As artificial intelligence extends beyond digital confines into cars, drones, and service robots, a new survey highlights the security and ethical risks when vision-language models guide these embodied systems. The review, published in Machine Intelligence Research, connects failures across perception, planning, instruction following, and human-robot interaction, covering issues like hallucinations, adversarial attacks, and privacy leakage. It underscores that a mistaken description or manipulated command can become a physical action, making safety a critical concern.
Vision-language models (VLMs) link images with text, while vision-language-action models (VLAs) extend this to robot plans and control signals, enabling natural-language instruction and flexible task execution. However, this creates a dependency chain where flawed data can distort perception, weak alignment can produce hallucinations, and malicious inputs can redirect decisions. In autonomous vehicles or industrial robots, such errors could lead to collisions or equipment damage. Existing safeguards are often fragmented and computationally costly, necessitating unified and adaptive defenses for multimodal agents in unpredictable physical conditions.
The study, conducted by researchers from the Institute of Automation, Chinese Academy of Sciences; University College London; Minzu University of China; and the China Academy of Electronics and Information Technology, was published online on July 13, 2026, with DOI: 10.1007/s11633-025-1626-x. It appears in a special issue on security and ethics of generative AI. The team examined VLM and VLA use across perception, planning, instruction following, and human-robot interaction, showing how failures can cascade. Forged traffic signs, altered labels, cloned voices, and deceptive captions can misguide systems, while adversarial perturbations and jailbreak prompts may bypass safety controls.
The authors organize countermeasures into connected layers, including hallucination filtering, cross-modal forgery detection, defenses against perturbations, differential privacy, and safeguards for navigation and physical control. They emphasize that no single filter can secure an embodied agent; protection must follow the entire path from sensor input to execution. The central insight is that safety must be integrated across model reasoning, system architecture, and physical action, with transparent risk metrics and human oversight for critical decisions.
The review provides a practical checklist for developers and regulators to evaluate embodied systems before deployment. Future platforms could combine interpretable reasoning, attack detection, and privacy-preserving computation under reproducible protocols. The authors call for designs addressing technical robustness, regulatory alignment, social equity, and environmental sustainability. This approach could support safer autonomous transport, healthcare assistance, and industrial robotics, while making responsibility easier to trace. They also warn that laboratory results may not transfer to noisy, culturally diverse environments, stressing the need for cross-disciplinary cooperation and stress-testing.


