Field notes on embodied AI security.
Methodology, honest results, and the vocabulary of a new category. Content is a byproduct of shipping - every transfer study and attack family becomes a note here.
- Sep 4, 2026
What an 88% attack success rate means
The full setup behind Provael's headline number - the control arm, the reword controls, the uncalibrated predicate, and what would change it.
Read note → - Aug 8, 2026
We printed a JS object where the signing key goes
/leaderboard rendered an object where the signing key goes, in the sentence asking you not to take our word for it. The signature stayed valid; the page didn't.
Read note → - Aug 3, 2026
We were blocking the crawlers we built for
Our CDN's default robots.txt told ClaudeBot, GPTBot and Google-Extended to stay out, two lines above our own file welcoming citations. Fixed, written down.
Read note → - Aug 2, 2026
Two tens: the device layer and the policy layer
A December 2025 paper enumerates ten vulnerabilities in the Unitree Go2 stack. Provael's Top 10 also has ten. Not competing lists — different layers.
Read note → - Jul 22, 2026
Why Provael publishes null results
A security measurement is only worth its honesty. Here is why we report the attacks that did not work as loudly as the ones that did.
Read note → - Jul 21, 2026
The embodiment gap: what text red-teaming misses
Tools like garak and PyRIT scan what a model says. A robot policy turns language into motion, and that is a failure text-only red-teaming has nothing to score.
Read note →
Full-text feed of every note, measured finding and tracked incident — including the null results. No account, nothing to unsubscribe from.