SE Humanoid Compute, Security More Complex Than AVs
Posted: Thu Sep 03, 2026 7:03 am
Key Takeaways:
Fig. 1: A humanoid robot in a factory setting. Source: Synopsys Humanoid robots are IoT devices, so legacy wisdom related to standards and regulations applies. “Humanoids are not perceived as IoT technologies owing to their human appearance, which means new risks can arise from stealth of information by realistic scams and confusion between a real, authorized agent and a machine, with privacy violations including short-distance eavesdropping, and impersonation,” noted Sylvain Guilley, chief technology officer and co-founder at Secure-IC, a Cadence company. Humanoid hacks could extend current phone and email scams. “An AI can call me and try to pretend they are an actual vendor, for example,” said Guilley. “I trust you because you sound natural. If we have a very fluid interaction, but all of a sudden you change avatars, and now you look like my boss, I will give you all the information. This is a real threat with humanoids. We tend to trust them because the difference between the machine and the human is smaller. It will be increasingly difficult to know what you are dealing with.” For example, while last-mile delivery robots tend to look cute, they could easily be spies. “During COVID, everyone started using Zoom, and it turned out that some people could connect and just listen and spy on the discussions. If we have a conference call, how do you even trust who is joining?” said Guilley. “AI will interact very smartly and be discreet enough to be believed as someone real. I’ve already seen some people manipulating avatars on the dark web to trade things, and those avatars were animated by real humans and understood their situation awareness.” All the layers of a robotics chip system are susceptible. “It’s all the layers, because to be smart, you need the power of the chips,” said Guilley. “You need inference on chip and reinforcement learning on chip. A human being is someone who is able to remain relevant, taking into account the context, so you need this capability of models that can reinforce themselves, so you need the computing power, but then manipulation will be more at a higher layer — the layer of how you put your agents together, what you prompt your agents to do, and it will happen. It’s no longer sci-fi.” Additional threat surfaces Vision is another attack surface. “The vision feeds directly into the control, the manipulation, and all the decisions that a robot has to make, and you can do a lot of things to exploit camera firmware, such as model-level attacks, where there is data poisoning via an over-the-air update, or privacy leakage,” said Neustadter. “You can have really unsafe manipulation of this robot, and it can grasp the wrong object. They can walk into dangerous spaces, or make unsafe gestures.” Wi-Fi and wireless communication also pose risks. “This is dangerous because it’s a remote architecture,” observed Neustadter. “It needs legal authentication, and it’s also prone to man-in-the-middle attacks or over-the-air firmware poisoning. The impact is that you can take over the full robot, send commands, and influence it.” Those communication risks underscore why authentication cannot depend on a single signal or interaction channel. And that makes multi-modal authentication an important safeguard. John Weil, vice president and general manager for IoT and edge AI processor business at Synaptics, explained that a second modality is needed. “Voice is not enough. You can add a touch event. You could add fingerprint, or camera plus voice. It helps with ID and context. The machine can see your eyes, and understands you’re present.” Conclusion: flexibility is key Open standards make it easier for more robotics developers to get involved in what is still a wide-open race with many obstacles along the way. “MIPI’s specifications offer architectural flexibility,” said Cohen. “Humanoid developers can leverage a homogeneous portfolio of standardized embedded interfaces that deliver the speed, latency, power efficiency, thermal performance, safety and reliability needed for the various application areas — whether for vision, display, actuator control, or flash storage. Beyond meeting technical system requirements, standardized interfaces also increase supplier interoperability and choice, improve economies of scale, and shorten development cycles.” Another option is RISC-V, which is an open standard. “Customers aren’t asking when to adopt RISC-V. They’re asking how they go RISC-V,” said James Prior, head of marketing at MIPS, a GlobalFoundries company. “Who do they partner with? If you think about robotics as similar to automotive and industrial, are they known for taking risks? Are aerospace guys risk takers? No, by definition, they literally have people’s lives in their hands. They don’t want to experiment, and that’s why they want this software-defined architecture, software-first approach, open standards-based technology, and a vibrant ecosystem.” Instead of taking a hardware-first approach, companies are thinking software first. “Usually, companies build the hardware, and then they build the virtual model afterward and say, ‘This is the model of what we built,’” said Prior. “Instead, it should be, ‘This is the model of what we want to build. Now, let’s make it physical.’ Logically, that would be the way that you do that, because the virtual one is much easier to change and cheaper to update than the physical one.” Humanoid developers must know their goal and the end application. This ensures they choose the correct architecture and avoid over-designing or under-designing. “For humanoids or mobile robots, it’s super important because over-designing might mean your robot runs out of battery in 30 minutes; then the ROI is gone,” said TI’s Campanella. “You could have two or three GPUs. Maybe your robot can do everything. It’s amazing, but then it runs out of power in 15 minutes. Or it costs you something you cannot even afford. Then you won’t sell your robot anymore. The architecture depends on where the robot will be deployed. What do you want your robot to do? You design your robot to meet those things.” At least for now, one size does not fit all. “There are so many things that come into the game — how many sensors, how many cameras, the level of dexterity of the robot,” Campanella said. “It’s very difficult to say what chips go where.” References [1] State of Robotics 2026: Frontier science, scaled by software (Robotics Center) Related Articles
Humanoid Touch And Voice Are Improving Rapidly
General-purpose humanoid robots need all their senses to function equally well; vision and movement are the farthest along, but others are catching up. Fine-Tuning Humanoid Vision And Movement
Ongoing innovations are enabling humanoids to see and move more like humans; smell and taste are next. The post Humanoid Compute, Security More Complex Than AVs appeared first on Semiconductor Engineering.
Source: https://semiengineering.com/humanoid-co ... -than-avs/
- Distributed compute includes AI-enabled MCUs/NPUs in the palm of the hand to pre-process finger data, while a centralized compute system often features a GPU to process the raw inputs from all sensors via an FPGA-based sensor bridge and Ethernet.
- Hybrid architectures are needed to accommodate various robotics applications, some of which will feature cloud-connected large language models and vision-language-action models. Others will benefit from targeted small language models.
- A wide variety of sensors, models, and connectivity options create a broad attack surface. Worst-case scenarios could include a man-in-the-middle attack, where compromised LLMs manipulate vulnerable groups such as the elderly and children using a natural language interface.
Fig. 1: A humanoid robot in a factory setting. Source: Synopsys Humanoid robots are IoT devices, so legacy wisdom related to standards and regulations applies. “Humanoids are not perceived as IoT technologies owing to their human appearance, which means new risks can arise from stealth of information by realistic scams and confusion between a real, authorized agent and a machine, with privacy violations including short-distance eavesdropping, and impersonation,” noted Sylvain Guilley, chief technology officer and co-founder at Secure-IC, a Cadence company. Humanoid hacks could extend current phone and email scams. “An AI can call me and try to pretend they are an actual vendor, for example,” said Guilley. “I trust you because you sound natural. If we have a very fluid interaction, but all of a sudden you change avatars, and now you look like my boss, I will give you all the information. This is a real threat with humanoids. We tend to trust them because the difference between the machine and the human is smaller. It will be increasingly difficult to know what you are dealing with.” For example, while last-mile delivery robots tend to look cute, they could easily be spies. “During COVID, everyone started using Zoom, and it turned out that some people could connect and just listen and spy on the discussions. If we have a conference call, how do you even trust who is joining?” said Guilley. “AI will interact very smartly and be discreet enough to be believed as someone real. I’ve already seen some people manipulating avatars on the dark web to trade things, and those avatars were animated by real humans and understood their situation awareness.” All the layers of a robotics chip system are susceptible. “It’s all the layers, because to be smart, you need the power of the chips,” said Guilley. “You need inference on chip and reinforcement learning on chip. A human being is someone who is able to remain relevant, taking into account the context, so you need this capability of models that can reinforce themselves, so