · 2025

Cybersecurity AI: Humanoid Robots as Attack Vectors

We show that a commercial humanoid (Unitree G1) can be repurposed as a surveillance and cyber-operations platform: a mobile sensor suite with network access that an attacker can weaponize against the environments it is invited…
Humanoids as attack vectors · a helper turned platformHumanoidin your spaceSurveillanceLateral movementPhysical actuationData exfiltration
Visual summaryOnce compromised, a humanoid inside a trusted space combines surveillance, data exfiltration, lateral network access and physical mobility in one attack platform.
Paper · 2025

CAI: An Open, Bug Bounty-Ready Cybersecurity AI

By 2028 most cybersecurity actions will be autonomous, with humans teleoperating. We present the first classification of autonomy levels in cybersecurity and introduce Cybersecurity AI (CAI), an open-source framework that…
CAI · specialized agents turn a goal into tested actionHuman goalwith oversightCAI agent teamreasondelegateuse toolsMeasured securityCTFs · bug bountiesrobot assessmentshuman-in-the-loop
Visual summaryCAI combines specialized agents, tool use and human oversight into measured security work across CTFs, bug bounties and robot assessments.
Paper · 2025

Cybersecurity AI Benchmark (CAIBench): A Meta-Benchmark for Evaluating Cybersecurity AI Agents

Cybersecurity spans multiple interconnected domains, complicating the development of meaningful, labor-relevant benchmarks. Existing benchmarks assess isolated skills rather than integrated performance. We find that pre-trained…
CAIBench · knowledge is not operational capabilityJeopardy CTFA & DCyber rangeKnowledgePrivacymeta-benchmark10,000+ instancesknowledge~70%robot targets (RCTF2)22%the gapknowledge ≠ action
Visual summaryCAIBench exposes the gap between knowledge and operational skill: models approach 70% on knowledge tasks but solve only 22% of the RCTF2 robot targets.
Paper · 2022

Robot cybersecurity, a review

Robots are often shipped insecure and in some cases fully unprotected. The rationale behind is threefold: first, defensive security mechanisms for robots are still on their early stages, not covering the complete threat…
Robotics knows it has a security problem — and mostly isn’t acting on itRECOGNITION · what roboticists say93%believe their robot can be hacked (ROS-Industrial)80%say robot security awareness is insufficient (ERF 2020)73%admit they have not invested enough (ROS)ACTION · what they actually do36%apply robot-specific defences (ROS)26%have actually invested in security (ROS)11%have ever security-tested, e.g. fuzzing (ROS-Industrial)
Visual summaryRobotics communities recognize the security problem far more often than they invest, deploy defenses or conduct security testing.
Paper · 2022

Robot teardown: stripping industrial robots for good

Building a robot requires careful selection of components that interact across networks while meeting timing deadlines. Given the complexity associated, as robots get damaged or security compromised, their components will…
Ethernet / Wi-FiRS485 busHMIsafetyEXTERNAL NETWORKremote · often unauthenticatedCONTROLLERcompute + safety logicARM MECHANICSactuators + sensorsTEACH PENDANTHMISAFETY PLCe-stop / limitsTeardown maps every internal and external network — the robot’s real attack surface.
Visual summaryRobot teardown exposes the internal and external networks that make up an industrial robot’s real attack surface.
Paper · 2022

SROS2: usable cybersecurity tools for ROS 2

Security in ROS 2 is only effective if developers actually use it. SROS2 provides a usable set of tools and a methodology to secure ROS 2 computational graphs, lowering the friction of enabling DDS security so that robots ship…
SROS2 · the three pillars DDS-Security adds to ROS 2ROS 2 nodeAuthenticationX.509 identity per nodeAccess controlper-node permissionsEncryptionAES-GCM over DDS
Visual summarySROS2 makes DDS-Security usable in ROS 2 by packaging node identity, least-privilege permissions and encrypted transport into developer tooling.
Paper · 2021

