Callisto Technology

Embodied Robot Cybersecurity Solution

Covering robot devices, operating systems, communication, cloud platforms, AI models, Agents, and the motion-control chain, helping robot companies build a full-lifecycle security system that is identifiable, protectable, monitorable, responsive, and auditable.

For humanoid robots, industrial robots, service robots, AGV/AMR, inspection robots, and robot cloud platforms.

Device & System Security
AI & Agent Security
Motion-Control Security
Cloud Operations & Compliance

Supports security analysis and system building around ROS/ROS2, Linux, Android, cloud platforms, OTA, APIs, and third-party components.

1. Perception & Sensors

2. AI Models & Agents

3. Motion Control & Execution

4. Communication, Cloud & OTA

What is Callisto Robot Security?

Callisto Robot Security targets humanoid robots, industrial robots, service robots, AGV/AMR, inspection robots, and robot cloud platforms. Built around five security domains — device and OS, communication and remote operations, AI and Agents, motion control, and cloud platform and security operations — it helps enterprises build identifiable, protectable, monitorable, responsive, and auditable security capabilities across the full R&D, production, delivery, operations, and vulnerability-response lifecycle.

Why do embodied robots need a dedicated cybersecurity system?

Traditional IT attacks usually affect data and business systems, whereas embodied robots can perceive the environment, make decisions, and perform physical actions. Cyberattacks, model attacks, or loss of privilege control can further translate into device loss of control, production disruption, privacy leaks, and personnel safety risks.

A more complex attack surface

Operating systems, ROS/ROS2, middleware, sensors, controllers, wireless communication, cloud platforms, and third-party components jointly form the attack surface.

Cyber risks can become physical risks

Unauthorized control commands, communication hijacking, or policy tampering can affect robot actions and safety boundaries.

AI and Agents introduce new risks

Including prompt injection, unauthorized tool calls, model poisoning, perception spoofing, memory poisoning, and task-planning tampering.

Products need continuous updates and operations

After delivery, robots still require ongoing vulnerability monitoring, OTA remediation, incident response, and version governance.

SYSTEM ARCHITECTURE

A five-layer robot security architecture across edge, network, cloud, and AI

Build security capabilities layer by layer from the robot endpoint to the cloud platform, linked with the AI, Agent, and motion-control chains.

Robot Security Architecture

Layer 1: Device & OS Security

Secure Boot and firmware integrity

Linux / Android / ROS / ROS2 security checks

Process, file, permission, and system-call monitoring

Risk control for USB, debug ports, SSH, ADB, JTAG interfaces

Malicious code and abnormal process detection

Layer 2: Communication & Remote Operations Security

Robot internal network and communication protocol analysis

ROS2 DDS communication security

Wi-Fi, Bluetooth, cellular, and private-network risks

API authentication and access control

Remote operations, debugging, and cloud-control channel security

OTA package signing, integrity verification, and rollback protection

Layer 3: AI, Perception & Agent Security

Vision, voice, and sensor input risk analysis

Adversarial sample and perception-spoofing detection

LLM prompt-injection protection

Agent tool-call permission control

Integrity of models, prompts, knowledge bases, and policy files

Memory-poisoning and task-planning risk analysis

Layer 4: Motion Control & Physical Safety

Safety validation before high-risk action execution

Control-command authorization and anti-replay

Limits on action range, speed, force, and zones

Degradation under anomalies, fail-safe on disconnection, and human takeover

Correlation analysis between cybersecurity and mechanical safety

Layer 5: Cloud Platform & Security Operations

Robot asset, version, and identity management

SBOM and third-party component vulnerability monitoring

Robot cloud platform and scheduling API security

Log ingestion, correlation analysis, and alert handling

Integration with VSOC / Robot-SOC

PSIRT, vulnerability disclosure, remediation, and audit closed loop

Core Robot Security Capabilities

Actionable security modules organized around identify, protect, monitor, respond, and audit.

Attack Surface Analysis & Threat Modeling

Identify attack entries across devices, OS, components, interfaces, communication, cloud services, and AI chains, producing asset inventories, data flows, and risk paths.

Firmware, Software & SBOM Analysis

Perform vulnerability identification, malicious code analysis, and SBOM governance for firmware, OS, ROS packages, container images, and third-party dependencies.

Communication Protocol & Interface Testing

Detect unauthorized access, weak authentication, cleartext transmission, protocol abuse, replay attacks, API privilege escalation, and abnormal data injection.