you need the computing power, but then manipulation will be more at a higher layer — the layer of how you put your agents together, what you prompt your agents to do, and it will happen. It’s no longer sci-fi.” Additional threat surfaces Vision is another attack surface. “The vision feeds directly into the control, the manipulation, and all the decisions that a robot has to make, and you can do a lot of things to exploit camera firmware, such as model-level attacks, where there is data poisoning via an over-the-air update, or privacy leakage,” said Neustadter. “You can have really unsafe manipulation of this robot, and it can grasp the wrong object. They can walk into dangerous spaces, or make unsafe gestures.” Wi-Fi and wireless communication also pose risks. “This is dangerous because it’s a remote architecture,” observed Neustadter. “It needs legal authentication, and it’s also prone to man-in-the-middle attacks or over-the-air firmware poisoning. The impact is that you can take over the full robot, send commands, and influence it.” Those communication risks underscore why authentication cannot depend on a single signal or interaction channel. And that makes multi-modal authentication an important safeguard. John Weil, vice president and general manager for IoT and edge AI processor business at Synaptics, explained that a second modality is needed. “Voice is not enough. You can add a touch event. You could add fingerprint, or camera plus voice. It helps with ID and context. The machine can see your eyes, and understands you’re present.” Conclusion: flexibility is key Open standards make it easier for more robotics developers to get involved in what is still a wide-open race with many obstacles along the way. “MIPI’s specifications offer architectural flexibility,” said Cohen. “Humanoid developers can leverage a homogeneous portfolio of standardized embedded interfaces that deliver the speed, latency, power efficiency, thermal performance, safety and reliability needed for the various application areas — whether for vision, display, actuator control, or flash storage. Beyond meeting technical system requirements, standardized interfaces also increase supplier interoperability and choice, improve economies of scale, and shorten development cycles.” Another option is RISC-V, which is an open standard. “Customers aren’t asking when to adopt RISC-V. They’re asking how they go RISC-V,” said James Prior, head of marketing at MIPS, a GlobalFoundries company. “Who do they partner with? If you think about robotics as similar to automotive and industrial, are they known for taking risks? Are aerospace guys risk takers? No, by definition, they literally have people’s lives in their hands. They don’t want to experiment, and that’s why they want this software-defined architecture, software-first approach, open standards-based technology, and a vibrant ecosystem.” Instead of taking a hardware-first approach, companies are thinking software first. “Usually, companies build the hardware, and then they build the virtual model afterward and say, ‘This is the model of what we built,’” said Prior. “Instead, it should be, ‘This is the model of what we want to build. Now, let’s make it physical.’ Logically, that would be the way that you do that, because the virtual one is much easier to change and cheaper to update than the physical one.” Humanoid developers must know their goal and the end application. This ensures they choose the correct architecture and avoid over-designing or under-designing. “For humanoids or mobile robots, it’s super important because over-designing might mean your robot runs out of battery in 30 minutes; then the ROI is gone,” said TI’s Campanella. “You could have two or three GPUs. Maybe your robot can do everything. It’s amazing, but then it runs out of power in 15 minutes. Or it costs you something you cannot even afford. Then you won’t sell your robot anymore. The architecture depends on where the robot will be deployed. What do you want your robot to do? You design your robot to meet those things.” At least for now, one size does not fit all. “There are so many things that come into the game — how many sensors, how many cameras, the level of dexterity of the robot,” Campanella said. “It’s very difficult to say what chips go where.” References [1] State of Robotics 2026: Frontier science, scaled by software (Robotics Center) Related ArticlesHumanoid Touch And Voice Are Improving Rapidly
General-purpose humanoid robots need all their senses to function equally well; vision and movement are the farthest along, but others are catching up. Fine-Tuning Humanoid Vision And Movement
Ongoing innovations are enabling humanoids to see and move more like humans; smell and taste are next. The post Humanoid Compute, Security More Complex Than AVs appeared first on Semiconductor Engineering.
Source: https://semiengineering.com/humanoid-co ... -than-avs/