Artificial intelligence (AI) systems are increasingly being deployed as embodied agents in drones, robots, and uncrewed aircraft systems (UAS), extending their attack surface beyond software and into the physical world. These systems tightly integrate perception, learning, decision-making, and control, creating security risks that are not fully addressed by traditional cybersecurity or AI robustness techniques. This talk presents recent work on Embodied AI Security, focusing on two complementary efforts. The first, CHAI (IEEE SaTML 2026), studies command-hijacking attacks against embodied agents that use large language models and vision-language models for high-level reasoning. The second, BADControl (USENIX Security 2026), examines backdoor and manipulation attacks on low-level controllers, including Proportional-Integral-Derivative (PID) controllers and Linear Quadratic Regulators (LQRs). Together, these projects show how adversaries can exploit the interface between cognition and control to induce unsafe or mission-failing behaviors through small, targeted perturbations. The talk concludes by discussing open challenges and outlining a research agenda for principled defenses that span sensing, decision-making, and control in autonomous systems, with particular attention to defending against low-cost but sophisticated drone swarms.


