Cybersecurity in robotics: challenges, quantitative modeling and practice

A book-length treatment of robot cybersecurity: the challenges that make robots hard to secure, quantitative models for reasoning about robot risk, and the practices — disclosure, scoring, testing — that move the field forward.
Cybersecurity in robotics · evidence into defensible decisionsRVSS severitydistributed componentssafety consequenceadversarial modellingquantified decisionsrisk · investment · defenserobot context + system structure + attacker–defender behaviour
Visual summaryQuantitative robot-security models connect robot-aware severity, distributed-system exposure, safety consequence and adversarial behaviour to defensible security decisions.
Paper · 2020

Red teaming the Robot Operating System (ROS) in industry

We red-team ROS and ROS-Industrial deployments as an attacker would, chaining reconnaissance, protocol abuse and lateral movement to take control of industrial robots — and derive concrete hardening guidance from what worked.
Red-teaming ROS-Industrial · four attack groups, one graphattack group 1attack group 2attack group 3attack group 4ROS computationalgraph4/4 compromise graph3/4 control mostrobot endpoints
Visual summaryFour attack groups compromised the ROS computational graph; three of the four then gained control of most robotic endpoints.
Paper · 2020

DevSecOps in robotics

Robots are long-lived, safety-critical and frequently updated — exactly the systems that benefit most from continuous security. This work adapts DevSecOps to robotics, embedding security testing, disclosure and patching into the…
DevSecOps in robotics · security through all four phasesDevelopmentDeploymentProductionPost-productioncontinuous security feedback — not a final gate
Visual summaryRobotics DevSecOps threads security through development, deployment, production and post-production instead of treating it as a final gate.
Paper · 2020

alurity: a toolbox for robot cybersecurity

Reproducibility is the bottleneck in robot security research. alurity is a modular, containerized toolbox that packages the tools and targets needed to research, teach and reproduce robot security work in a consistent environment.
Alurity · a modular, containerized robot-security toolboxrobotsrobot componentsforensicsexploitationtestingreconnaissanceIDE / UIseven reusable groups · simulated, emulated and physical labs
Visual summaryalurity composes seven reusable groups of robot, testing, reconnaissance, exploitation, forensic and development modules into reproducible simulated, emulated and physical security labs.
Report · 2020

Securing robot endpoints in Operational Technology (OT) environments: Extending KICS with the Robot Immune System (RIS)

Are robot endpoints secure in industrial environments? Current industrial security solutions monitor network interaction and detect unexpected traffic and cyber-threats, but robot-specific protocols and tools are commonly unknown…
Network monitoring is blind to the robot endpointnetworkrobot busCONTROL STATIONROBOT CONTROLLERROBOTmechanics + actuatorsKICS for Networks · monitors the industrial networkKICS for Nodes: hardenedRIS · Robot Endpoint Protection at the controllercovers the controller→robot traffic no network sensor sees
Visual summaryNetwork monitoring leaves a blind spot between controller and mechanics; endpoint protection closes it at the robot.
Paper · 2019

Introducing the Robot Vulnerability Database (RVD)

The Robot Vulnerability Database (RVD) is an open, community-driven archive that registers and records robot vulnerabilities and bugs. It gives the field a shared, machine-readable memory of what has gone wrong, scored with RVSS…
Robot Vulnerability Database · a shared record for the fieldcommunity reportsvendor disclosuresresearch findingsstructured RVD recordbug · weakness · vulnerabilityvendor · robot · component · CVEaffected componentcoordinated disclosureRVSS severity
Visual summaryRVD gives robotics a shared, structured record of bugs, weaknesses and vulnerabilities, linking affected components to coordinated disclosure and robot-aware severity.
Paper · 2019

Akerbeltz: the first ransomware for industrial robots

Akerbeltz is, to our knowledge, the first ransomware built for industrial collaborative robots. Demonstrated against Universal Robots' UR3, UR5 and UR10 cobots, it shows how an attacker can hold a factory's robots — and therefore…
Akerbeltz · ransomware built for a robotIndustrial robotunprotected controllerexploitLOCKEDIP encrypted · haltedpay?Ransom demandor the line stays down
Visual summaryAkerbeltz turns an exposed Universal Robots controller into a ransom lever: gain control, lock the robot, encrypt its programs and intellectual property, then halt production.
Paper · 2018

Towards an open standard for assessing the severity of robot vulnerabilities (RVSS)

