{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:VICWIOCY74WXRCUI2CIXDMO6DR","short_pith_number":"pith:VICWIOCY","canonical_record":{"source":{"id":"2605.02900","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-03-28T13:21:44Z","cross_cats_sorted":["cs.AI","cs.CV","cs.RO"],"title_canon_sha256":"13530b6cd35985836d725a6950c5d0acaa6e3f0846ee747cd820daf0c872bf96","abstract_canon_sha256":"95677cc6f92838b71d5d662528f81f56195befbeae360d181fa791961da08934"},"schema_version":"1.0"},"canonical_sha256":"aa05643858ff2d788a88d09171b1de1c702e246d4ada8313d05d54db1da9e1b2","source":{"kind":"arxiv","id":"2605.02900","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.02900","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"arxiv_version","alias_value":"2605.02900v2","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.02900","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"pith_short_12","alias_value":"VICWIOCY74WX","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"pith_short_16","alias_value":"VICWIOCY74WXRCUI","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"pith_short_8","alias_value":"VICWIOCY","created_at":"2026-05-26T02:03:14Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:VICWIOCY74WXRCUI2CIXDMO6DR","target":"record","payload":{"canonical_record":{"source":{"id":"2605.02900","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-03-28T13:21:44Z","cross_cats_sorted":["cs.AI","cs.CV","cs.RO"],"title_canon_sha256":"13530b6cd35985836d725a6950c5d0acaa6e3f0846ee747cd820daf0c872bf96","abstract_canon_sha256":"95677cc6f92838b71d5d662528f81f56195befbeae360d181fa791961da08934"},"schema_version":"1.0"},"canonical_sha256":"aa05643858ff2d788a88d09171b1de1c702e246d4ada8313d05d54db1da9e1b2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T02:03:14.109402Z","signature_b64":"SdWTlyLpbDKLFlg4R/aORXd24b/cXVbclsZWEjzphQNxxHz5OWhN61R7Ifj6Ukjkv8g5HSQhx7K9rqz1wZ+7Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"aa05643858ff2d788a88d09171b1de1c702e246d4ada8313d05d54db1da9e1b2","last_reissued_at":"2026-05-26T02:03:14.108584Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T02:03:14.108584Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.02900","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:03:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PbqjVQkRc/MD1TudXA3/3w5Se/aG1r9/iu+tDW5HS2/EjuYyHefIxRxP0/bmm123jdjt4MIU2rxSstIi8IaVCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T11:08:32.048056Z"},"content_sha256":"41e9378ee3080169b47e1257d1c25a38d14c3c6beeb8f186f0073a6e81cff349","schema_version":"1.0","event_id":"sha256:41e9378ee3080169b47e1257d1c25a38d14c3c6beeb8f186f0073a6e81cff349"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:VICWIOCY74WXRCUI2CIXDMO6DR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Embodied AI requires safety measures that span the full pipeline from perception and planning to physical action and human interaction.","cross_cats":["cs.AI","cs.CV","cs.RO"],"primary_cat":"cs.CR","authors_text":"Bo Li, Chaowei Xiao, Cong Wang, Hanxun Huang, James Bailey, Jianping Wang, Jiayu Li, Jingjing Chen, Jun Sun, Kun Wang, Ming Wen, Qi Zhang, Ran He, Sarah Erfani, Tao Gui, Tiehua Zhang, Xiang Zheng, Xiao Li, Xinfeng Li, Xingjun Ma, Xin Wang, Xinyu Xia, Xipeng Qiu, Xuanjing Huang, Xun Gong, Ye Sun, Yifeng Gao, Yige Li, Yi Liu, Yixin Cao, Yixu Wang, Yu-Gang Jiang, Yunhan Zhao, Yutao Wu, Zhineng Chen, Zhipeng Wei, Zixing Chen, Zuxuan Wu","submitted_at":"2026-03-28T13:21:44Z","abstract_excerpt":"Embodied Artificial Intelligence (Embodied AI) integrates perception, cognition, planning, and interaction into agents that operate in open-world, safety-critical environments. As these systems gain autonomy and enter domains such as transportation, healthcare, and industrial or assistive robotics, ensuring their safety becomes both technically challenging and socially indispensable. Unlike digital AI systems, embodied agents must act under uncertain sensing, incomplete knowledge, and dynamic human-robot interactions, where failures can directly lead to physical harm. This survey provides a co"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"This survey provides a comprehensive and structured review of safety research in embodied AI, examining attacks and defenses across the full embodied pipeline, from perception and cognition to planning, action and interaction, and agentic system, while revealing several overlooked challenges.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The assumption that the selection and synthesis of over 400 papers accurately captures the current state of the field and that the proposed multi-level taxonomy meaningfully unifies previously fragmented research lines.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"The survey organizes over 400 papers on embodied AI safety into a multi-level taxonomy and flags overlooked issues such as fragile multimodal fusion and unstable planning under jailbreaks.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Embodied AI requires safety measures that span the full pipeline from perception and planning to physical action and human interaction.