OTA & Remote Operations Security

Review update-package signing, source authentication, version control, rollback protection, and remote debugging privileges to reduce supply-chain and remote-takeover risks.

Robot Runtime Security Monitoring

Monitor abnormal processes, file changes, permission calls, network connections, resource consumption, and policy deviations, supporting alerts and coordinated handling.

AI & Agent Runtime Security

Identify and constrain prompt injection, unauthorized tool calls, model input attacks, knowledge-base poisoning, and unintended task execution.

Data Security & Privacy Protection

Apply classification, minimized collection, masking, encryption, and access auditing to audio/video, environmental, map, location, personnel, and operational data.

Security Operations & Incident Response

Integrate edge, cloud, and AI events into a unified platform for asset correlation, risk assessment, policy dispatch, remediation tracking, and evidence retention.

The Robot Security Lifecycle from R&D to Operations

Covering six phases: security baseline, threat modeling, testing, remediation design, pre-launch audit, and continuous operations.

01

Security Baseline & Asset Inventory

Input

System architecture, software versions, communication interfaces, cloud platform materials

Output

Asset inventory, SBOM, attack surface list

02

Threat Modeling & Risk Assessment

Input

Asset inventory, attack surface, business and deployment scenarios

Output

Threat model, attack paths, risk grading, remediation priorities

03

Firmware, Software, Interface & Protocol Testing

Input

Firmware and software packages, communication protocols, APIs and remote channels

Output

Vulnerability list, test evidence, reproduction steps, impact analysis

04

Security Capability Design & Remediation

Input

Risk grading, test conclusions, product and R&D constraints

Output

Security architecture, control policies, remediation advice, interface requirements

05

Pre-launch Validation & Delivery Audit

Input

Remediation results, release versions, deployment configuration

Output

Validation report, residual risks, release recommendations, audit evidence

06

Vulnerability Monitoring, OTA Remediation & Continuous Operations

Input

Runtime logs, threat intelligence, live incidents

Output

Vulnerability alerts, impact analysis, remediation tracking, incident reports

Robot Cybersecurity Regulations & Standards Support

There is currently no single global cybersecurity regulation for embodied robots. Robot companies typically need to consider digital product cybersecurity, machinery safety, AI governance, data protection, and operational security requirements at the same time. The applicability of the regulations below should be assessed based on product, use case, market, and deployment model.

Regulation / StandardTypePrimary FocusMeaning for Robot Companies
EU Cyber Resilience Act (CRA)
EU Law
Product cybersecurity, vulnerability handling, security updates, technical documentation, SBOM, and incident reportingApplies to "products with digital elements" within scope (not all robots unconditionally). Main obligations apply from 2027-12-11; known exploited vulnerability and serious incident reporting obligations apply from 2026-09-11.
EU Machinery Regulation 2023/1230
EU Law
Preventing tampering of safety-related software and control systems; linking cyber risk with machinery safetyFirst determine whether the product falls within its scope. As machinery products, robots must incorporate cyber risk into machinery safety assessment.
EU AI Act
EU Law
Risk management, logging, human oversight, robustness, and cybersecurity for high-risk AI systemsRequires assessment based on use case, product regulations, and high-risk classification — not all AI-enabled robots are high-risk AI. Refer to the official timeline as of 2026-07.
NIS2
EU Law
Enterprise risk management, supply chain, incident response, and business continuityApplicability depends on entity sector, size, and member state transposition — not all critical-sector robot operators are automatically subject to NIS2.
IEC 62443
Recommended Standard
Cybersecurity for industrial automation and control systemsAn important reference framework for industrial robot and production-line security design and assessment (not EU law).
ISO 10218 / ISO/TS 15066
Recommended Standard
Safety of industrial robots and collaborative robotsA foundational reference standard for mechanical and collaborative safety design.
ISO 13482
Recommended Standard
Safety of personal care robotsA reference standard for service and care robot safety design.
ETSI EN 303 645
Recommended Standard
Cybersecurity baseline for consumer IoT devicesA baseline security reference for connected robot devices (not EU law).
ISO/IEC 42001
Recommended Standard
AI management systemA reference standard for building AI governance and management systems.

Note: In the table above, the EU CRA, EU Machinery Regulation 2023/1230, EU AI Act, and NIS2 are EU laws; the IEC, ISO, ETSI, and ISO/IEC series are recommended standards or industry reference frameworks, not laws. Specific applicability must be assessed based on product, use case, market, and deployment model. Callisto supports requirement mapping, gap analysis, technical remediation, and compliance evidence building, and does not guarantee certification outcomes.