General-purpose severity scores (CVSS) miss what makes robots dangerous: physical consequence, safety impact and environmental context. The Robot Vulnerability Scoring System (RVSS) extends CVSS with robot-specific metrics so…
RVSS · CVSS extended for cyber-physical consequenceCVSS baseexploitability · impact+Robot contextsafety · age · downstreamenvironmental modifiersRVSSrobot-aware severity
Visual summaryRVSS retains the CVSS base while adding physical safety, vulnerability age, downstream impact and robot-environment context so cyber-physical consequences affect severity.
Paper · 2018

Aztarna, a footprinting tool for robots

Industry 4.0 is changing the commonly held assumption that robots are deployed in closed, isolated networks. Analysed from a security point of view the picture is disheartening: the robotics industry has not seriously followed…
What aztarna found on the open internet61,265industrial routers detected · Shodan (eWON, Moxa, Westermo, Sierra Wireless)26,801reachable when probed9,009on DEFAULT or NO credentials — 33% of those reachableEach insecure router is a doorway to the robots behind it. aztarna also found ROS masters reachable on theopen internet (default master port 11311) — inherently unauthenticated, and trivially footprinted.
Visual summaryaztarna’s Internet-wide scan found thousands of industrial routers and ROS systems exposed with weak or missing access controls.
Paper · 2018

The Robot Security Framework (RSF): a methodology to assess robot security

Robot security assessments are often ad hoc and incomparable. The Robot Security Framework (RSF) proposes a systematic, layered methodology — physical, network, firmware, operating-system and application — so assessments are…
The Robot Security Framework · assess every layer, methodicallyPhysicalNetworkFirmwareApplicationaspectcriteriarationale · method
Visual summaryRSF structures a holistic assessment across four main layers—physical, network, firmware and application—so findings are systematic and comparable.
Paper · 2018

The Robotics CTF (RCTF): a playground for robot hacking

You learn security by breaking things safely. The Robotics CTF (RCTF) is an online capture-the-flag environment of vulnerable robot scenarios, letting researchers and students practice robot hacking and defense reproducibly.
Robotics CTF · a capture-the-flag playground for robot hackingscenario 1scenario 2scenario 3scenario 4scenario 5scenario 6scenario 7scenario 8scenario 9nine safe, reproducible robot targets · playable from a browser
Visual summaryRCTF provides nine reproducible, intentionally vulnerable robot scenarios that researchers can run locally, reshape and attack safely from a browser.
Paper · 2018

