STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
EMBODIED AI SECURITY · INCIDENT INDEX · PV-013

When AI got a body, the incidents got physical.

Software has CVE/NVD. General AI has the AI Incident Database. Physical AI has had no single index - robot and vision-language-action security events are scattered across CVE records, CISA advisories, and arXiv. This is that index: every entry independently verifiable, each mapped to the Embodied AI Security Top 10.

5 deployed · 6 researchCVE · CISA · arXiv · pressLiving index - sourced only
Embodied AI security events · newest first · deployed incidents and research results, labelled per row · each links to its primary source and EAI mapping
DateIncidentMaps toSource
2026-08
UniBLEed - two root-RCE chains in the Unitree G1 EDU, one reachable from Bluetooth range with no pairing
Chained remote code execution: BLE GATT + WiFi provisioning (CVE-2026-76640) and a DDS bridge + path traversal (CVE-2026-76639) · CVE (2), both PUBLISHED 2026-08-27
Unitree G1 EDU humanoid, firmware through 1.5.2 - the Locomotion PC, which runs motors, cameras, audio and voice as root - Disclosed 27 August 2026 by Olivier Laflamme. CVE-2026-76640 needs only Bluetooth proximity and no pairing or credentials: crafted writes to an unprotected GATT characteristic overflow a fixed 500-byte SSID accumulator with a 1050-byte payload across BLE connections, corrupting an adjacent mainloop function-pointer entry that the cleanup path later invokes with attacker-controlled data through system() as uid 0. CVE-2026-76639 is network-adjacent: an unauthenticated WebRTC-to-DDS bridge on TCP 9991, a world-readable static AES-128 key, and path traversal in the chat_go knowledge upload combine to plant a payload in bashrunner’s script directory and run it as root. Both records were read at cve.org before this entry was published; both are PUBLISHED, assigned by VulnCheck, and name Unitree Robotics G1 EDU through 1.5.2. THIS IS THE CLASS PROVAEL DOES NOT TEST. Provael attacks a policy through the instructions and observations it receives; nothing here touches a policy. The entry point is a radio, the bug is a missing bounds check in C, and the outcome is uid 0 on the computer the policy happens to run on — EAI07, which the registry marks out of scope for a VLA red-teamer by design, and which is assessed with IEC 62443 and ATT&CK-for-ICS methods and CVE scanning against the robot’s own stack. A clean Provael run says nothing whatsoever about this. That boundary is a large part of why this index exists: the risks a policy scanner cannot see still belong on the map.
Laflamme, UniBLEed (researcher write-up); CVE-2026-76639 / CVE-2026-76640 →
2026-08
DURA - a diffusion-optimised patch that works when printed, and needs only the robot’s emitted actions
Adversarial patch optimised along a diffusion latent trajectory, white-box and black-box · Research
OpenVLA-7B and pi0-FAST on LIBERO, plus a real Franka arm - Reports 100% ASR under white-box access across all four LIBERO suites in both the simulated and physical patch settings, 86.0% and 79.3% black-box, and 77% from a patch covering 2% of the image (99% at 5%), against 23.5% benign and 39.5% clean-patch baselines. What is new is the black-box variant: it needs only the victim’s emitted actions, so an observable action stream is itself an attack surface rather than just an output. Third-party work - Provael did not run it, and unlike most entries here it was demonstrated on physical hardware, with a printed patch held in the arm’s camera view.
arXiv:2608.10393 →
2026-08
DRIFT - flow-matching robustness reported as an artefact of how it was measured
Universal gripper patch optimised against the first denoising step · Research
Flow-matching VLA policies (pi0, pi0.5) - Reports that the adversarial robustness flow-matching policies were credited with "is largely illusory: it stems from prior attacks ignoring the multi-step denoising ODE", and that attacking only the first denoising step beats attacking a wider window. Not a deployed incident and no robot was harmed: a white-box result on off-the-shelf policies in simulation.
arXiv:2608.03207 →
2026-08
AGSD and SARF - attention-hijacking patch, and a defense measured on real hardware
Printable patch that hijacks action-to-vision attention, plus a fine-tuning defense · Research
OpenVLA on LIBERO, and a physical PiPER manipulator - AGSD drives OpenVLA to a 100% failure rate under attack; the paired SARF defense cuts that to 14.2-56.8% and, on a real PiPER arm, lifts average success under attack from 23.0% to 65.0%. Listed because the defense half carries a physical-robot number - the kind of evidence Provael does not have for any family.
arXiv:2608.03231 →
2026-05
Command injection in Universal Robots PolyScope 5
Unauthenticated OS command injection → controller RCE · CVSS 9.8
Universal Robots cobot controllers (PolyScope 5 < 5.25.1) - CISA advisory ICSA-26-134-17: an unauthenticated attacker with network access to the Dashboard Server executes commands on the robot controller - enough to alter safety configurations or manipulate physical movement.
CISA ICSA-26-134-17 →
2026-04
Unauthenticated RCE in Hugging Face LeRobot
Unsafe pickle deserialization over unauthenticated gRPC · CVSS 9.8
LeRobot async-inference PolicyServer (the default open VLA stack, 21.5k★) - CVE-2026-25874: any attacker who can reach the PolicyServer port runs arbitrary code on the host - a server that sits directly in the control path and whose outputs govern actuator commands on the robot's joints.
CVE-2026-25874 (Resecurity) →
2025-11
AttackVLA / BadVLA - targeted action hijack & backdoors
Targeted action-sequence hijack and implanted backdoors · Research
Vision-language-action robot policies - Drove a real robot through an attacker-specified action sequence, and showed backdoors that trigger a chosen motion on a hidden cue - the danger is in the trajectory, not the words.
arXiv:2511.12149 →
2025-09
FreezeVLA - adversarial policy paralysis
Adversarial-image freeze (no-op / paralysis) · Research
Open vision-language-action policies - Reported roughly 76% paralysis attack-success rate: an adversarial image freezes the policy into inaction - an availability failure that a single task-success metric hides.
arXiv:2509.19870 →
2025-09
UniPwn - Unitree Go2 / G1 exploit chain
Unauthenticated comms/BLE exploit → RCE, wormable · Real-world
Unitree quadruped & humanoid robots - An unauthenticated exploit chain against widely-deployed Unitree robots enabling remote code execution and self-propagation, alongside separately-reported covert telemetry from the same platform.
IEEE Spectrum →
2024-10
RoboPAIR - jailbreaking LLM-controlled robots
Automated policy / instruction jailbreak · Research
LLM-driven robots (Unitree Go2, Clearpath, an AV stack) - An automated jailbreak that reliably drove LLM-controlled robots to perform disallowed physical actions - the external validation Provael cites for EAI01.
arXiv:2410.13691 →
2019
Adversarial road stickers steer Tesla Autopilot
Physical adversarial-perception patch · Real-world
Tesla Autopilot (deployed driver-assist) - Researchers placed three small stickers on the road that steered Autopilot into the oncoming lane - the canonical proof that adversarial perception moves a real machine, not just a benchmark.
IEEE Spectrum →

These are the risks. Provael measures them.

The Embodied AI Security Top 10 turns this incident surface into a taxonomy - and Provael turns the taxonomy into a reproducible attack-success rate for your own policy.