Cybersecurity AI: Humanoid Robots as Attack Vectors

Papers with Code Trending Papers

Summary

This paper presents a systematic security assessment of the Unitree G1 humanoid robot, revealing critical vulnerabilities including BLE provisioning protocol exploits, hardcoded AES keys, and a resident Cybersecurity AI agent capable of exfiltration and offensive operations, arguing for adaptive CAI-powered defenses as humanoids enter critical infrastructure.

We present a systematic security assessment of the Unitree G1 humanoid showing it operates simultaneously as a covert surveillance node and can be purposed as an active cyber operations platform. Initial access can be achieved by exploiting the BLE provisioning protocol which contains a critical command injection vulnerability allowing root access via malformed Wi-Fi credentials, exploitable using hardcoded AES keys shared across all units. Partial reverse engineering of Unitree's proprietary FMX encryption reveal a static Blowfish-ECB layer and a predictable LCG mask-enabled inspection of the system's otherwise sophisticated security architecture, the most mature we have observed in commercial robotics. Two empirical case studies expose the critical risk of this humanoid robot: (a) the robot functions as a trojan horse, continuously exfiltrating multi-modal sensor and service-state telemetry to 43.175.228.18:17883 and 43.175.229.18:17883 every 300 seconds without operator notice, creating violations of GDPR Articles 6 and 13; (b) a resident Cybersecurity AI (CAI) agent can pivot from reconnaissance to offensive preparation against any target, such as the manufacturer's cloud control plane, demonstrating escalation from passive monitoring to active counter-operations. These findings argue for adaptive CAI-powered defenses as humanoids move into critical infrastructure, contributing the empirical evidence needed to shape future security standards for physical-cyber convergence systems.
Original Article
View Cached Full Text

Cached at: 05/24/26, 12:28 PM

Paper page - Cybersecurity AI: Humanoid Robots as Attack Vectors

Source: https://huggingface.co/papers/2509.14139 Published on Sep 17, 2025

Abstract

The Unitree G1 humanoid robot is vulnerable to BLE provisioning protocol exploits, exfiltrates sensor data, and can be repurposed for active cyber operations, highlighting the need for improved security standards in commercial robotics.

We present a systematic security assessment of the Unitree G1 humanoid showing it operates simultaneously as a covert surveillance node and can be purposed as an active cyber operations platform. Initial access can be achieved by exploiting theBLE provisioning protocolwhich contains a criticalcommand injection vulnerabilityallowing root access via malformedWi-Fi credentials, exploitable usinghardcoded AES keysshared across all units. Partial reverse engineering of Unitree’s proprietaryFMX encryptionreveal astatic Blowfish-ECB layerand a predictableLCG mask-enabled inspection of the system’s otherwise sophisticated security architecture, the most mature we have observed in commercial robotics. Two empirical case studies expose the critical risk of this humanoid robot: (a) the robot functions as a trojan horse, continuously exfiltrating multi-modal sensor and service-state telemetry to 43.175.228.18:17883 and 43.175.229.18:17883 every 300 seconds without operator notice, creating violations ofGDPRArticles 6 and 13; (b) a residentCybersecurity AI(CAI) agent can pivot from reconnaissance to offensive preparation against any target, such as the manufacturer’scloud control plane, demonstrating escalation from passive monitoring to active counter-operations. These findings argue foradaptive CAI-powered defensesas humanoids move into critical infrastructure, contributing the empirical evidence needed to shape future security standards forphysical-cyber convergencesystems.

View arXiv pageView PDFProject pageGitHub8.69kautoAdd to collection

Get this paper in your agent:

hf papers read 2509\.14139

Don’t have the latest CLI?curl \-LsSf https://hf\.co/cli/install\.sh \| bash

Models citing this paper0

No model linking this paper

Cite arxiv.org/abs/2509.14139 in a model README.md to link it from this page.

Datasets citing this paper0

No dataset linking this paper

Cite arxiv.org/abs/2509.14139 in a dataset README.md to link it from this page.

Spaces citing this paper0

No Space linking this paper

Cite arxiv.org/abs/2509.14139 in a Space README.md to link it from this page.

Collections including this paper0

No Collection including this paper

Add this paper to acollectionto link it from this page.

Similar Articles

Robot Dogs Are a Security Nightmare

Lobsters Hottest

This article critiques the deployment of Unitree robot dogs by law enforcement and security firms, highlighting severe cybersecurity vulnerabilities, physical safety risks like LiDAR blind spots, and the reality that many units are remotely operated rather than autonomous.

Cybersecurity insecurities

Reddit r/ArtificialInteligence

The article speculates whether AI systems used in cybersecurity by tech companies are intentionally designed to produce bad code, potentially enabling exploitation for AI-related gains.

Evaluating potential cybersecurity threats of advanced AI

Google DeepMind Blog

DeepMind published a comprehensive framework for evaluating offensive cybersecurity capabilities of advanced AI models, analyzing over 12,000 real-world AI-powered cyberattack attempts across 20 countries and creating a 50-challenge benchmark covering the entire attack chain to help defenders prioritize security resources.

The AI cybersecurity arms race is on

Reddit r/artificial

The article discusses the emerging AI cybersecurity arms race, where AI agents are employed for both malicious attacks and defensive measures, supported by recent incidents and research highlighting the growing threat and response.