Page 1 of 1

SE Humanoid Compute, Security More Complex Than AVs

Posted: Thu Sep 03, 2026 7:03 am
by admin
Key Takeaways:
  • Distributed compute includes AI-enabled MCUs/NPUs in the palm of the hand to pre-process finger data, while a centralized compute system often features a GPU to process the raw inputs from all sensors via an FPGA-based sensor bridge and Ethernet.
  • Hybrid architectures are needed to accommodate various robotics applications, some of which will feature cloud-connected large language models and vision-language-action models. Others will benefit from targeted small language models.
  • A wide variety of sensors, models, and connectivity options create a broad attack surface. Worst-case scenarios could include a man-in-the-middle attack, where compromised LLMs manipulate vulnerable groups such as the elderly and children using a natural language interface.
The market for robots and humanoids is growing rapidly for industrial applications, but it’s poised for much faster growth if battery life can be extended beyond just a few hours, costs can be reduced, and these systems of systems can be secured against hackers. In the U.S., robotic sales reached $11.4 billion in 2026, up 29% year over year, according to a Robotics Center report. Amazon Robotics currently dominates the U.S. market, while other companies vie for a slice of the future. These include Figure AI, Agility Robotics, Apptronik, Tesla (Optimus), Boston Dynamics, Physical Intelligence (Pi), 1X Technologies, Covariant, and Skild AI. [1] The report noted that these companies integrate AI, vision-language-action models (VLAs), and foundation models as a core architectural element. They do not retrofit AI onto conventional robots. Instead, they offer AI as the product, with hardware as the delivery mechanism. Chip architectures in some humanoid robots resemble software-defined, autonomous vehicles with distributed, zonal compute. Others resemble a drone with centralized compute. The common denominator for all kinds of robots is a heterogeneous architecture comprised of MCUs, MPUs, CPUs, GPUs, image signal processing, and digital signal processing. “Humanoid compute is likely to be a hybrid model of a central powerful processing system with distributed or zonal compute for pre-processing of data from places such as the fingers,” said Ronald Stärz, system architect for humanoid robots at Infineon Technologies. “This mirrors the shift automotive already made, from centralized ECUs to zonal architectures, driven by latency, bandwidth, and fault tolerance requirements. Humanoid robotics is arriving at the same conclusion. The architecture has two layers — a central AI unit handles high-level inference and planning, with a dedicated microcontroller acting as its safety companion at the main compute level. Distributed microcontrollers at the joint level handle real-time processing and local actuation. Safety must never be left to the AI model alone. A separate, certified hardware component must enable it. The performance of the overall system is ultimately defined by its chips.” Others agree that hybrid architectures are likely. “While centralized compute may be best suited for global perception, scene understanding, task planning and overall coordination across the chassis, distributed localized compute may be advantageous for ultra-fast local control loops, such as those required for hands, feet, balance systems, tactile feedback and collision avoidance,” said Edo Cohen, chair, MIPI Alliance Physical AI Birds of a Feather (BoF) Group. “In hybrid architectures, a central processor determines the higher-level task — what object to pick up, where to move it, and how to sequence the action — while localized compute within a robotic hand performs real-time inference to adjust grip force within milliseconds. However, from a bill-of-materials, power, and system complexity perspective, adopting a centralized compute architecture leveraging high-speed interfaces may be the most efficient approach because it can reduce component count, simplify system integration, and streamline software development. We expect the market to adopt a mix of centralized and hybrid architectures based on specific use-case requirements and future technology advancements.” In a humanoid robot, inputs come from multi-modal sensors, including cameras, microphones, radar, lidar, ultrasonic sensors, and a variety of touch sensors such as magnetic, capacitive, and resistive. Touch sensing, in particular, is advancing as the humanoid segment grows. “Earlier robotic systems, such as older Roombas, used simple bump sensors that functioned as switches, triggering different responses based on the type of collision,” said Amit Kumar, director of automotive product management for Tensilica products at Cadence. “For example, hitting a solid wall might cause a 45-degree turn, whereas a softer obstacle might result in a smaller adjustment. However, humanoids need to be far more sophisticated and responsive. Adaptive manipulation enables the robot to grip objects securely without crushing or slipping them. Tactile sensors at the fingertips provide continuous feedback on how much force to apply.” A centralized approach to compute uses the same type of front-end sensors as a distributed system, except they will not be AI-enabled. They will be dumb instead of smart. “You can fuse the data afterward, and get the best out of each sensor,” said Giovanni Campanella, robotics and industrial automation general manager at Texas Instruments. “In the end, you want those robots to be human-like, so the space is very limited. Small sensors without AI processing on the edge let you add more sensors for better perception and safety. Putting processing in one place enables miniaturization to fit the robot’s form factor and helps with power and