Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Preprint . 2026
License: CC BY
Data sources: ZENODO
https://doi.org/10.2139/ssrn.7...
Article . 2026 . Peer-reviewed
Data sources: Crossref
ZENODO
Preprint . 2026
License: CC BY
Data sources: Datacite
ZENODO
Preprint . 2026
License: CC BY
Data sources: Datacite
addClaim

The Physical Vulnerability of Embodied AI: Physical-layer Provenance, Compliance Architecture, and Safety Governance at the Kinetic Edge

Authors: Hsu, Chin-Yu;

The Physical Vulnerability of Embodied AI: Physical-layer Provenance, Compliance Architecture, and Safety Governance at the Kinetic Edge

Abstract

<p><span>When AI systems begin to drive motors, brakes, steering, and robotic arms, a hallucinated or hijacked command no longer produces merely a wrong sentence — it produces real-world kinetic harm. As artificial general intelligence (AGI) and large-language-model-driven agentic systems move into humanoid robots, L4+ autonomous driving, and other embodied-AI settings, the boundary of AI safety has crossed from the informational domain into the cyber-physical domain. This paper argues that software alignment, semantic filtering, RTOS scheduling, and software watchdogs are structurally insufficient to guarantee kinetic safety, because the safety interruption itself must traverse the same software stack that can be delayed, bypassed, or misled. We propose an auditable physical safety shell that is independent of the AI planner and anchors trust at the physical boundary through physical-layer provenance, inertial continuity, dissipation traces, and a hardware interruption path. Three mechanisms are introduced: Causal Vacuum Detection (CVD) audits whether an actuation command carries an explainable physical dissipation trace; Spatial-Inertial phase Identification (SII) checks continuity with the machine's current inertial state; and a Zeno-Triggered Joule Latch (ZTJ-L) provides a de-energize-to-trip fail-safe below the operating system. The key contribution is to relocate high-integrity safety responsibility away from unverifiable model weights toward a smaller, third-party-testable physical component, and to map this shell onto IEC 61508, ISO 26262, ISO 13849, and ISO/PAS 8800:2024 — including a concrete defense against the "substantial modification trap" under Machinery Regulation (EU) 2023/1230. The result is a governance pattern in which, even when the model errs, hallucinates, or is jailbroken, human control remains verifiable at an auditable physical boundary.</span><span></span></p>

Keywords

AI Governance, Causal Vacuum Detection (CVD), Topological Geometric Offload (TGO), Spatial-Inertial phase Identification (SII), Embodied AI Security, Cyber-Physical Safety, Zeno-Triggered Joule Latch (ZTJ-L), Physical-Layer Provenance, Functional Safety

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average