CyberSec 2026 Exposes Physical AI Flaw That Lets a Flyer Hijack Robot Commands
Physical AI uses vision-language-action models, or VLAs, to help robots interpret images and text and translate them directly into physical movement. But the models retain large language models' strong tendency to follow instructions, turning prompt injection from an information-security risk into a threat to people and equipment. Cybersecurity company VicOne therefore focused on this emerging attack surface at Taiwan's CyberSec 2026 conference.
During CyberSec 2026, VicOne demonstrated AI command hijacking, or CHAI, against a robot dog using a flyer containing specific text instructions. After the camera read the text in its surroundings, the VLA could disregard its original task and instead direct the robot dog to punch. The demonstration involved no transaction and disclosed no financial loss. Its significance was that visible text alone could potentially alter a robot's physical behavior.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →