Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Huang, Yuhang, Li, Junchao, Ma, Boyang, Dai, Xuelong, Xu, Minghui, Xu, Kaidi, Zhang, Yue, Wang, Jianping, Cheng, Xiuzhen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914184985313280
author Huang, Yuhang
Li, Junchao
Ma, Boyang
Dai, Xuelong
Xu, Minghui
Xu, Kaidi
Zhang, Yue
Wang, Jianping
Cheng, Xiuzhen
author_facet Huang, Yuhang
Li, Junchao
Ma, Boyang
Dai, Xuelong
Xu, Minghui
Xu, Kaidi
Zhang, Yue
Wang, Jianping
Cheng, Xiuzhen
contents Embodied AI systems integrate language models with real world sensing, mobility, and cloud connected mobile apps. Yet while model jailbreaks have drawn significant attention, the broader system stack of embodied intelligence remains largely unexplored. In this work, we conduct the first holistic security analysis of the Unitree Go2 platform and uncover ten cross layer vulnerabilities the "Ten Sins of Embodied AI Security." Using BLE sniffing, traffic interception, APK reverse engineering, cloud API testing, and hardware probing, we identify systemic weaknesses across three architectural layers: wireless provisioning, core modules, and external interfaces. These include hard coded keys, predictable handshake tokens, WiFi credential leakage, missing TLS validation, static SSH password, multilingual safety bypass behavior, insecure local relay channels, weak binding logic, and unrestricted firmware access. Together, they allow adversaries to hijack devices, inject arbitrary commands, extract sensitive information, or gain full physical control.Our findings show that securing embodied AI requires far more than aligning the model itself. We conclude with system level lessons learned and recommendations for building embodied platforms that remain robust across their entire software hardware ecosystem.
format Preprint
id arxiv_https___arxiv_org_abs_2512_06387
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
Huang, Yuhang
Li, Junchao
Ma, Boyang
Dai, Xuelong
Xu, Minghui
Xu, Kaidi
Zhang, Yue
Wang, Jianping
Cheng, Xiuzhen
Cryptography and Security
Robotics
Embodied AI systems integrate language models with real world sensing, mobility, and cloud connected mobile apps. Yet while model jailbreaks have drawn significant attention, the broader system stack of embodied intelligence remains largely unexplored. In this work, we conduct the first holistic security analysis of the Unitree Go2 platform and uncover ten cross layer vulnerabilities the "Ten Sins of Embodied AI Security." Using BLE sniffing, traffic interception, APK reverse engineering, cloud API testing, and hardware probing, we identify systemic weaknesses across three architectural layers: wireless provisioning, core modules, and external interfaces. These include hard coded keys, predictable handshake tokens, WiFi credential leakage, missing TLS validation, static SSH password, multilingual safety bypass behavior, insecure local relay channels, weak binding logic, and unrestricted firmware access. Together, they allow adversaries to hijack devices, inject arbitrary commands, extract sensitive information, or gain full physical control.Our findings show that securing embodied AI requires far more than aligning the model itself. We conclude with system level lessons learned and recommendations for building embodied platforms that remain robust across their entire software hardware ecosystem.
title Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
topic Cryptography and Security
Robotics
url https://arxiv.org/abs/2512.06387