battery runtime. If you have a lot of small processors with the sensors, they all use power. The GPU will also consume a lot of power, but as you add more and more [dumb] sensors, you move the power to just one place. Then you can work on optimizing that.” Raw sensor data can be streamed into an FPGA-based sensor bridge (such as Nvidia’s HoloScan), which packetizes it over Ethernet. “Then the magic happens in the GPU, where there will be AI models that get raw data from the sensors, and basically perceive everything that is happening — objects on the paths of the robot, humans walking by, kids, pets, and high-speed objects,” said Campanella. However, choosing an architecture involves more than AI acceleration. “It’s the entire pipeline,” said Nebu Philips, senior director of strategy and business development at Synaptics. “You’re bringing in a stream. You’re decoding, so you have hardware decoders built in. Or, you could use the CPUs for a soft ISP. It depends on what kind of processing you’re doing, what aggregation point, and whether you’re talking about a humanoid design or cobots and service robots. There’s no one-size-fits-all. If you look at the latest SDK releases from Nvidia, they talk about a certain amount of inferencing happening in different areas, with things like HoloScan. They enable APIs to connect into a larger processing framework. Does it have to be a simple ship of every function to a cold GPU? No. They’re allowing these bridge functions so you can do more, making the overall architecture more scalable and efficient. That’s where we are in that market evolution phase.” Distributed compute: cloud to robot to limb  Like much of the edge landscape, robotics is toggling between localized AI processing and the cloud. Humanoids might connect to the cloud for ongoing training of LLMs and other forms of AI, such as vision-language-action models, but edge AI processing offers many benefits. “Both approaches will always be taken,” said Matthew Bubis, director of product management at Imagination Technologies. “It depends on the company’s balance of priorities. Do they want full control over their systems, with privacy of their data? Do they want control over internal costs and the specific design of what computers run and how they run it? If they want all that, then they’ll be choosing a local, edge-based solution, whereas, if that company is providing a network of robots and systems that then operates in an environment that has excellent data center access, that could be either wired or wireless. And if they have to do very intensive compute operations that can’t be localized, then they’re likely to pick the data center-based solutions. It really depends on the balance of that particular company’s parameters and what they prioritize. There’s never going to be a one-size-fits-all solution of either local or centralized AI processing.” Humanoid security versus autonomous vehicles Humanoids and autonomous vehicles are both fast-moving applications with many opportunities, but each has different risks. “Humanoids introduce security risks distinct from autonomous vehicles,” said Infineon’s Stärz. “Physical proximity is the key difference. A vehicle operates in a defined domain. A humanoid operates in homes, hospitals, and schools, in direct contact with people. A compromised system in that setting carries immediate, personal consequences. The convergence of functional safety and cybersecurity is critical. A cyberattack on a digital system costs data. On a physically capable robot, it can cause physical harm. These disciplines must be addressed together at the chip level. Infineon builds security in at the chip level, not as a software layer afterward. Our chips give robots a built-in identity, secure boot, protected key storage, and encrypted communications. Our portfolio is also post-quantum-cryptography-ready and complies with the EU Cyber Resilience Act, EU AI Act, and Common Criteria standards. Cybersecurity certification is not an obstacle. It is the foundation of public trust.” One area where humanoids and vehicles diverge is AI perception security. “You really need to have protection for model integrity,” said Dana Neustadter, senior director of product management at Synopsys. “How do you load the AI or make an AI update securely and be able to have runtime protection? The liability and compliance will be much more complex, and should be, for these kinds of robots compared to cars. Both are physical AI, but humanoids add another level of complexity. The technology is moving far ahead so fast that the regulations and governance are falling behind, and the geopolitical situation makes things even more complex and complicated.” Image Fig. 1: A humanoid robot in a factory setting. Source: Synopsys Humanoid robots are IoT devices, so legacy wisdom related to standards and regulations applies. “Humanoids are not perceived as IoT technologies owing to their human appearance, which means new risks can arise from stealth of information by realistic scams and confusion between a real, authorized agent and a machine, with privacy violations including short-distance eavesdropping, and impersonation,” noted Sylvain Guilley, chief technology officer and co-founder at Secure-IC, a Cadence company. Humanoid hacks could extend current phone and email scams. “An AI can call me and try to pretend they are an actual vendor, for example,” said Guilley. “I trust you because you sound natural. If we have a very fluid interaction, but all of a sudden you change avatars, and now you look like my boss, I will give you all the information. This is a real threat with humanoids. We tend to trust them because the difference between the machine and the human is smaller. It will be increasingly difficult to know what you are dealing with.” For example, while last-mile