STALE MEASUREMENTNewest real-model measurement: 26 days old, measured with v0.32.0; 7 releases have shipped since, past this project’s own 7-day window. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
COMMUNITY DRAFT · VERSIONED · v0.2

The Embodied AI Security Top 10

A robot policy has its own attack surface, and it needs its own risk taxonomy. This is a versioned, community-draft list for vision-language-action policies - each entry with a definition, a real example, how Provael tests it (or why it is out of scope), mitigations, and a compliance mapping.

Cross-mapped to OWASP Agentic + LLM Top 10MITRE ATLASProvael covers 8 / 10EAI01 measured on SmolVLASee these risks in the wild →Measured per family →

The ten risks

RELATIONSHIP TO OTHER TAXONOMIES

Complementary to RoboJailBench - not a rival.

RoboJailBench (Yeke, Zhou, Lin, Cai, Bianchi & Celik - Purdue University; arXiv:2605.19328v1) proposes an 18-category harm-outcome taxonomy - what harm results (collision, force violation, unauthorized capture). This list is an attack-mechanism taxonomy - how the system is attacked. One mechanism here produces many of their harms, and several entries (poisoning, injection, CPS, evaluation) are delivery mechanisms or meta-risks with no single harm counterpart. Two axes of the same problem - complementary, not competing.

Mapped against their 18 harm categories, Provael measures 2 covered, 5 partial, 9 not covered, and 2 out of scope by design - deliberately not a clean sweep. A crosswalk that claimed to cover all 18 would be measuring the wrong thing.

$ provael crosswalk --target robojailbench
OPEN RFC · v0.2 → v0.3

The list is a draft. Help version it.

The ranking is expert-elicited, not data-driven, and it will change as the field matures. If an entry is wrong, mis-ranked, or missing - or you have field evidence, a real incident, or a defense result to add - bring it. Co-authors and disputes are both welcome, and the CC BY-SA 4.0 license keeps it open.

  1. Propose - open a discussion or issue with the change and your evidence.
  2. Discuss - argue it in the open; maintainers and contributors weigh in.
  3. Vote - rough consensus decides what lands in the next revision.
  4. Version - merged changes ship in a numbered draft (v0.2 → v0.3), contributors credited.
CONTRIBUTORS

Be the first organization on this list. This is a new, independent community project - no contributors are listed yet. Propose or dispute an entry, and when your change is adopted you will be credited here.

Start a contribution →

Test your policy against the Top 10.

Run Provael locally and measure your own attack-success rate, or book a red-team assessment for an evidence pack you can file.