Applicable Robot Products & Business Scenarios

For each robot form factor, we outline the primary assets, typical risks, and key security capabilities.

Humanoid & Embodied AI Robots

Primary Assets

Perception sensors, AI models and Agents, controllers, operational data

Typical Risks

Perception spoofing, model/Agent privilege escalation, remote takeover, control-command tampering, and privacy data leaks

Key Security Capabilities

AI runtime protection, action safety validation, system integrity monitoring, and behavior auditing

Industrial Arms & Collaborative Robots

Primary Assets

Control programs, ICS network, PLC/controllers, production data

Typical Risks

ICS network intrusion, ransomware, control-program tampering, supply-chain vulnerabilities, and line downtime

Key Security Capabilities

IEC 62443 risk analysis, network segmentation, protocol monitoring, runtime detection, and security operations

AGV / AMR & Smart Logistics Robots

Primary Assets

Scheduling systems, positioning and navigation, wireless communication, task data

Typical Risks

Communication hijacking, positioning spoofing, scheduling privilege abuse, and fleet loss of control

Key Security Capabilities

Communication encryption and authentication, scheduling API security, anomaly monitoring, and coordinated handling

Medical, Elderly Care & Nursing Robots

Primary Assets

Physiological and imaging data, interaction systems, cloud records

Typical Risks

Privacy data leaks, unauthorized access, command tampering, and compliance risks

Key Security Capabilities

Data classification, access auditing, privacy protection, and runtime monitoring

Hotel, Commercial & Delivery Service Robots

Primary Assets

User data, maps and locations, payment and business interfaces

Typical Risks

Privacy leaks, malicious manipulation, API privilege escalation, and business fraud

Key Security Capabilities

Authentication, permission governance, data masking, and anomaly detection

Campus, Power & Energy Inspection Robots

Primary Assets

Imaging and inspection data, communication links, critical infrastructure information

Typical Risks

Communication hijacking, footage tampering, data leaks, and unauthorized control

Key Security Capabilities

Transport encryption, integrity verification, access control, and security operations

Special Operations & Public Safety Robots

Primary Assets

Control channels, mission payloads, location and status data

Typical Risks

Remote takeover, command tampering, communication interference, and privilege escalation

Key Security Capabilities

Strong authentication, anti-replay commands, action safety boundaries, and fail-safe handling

Robot Cloud Platform & Central Scheduling

Primary Assets

Device identities, scheduling APIs, versions and configuration, massive operational data

Typical Risks

API privilege escalation, bulk data leaks, supply-chain risk, and lateral movement

Key Security Capabilities

Asset and identity management, API security, SBOM monitoring, and VSOC / Robot-SOC integration

What Can Customers Get?

Depending on project scope, Callisto can deliver the following robot security outputs.

Robot asset and attack surface inventory

System architecture and data-flow analysis

SBOM and third-party component risk report

Firmware and software vulnerability report

ROS / ROS2 and communication protocol test report

OTA and remote operations security assessment report

AI / Agent risk analysis report

Threat model and attack paths

Remediation recommendations and priorities

Security architecture and control policies

Runtime monitoring and alert rules

PSIRT and vulnerability response process

Regulation/standard mapping and compliance evidence package

The specific delivery scope is determined by product architecture, deployment scenario, and project phase.

Why Choose Callisto?

Integrated across edge, network, cloud, and AI

Rather than focusing on single-device vulnerabilities, we cover robot endpoints, communication links, cloud platforms, AI models, and security operations.

Linking cyber risk with physical risk

We correlate attack paths with control privileges, action impact, and business consequences, helping customers identify the high-risk issues that truly affect product safety.

From assessment to continuous operations

We support security assessment, product remediation, pre-launch validation, vulnerability monitoring, incident response, and operational closed loops.

Transferring automotive-grade system security experience

We extend engineering experience in edge-cloud security, OTA, supply chain, vulnerability management, and security operations from intelligent vehicles to robots.

Robot Cybersecurity FAQ

Robot cybersecurity protects robot devices, operating systems, communication, cloud platforms, AI models, and Agents from unauthorized access, command tampering, and data leaks. It spans the full R&D-to-operations lifecycle, aiming to prevent cyber risks from becoming physical safety risks.