Robot hazards: from safety to security

Robotics landscape is experiencing big changes. Robots are spreading and will soon be everywhere. Systems traditionally employed in industry are being replaced by collaborative robots, while more and more professional and…
From safety to security · a hazard is now a security hazardSAFETYprotect the environment from the robotthe bridgeSECURITYprotect the robot from the environment
Visual summarySafety protects people and the environment from robot failure; security protects the robot from deliberate interference. In a connected robot, both lead to the same physical hazard.
Research note · 2026
Foundation-model robots: a new attack surface
As robots hand control to large language and vision–language–action models, the reasoning loop itself becomes attackable. This briefing surveys the 2026 literature on foundation-model robot…
2026
Research note · 2026
Hardening a robot: the controls that hold
This lab spends most of its time showing how robots break. This briefing is the counterweight: the concrete, mostly-free controls that actually hold a robot — SROS2 and DDS-Security on the…
2026
Research note · 2026
Phoning home: the robot cloud as a fleet-wide risk
Every modern robot keeps an always-on connection to its maker — for telemetry, remote management, over-the-air updates and cloud teleoperation. That convenience turns the manufacturer…
2026
Research note · 2026
Spoofing the senses: the attack beneath the software
A robot senses the world, then acts — so the most fundamental attack skips the software entirely and lies to the sensors themselves. A sound at a gyroscope resonant frequency, a counterfeit…
2026
Research note · Mar 17, 2022
SROS2: Usable Cyber Security Tools for ROS 2
We propose a robot cybersecurity methodology to secure computational graphs and improve SROS2, usable security tools for ROS 2. We argue that without usability, security in robotics will be…
2022
Research note · Dec 13, 2021
Robot Hacking Manual (RHM) v0.4
Learn robot cybersecurity through the Robot Hacking Manual (RHM), an introductory series about cybersecurity in robotics, with an attempt to provide comprehensive case studies and…
2021
Research note · Nov 28, 2021
Hacking ROS 2 ethically
We study the underlying default communication middleware of ROS 2, OMG's Data Distribution Service (DDS) and 6 popular implementations. We found all DDS implementations vulnerable to…
2021
Research note · Nov 25, 2021
Robot Hacking Manual (RHM)
The Robot Hacking Manual (RHM) is an introductory series about cybersecurity for robots, with an attempt to provide comprehensive case studies and step-by-step tutorials with the intent to…
2021
Research note · Jul 24, 2021
Reviewing the status of robot cybersecurity
What's the status of cybersecurity in robotics? and, how can we best improve cyber-resillience in robotics? In this article we answer these questions and review the status of the robot…
2021
Research note · Jul 18, 2021
Robot teardown
Robot teardown fuels security research by understanding the underlying robot hardware architectures. The results help uncover security vulnerabilities, research quality and safety. We…
2021
Research note · Nov 2, 2020
Safety requires security in robotics
This article discusses briefly the connection between safety and security in robotics, while reasons about how security must be implemented at the robot endpoint to fullfil safety…
2020
Research note · Sep 17, 2020
Red teaming the Robot Operating System in industry
Can ROS be used securely for industrial use cases even though its origins didn't consider it? The present study answers this question experimentally by performing a red team exercise over…
2020
Research note · Aug 24, 2020
Disrupting ROS and ROS-Industrial communications by attacking underlying network protocols
This article aims to illustrate the consequences that some simple attacks targeting these underlying network protocols could have in ROS and ROS-Industrial deployments.
2020
Research note · Jul 10, 2020
Monthly reports on robot cybersecurity vulnerabilities - May and June 2020
A total of 23 robot cybersecurity vulnerabilities were reported from May to June 2020 according to the Robot Vulnerability Database (RVD). Vulnerabilities reported affect different vendors…
2020
Research note · Jun 23, 2020
IT, OT, IoT and Robotics, a security comparison
Cyber security aspects that apply to different domains including IT, OT, IoT or robotics are analyzed and compared together.
2020
Research note · May 31, 2020
Robotics and its compromised new supply chain
Insecurities in robotics are not just in the robots themselves, they are also in the whole supply chain, difficulting serving safe and secure robotics solutions.
2020
Research note · May 17, 2020
Vulnerability coordination and disclosure in robotics
As nicely pointed out in [1], responsible cybersecurity research and more specifically, vulnerability disclosure, is a two-way street. Vendors and manufacturers[2], as well as…
2020
Research note · May 8, 2020
The robotics "air gap"
The robotics air gap is a network security measure employed wherein the robot is assumed to be physically isolated from insecure networks. Robots however are networks of devices by…
2020
Research note · May 6, 2020
More than 100 companies use vulnerable collaborative robots
More than 100 companies are using insecure collaborative robots putting at risk tenths of thousands of workers and infrastructures around the world. These insecurities stem from…
2020
Research note · May 3, 2020
Monthly report on robot cybersecurity vulnerabilities - April 2020
A total of 67 robot cybersecurity flaws were reported in April 2020 according to the Robot Vulnerability Database (RVD), all of them vulnerabilities applying and confirmed to Universal…
2020
Research note · Apr 26, 2020
Delivering unprotected IP into robots, Universal Robots+
Universal Robots delivers unprotected Intellectual Property through their insecure development platform, Universal Robots+. More than 600 partners affected have already submitted their…
2020
Research note · Apr 19, 2020
Universal Robots cobots are not secure
Tenths of thousands of users of Universal Robots are using insecure technology that might easily lead to safety hazards. This article argues about why and how we reached this situation and…
2020
Research note · Apr 13, 2020
Quality, safety and security in robotics
Quality, safety and security are often misunderstood, mistaken or disregarded in robotics. This article argues about these terms and their relationship in the context of robotics,…
2020
Research note · Nov 7, 2019
Real-time security for robotics
Real-time is not real-fast: robot security must preserve end-to-end control deadlines even under malicious activity.
2019