delivery robots tend to look cute, they could easily be spies. “During COVID, everyone started using Zoom, and it turned out that some people could connect and just listen and spy on the discussions. If we have a conference call, how do you even trust who is joining?” said Guilley. “AI will interact very smartly and be discreet enough to be believed as someone real. I’ve already seen some people manipulating avatars on the dark web to trade things, and those avatars were animated by real humans and understood their situation awareness.” All the layers of a robotics chip system are susceptible. “It’s all the layers, because to be smart, you need the power of the chips,” said Guilley. “You need inference on chip and reinforcement learning on chip. A human being is someone who is able to remain relevant, taking into account the context, so you need this capability of models that can reinforce themselves, so you need the computing power, but then manipulation will be more at a higher layer — the layer of how you put your agents together, what you prompt your agents to do, and it will happen. It’s no longer sci-fi.” Additional threat surfaces Vision is another attack surface. “The vision feeds directly into the control, the manipulation, and all the decisions that a robot has to make, and you can do a lot of things to exploit camera firmware, such as model-level attacks, where there is data poisoning via an over-the-air update, or privacy leakage,” said Neustadter. “You can have really unsafe manipulation of this robot, and it can grasp the wrong object. They can walk into dangerous spaces, or make unsafe gestures.” Wi-Fi and wireless communication also pose risks. “This is dangerous because it’s a remote architecture,” observed Neustadter. “It needs legal authentication, and it’s also prone to man-in-the-middle attacks or over-the-air firmware poisoning. The impact is that you can take over the full robot, send commands, and influence it.” Those communication risks underscore why authentication cannot depend on a single signal or interaction channel. And that makes multi-modal authentication an important safeguard. John Weil, vice president and general manager for IoT and edge AI processor business at Synaptics, explained that a second modality is needed. “Voice is not enough. You can add a touch event. You could add fingerprint, or camera plus voice. It helps with ID and context. The machine can see your eyes, and understands you’re present.” Conclusion: flexibility is key Open standards make it easier for more robotics developers to get involved in what is still a wide-open race with many obstacles along the way. “MIPI’s specifications offer architectural flexibility,” said Cohen. “Humanoid developers can leverage a homogeneous portfolio of standardized embedded interfaces that deliver the speed, latency, power efficiency, thermal performance, safety and reliability needed for the various application areas — whether for vision, display, actuator control, or flash storage. Beyond meeting technical system requirements, standardized interfaces also increase supplier interoperability and choice, improve economies of scale, and shorten development cycles.” Another option is RISC-V, which is an open standard. “Customers aren’t asking when to adopt RISC-V. They’re asking how they go RISC-V,” said James Prior, head of marketing at MIPS, a GlobalFoundries company. “Who do they partner with? If you think about robotics as similar to automotive and industrial, are they known for taking risks? Are aerospace guys risk takers? No, by definition, they literally have people’s lives in their hands. They don’t want to experiment, and that’s why they want this software-defined architecture, software-first approach, open standards-based technology, and a vibrant ecosystem.” Instead of taking a hardware-first approach, companies are thinking software first. “Usually, companies build the hardware, and then they build the virtual model afterward and say, ‘This is the model of what we built,’” said Prior. “Instead, it should be, ‘This is the model of what we want to build. Now, let’s make it physical.’ Logically, that would be the way that you do that, because the virtual one is much easier to change and cheaper to update than the physical one.” Humanoid developers must know their goal and the end application. This ensures they choose the correct architecture and avoid over-designing or under-designing. “For humanoids or mobile robots, it’s super important because over-designing might mean your robot runs out of battery in 30 minutes; then the ROI is gone,” said TI’s Campanella. “You could have two or three GPUs. Maybe your robot can do everything. It’s amazing, but then it runs out of power in 15 minutes. Or it costs you something you cannot even afford. Then you won’t sell your robot anymore. The architecture depends on where the robot will be deployed. What do you want your robot to do? You design your robot to meet those things.” At least for now, one size does not fit all. “There are so many things that come into the game — how many sensors, how many cameras, the level of dexterity of the robot,” Campanella said. “It’s very difficult to say what chips go where.” References [1] State of Robotics 2026: Frontier science, scaled by software (Robotics Center) Related Articles
Humanoid Touch And Voice Are Improving Rapidly
General-purpose humanoid robots need all their senses to function equally well; vision and movement are the farthest along, but others are catching up. Fine-Tuning Humanoid Vision And Movement
Ongoing innovations are enabling humanoids to see and move more like humans; smell and taste are next. The post Humanoid Compute, Security More Complex Than AVs appeared first on Semiconductor Engineering.

Source: https://semiengineering.com/humanoid-co ... -than-avs/