Skip to main content
  1. Home
  2. Computing
  3. News

AI-controlled robots can be jailbroken, and the results could be disastrous

Add as a preferred source on Google
The Figure 02 robot looking at its own hand
Figure Robotics

Researchers at Penn Engineering have reportedly uncovered previously unidentified security vulnerabilities in a number of AI-governed robotic platforms.

“Our work shows that, at this moment, large language models are just not safe enough when integrated with the physical world,” George Pappas, UPS Foundation Professor of Transportation in Electrical and Systems Engineering, said in a statement.

Recommended Videos

Pappas and his team developed an algorithm, dubbed RoboPAIR, “the first algorithm designed to jailbreak LLM-controlled robots.” And unlike existing prompt engineering attacks aimed at chatbots, RoboPAIR  is built specifically to “elicit harmful physical actions” from LLM-controlled robots, like the bipedal platform Boston Dynamics and TRI are developing.

RoboPAIR reportedly achieved a 100% success rate in jailbreaking three popular robotics research platforms: the four-legged Unitree Go2, the four-wheeled Clearpath Robotics Jackal, and the Dolphins LLM simulator for autonomous vehicles. It took mere days for the algorithm to fully gain access to those systems and begin bypassing safety guardrails. Once the researchers had taken control, they were able to direct the platforms to take dangerous actions, such as driving through road crossings without stopping.

“Our results reveal, for the first time, that the risks of jailbroken LLMs extend far beyond text generation, given the distinct possibility that jailbroken robots could cause physical damage in the real world,” the researchers wrote.

The Penn researchers are working with the platform developers to harden their systems against further intrusion, but warn that these security issues are systemic.

“The findings of this paper make abundantly clear that having a safety-first approach is critical to unlocking responsible innovation,” Vijay Kumar, a coauthor from the University of Pennsylvania, told The Independent. “We must address intrinsic vulnerabilities before deploying AI-enabled robots in the real world.”

“In fact, AI red teaming, a safety practice that entails testing AI systems for potential threats and vulnerabilities, is essential for safeguarding generative AI systems,” added Alexander Robey, the paper’s first author, “because once you identify the weaknesses, then you can test and even train these systems to avoid them.”

Andrew Tarantola
Former Computing Writer
Andrew Tarantola is a journalist with more than a decade reporting on emerging technologies ranging from robotics and machine…
Viture Pro 2 review: Affordable glasses that I loved more for work than play
One of the lightest and brightest XR glasses you will find for the price.
Viture Pro 2 smart glasses

Quick summary

Two years ago, I had the chance to test out the Viture Pro smart glasses. I was impressed by the chic design and the stunning display units, but there were a few minor hiccups that kept them from becoming an instant buy for XR fans. The asking price of $459, ultimately, made them a tough recommendation for anyone who is not a diehard enthusiast or doesn't have the spare cash to spend. The successor, however, is an altogether different beast.

Read more
Your Mac might have a screen sharing problem, and hackers already know about it
A patch is only useful once you install it.
macOS Tahoe 26 public beta running on the M4 MacBook Air 15

If you've been putting off that macOS update sitting in your notifications, this is the week to stop and install it. 

Apple quietly patched a serious screen sharing flaw in macOS earlier this month. While that usually means the issue is resolved, new evidence shows hackers already broke into unpatched Macs, hijacked them, and used them for cryptocurrency mining before the fix shipped.

Read more
The US is trying to kick foreign robots out, but the local supply chain might not be there yet
Building a robot supply chain from scratch takes years that Washington isn't giving anyone.
LG CLOiD Home Robot

The FCC has a track record of using its Covered List to squeeze Chinese tech out of American markets, and robots just became its newest target. Foreign-made humanoids, quadrupeds, and even robot vacuums now need to be mostly built in the U.S. to sell here (via Rest of World). 

So what does the new rule actually require?

Read more