Adversarial attacks on physical AI systems pose novel safety risks for modern robots. Researchers at NeurIPS 2025 introduced BadVLA, a backdoor attack targeting Vision-Language-Action models that causes conditional deviations in robot action trajectories when a specific trigger is present. The attack surface spans training pipelines, system infrastructure, and runtime perception, challenging conventional safety assessments that assume machines fail predictably rather than being deliberately manipulated.
Opening Kapyn…