The Embodied AI Security Top 10
A robot policy has its own attack surface, and it needs its own risk taxonomy. This is a versioned, community-draft list for vision-language-action policies — each entry with a definition, a real example, how Provael tests it (or why it is out of scope), mitigations, and a compliance mapping.
The ten risks
The “Embodied AI Security Top 10” is an independent community project maintained by Sattyam Jain (Provael), licensed CC BY-SA 4.0. Independent community project. Not affiliated with or endorsed by the OWASP Foundation or MITRE. Version v0.2 (draft), updated 2026-06-27. Ranking is expert-elicited, not data-driven — there is no embodied-vulnerability incidence corpus yet, and the order will change as one matures. Provael ships a runnable, sim-only attack family for 8 / 10 — EAI07 and EAI10 are out of scope for a VLA-policy red-teamer by design. Only EAI01 carries a real measured result; every other covered family is stub-validated scaffolding — no invented numbers.
Complementary to RoboJailBench — not a rival.
RoboJailBench (Yeke, Zhou, Lin, Cai, Bianchi & Celik — Purdue University; arXiv:2605.19328v1) proposes an 18-category harm-outcome taxonomy — what harm results (collision, force violation, unauthorized capture). This list is an attack-mechanism taxonomy — how the system is attacked. One mechanism here produces many of their harms, and several entries (poisoning, injection, CPS, evaluation) are delivery mechanisms or meta-risks with no single harm counterpart. Two axes of the same problem — complementary, not competing.
Mapped against their 18 harm categories, Provael measures 2 covered, 5 partial, 9 not covered, and 2 out of scope by design — deliberately not a clean sweep. A crosswalk that claimed to cover all 18 would be measuring the wrong thing.
Test your policy against the Top 10.
Run Provael locally and measure your own attack-success rate, or book a red-team assessment for an audit-ready evidence pack.