Traditional robot security focuses on devices and networks, while embodied AI security must also cover AI models, perception inputs, and Agent decisions. Because embodied robots perceive the environment and perform physical actions, model attacks and privilege escalation can directly affect action safety.

The main risks include perception spoofing, model or Agent privilege escalation, remote takeover, control-command tampering, and privacy data leaks. Since humanoid robots interact directly with people and the physical environment, these risks can carry physical safety implications.

ROS2 is built on DDS and offers security mechanisms such as SROS2 that support authentication, encryption, and access control, but they may not be enabled by default. Effective risk reduction requires engineering configuration of node permissions, communication policies, and system hardening.

An SBOM (Software Bill of Materials) records the operating systems, open-source components, and third-party dependencies a robot uses. With an SBOM, companies can quickly locate affected components, assess vulnerability impact, and support vulnerability-handling and disclosure requirements under regulations such as the CRA.

Main risks include tampered update packages, untrusted sources, and lack of signature validation and rollback protection. If the OTA channel is abused, attackers may push malicious firmware or affect device availability, so signing, integrity verification, and version control are required.

We recommend enabling strong authentication, least privilege, channel encryption, and access auditing for remote debugging and cloud-control channels, and restricting high-risk entries such as SSH, ADB, and debug ports. All remote actions should be traceable and linked with operational monitoring.

Agents can call tools and drive actions, so prompt injection or unauthorized tool calls may trigger unintended actions. Tool calls need permission control, high-risk actions need pre-execution validation, and behavior logs should be retained for auditing.

IEC 62443 is a recommended standard for industrial automation and control systems, not a mandatory law. It is an important reference for industrial robot and production-line security design and assessment, and many customers and industries adopt it as a security requirement in procurement and audits.

Typically the EU CRA (product cybersecurity), EU Machinery Regulation 2023/1230 (machinery safety), EU AI Act (AI governance), and NIS2 (operational security). Callisto supports requirement mapping, gap analysis, and compliance evidence building, but does not guarantee certification outcomes.

It usually includes monitoring of abnormal processes, file changes, permission calls, network connections, resource consumption, and policy deviations, combined with alerting and coordinated handling. The goal is to promptly identify behavior deviating from normal logic and respond per policy.

Callisto provides attack surface analysis, firmware and SBOM analysis, communication and interface testing, OTA and remote operations security, runtime monitoring, AI/Agent security, data protection, and security operations, covering assessment, remediation, and continuous operations.

It usually requires system architecture, software versions, communication interfaces, cloud platform and OTA materials, plus deployment scenario and target market descriptions. More complete materials help define the priority assessment scope and attack surface list.

On top of a traditional SOC’s asset, log, and response capabilities, a Robot-SOC adds focus on robot endpoints, AI/Agents, and motion control, correlating edge, cloud, and AI events to support security monitoring and handling for large-scale robot operations.

Start Assessing Your Robot System Security Risks

If your product is entering mass production, customer audits, overseas certification, or large-scale operations, Callisto can conduct security assessment and system building around robot endpoints, ROS/ROS2, cloud platforms, OTA, AI Agents, and the supply chain.

Share your product type, system architecture, target market, and current phase, and we will help determine the priority assessment scope.

Last updated: July 2026 · Content by the Callisto Robot Security Team

Contact us to evaluate robot product security

Define the priority assessment scope around robot endpoints, ROS/ROS2, cloud platforms, OTA, AI Agents, and the supply chain.
Callisto (Beijing) Technology Co., Ltd. is a national high-tech enterprise founded by one of the world's first technical experts focusing on automotive network security, invested by world-renowned institutions, and possessing a number of independent intellectual property rights.
GDPR
Chinese vehicle cybersecurity standard:
General Technical Requirements for Automobile Information Security
Comply with" Guidelines for the Construction of Internet of Vehicles Network Security and Data Security Standard System",meet GB/T 40861-2021 "General Technical Requirements for Automobile Information Security", establish and provide automobile network security services. Any data we process for our customers and any risks we discover are the private assets of our customers and cannot be accessed without authorization.
©2022 Callisto (Beijing) Technology Co., Ltd.ICP No. 2022011284-1
ISO/SAE 21434
Vehicle cybersecurity certification:
ISO/SAE 21434 and UN R155UN R156

Contact us for ISO and WP.29 certification services to meet EU regulations.

Tel: 4001059410

Address: 201, Building 2A, Silicon Valley Liangcheng, Haidian District, Beijing