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"f300719ca46111e699ba0f70b0b49b85d0fb8588b45545085340a0c7a223fa69"},"source":{"id":"2605.02900","kind":"arxiv","version":2},"verdict":{"id":"00c7b152-3f48-4965-b79b-c7f9c4a3c79a","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-14T22:17:29.123090Z","strongest_claim":"This survey provides a comprehensive and structured review of safety research in embodied AI, examining attacks and defenses across the full embodied pipeline, from perception and cognition to planning, action and interaction, and agentic system, while revealing several overlooked challenges.","one_line_summary":"The survey organizes over 400 papers on embodied AI safety into a multi-level taxonomy and flags overlooked issues such as fragile multimodal fusion and unstable planning under jailbreaks.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The assumption that the selection and synthesis of over 400 papers accurately captures the current state of the field and that the proposed multi-level taxonomy meaningfully unifies previously fragmented research lines.","pith_extraction_headline":"Embodied AI requires safety measures that span the full pipeline from perception and planning to physical action and human interaction."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.02900/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":1,"snapshot_sha256":"9c645991637464f4172ee8ea2876bfb8ea28833dad0d6f2d59e11261187d234c"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"00c7b152-3f48-4965-b79b-c7f9c4a3c79a"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:03:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BSLoEjHxZ4M7bzcchHgNwE8Dc1BGRLOaalLgKtIfFZRL/xTXNcVb//3FiiIIxdIPLVZDcW5KI0k5ag1/B6RQDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T11:08:32.048853Z"},"content_sha256":"e3eed99e00aa1c755d9e8157e51a89988b11715479b91d80ee625658999dbd34","schema_version":"1.0","event_id":"sha256:e3eed99e00aa1c755d9e8157e51a89988b11715479b91d80ee625658999dbd34"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/VICWIOCY74WXRCUI2CIXDMO6DR/bundle.json","state_url":"https://pith.science/pith/VICWIOCY74WXRCUI2CIXDMO6DR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/VICWIOCY74WXRCUI2CIXDMO6DR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T11:08:32Z","links":{"resolver":"https://pith.science/pith/VICWIOCY74WXRCUI2CIXDMO6DR","bundle":"https://pith.science/pith/VICWIOCY74WXRCUI2CIXDMO6DR/bundle.json","state":"https://pith.science/pith/VICWIOCY74WXRCUI2CIXDMO6DR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/VICWIOCY74WXRCUI2CIXDMO6DR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:VICWIOCY74WXRCUI2CIXDMO6DR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"95677cc6f92838b71d5d662528f81f56195befbeae360d181fa791961da08934","cross_cats_sorted":["cs.AI","cs.CV","cs.RO"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-03-28T13:21:44Z","title_canon_sha256":"13530b6cd35985836d725a6950c5d0acaa6e3f0846ee747cd820daf0c872bf96"},"schema_version":"1.0","source":{"id":"2605.02900","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.02900","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"arxiv_version","alias_value":"2605.02900v2","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.02900","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"pith_short_12","alias_value":"VICWIOCY74WX","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"pith_short_16","alias_value":"VICWIOCY74WXRCUI","created_at":"2026-05-26T02:03:14Z"},{"alias_kind":"pith_short_8","alias_value":"VICWIOCY","created_at":"2026-05-26T02:03:14Z"}],"graph_snapshots":[{"event_id":"sha256:e3eed99e00aa1c755d9e8157e51a89988b11715479b91d80ee625658999dbd34","target":"graph","created_at":"2026-05-26T02:03:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"This survey provides a comprehensive and structured review of safety research in embodied AI, examining attacks and defenses across the full embodied pipeline, from perception and cognition to planning, action and interaction, and agentic system, while revealing several overlooked challenges."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The assumption that the selection and synthesis of over 400 papers accurately captures the current state of the field and that the proposed multi-level taxonomy meaningfully unifies previously fragmented research lines."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"The survey organizes over 400 papers on embodied AI safety into a multi-level taxonomy and flags overlooked issues such as fragile multimodal fusion and unstable planning under jailbreaks."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Embodied AI requires safety measures that span the full pipeline from perception and planning to physical action and human interaction."}],"snapshot_sha256":"f300719ca46111e699ba0f70b0b49b85d0fb8588b45545085340a0c7a223fa69"},"formal_canon":{"evidence_count":1,"snapshot_sha256":"9c645991637464f4172ee8ea2876bfb8ea28833dad0d6f2d59e11261187d234c"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.02900/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Embodied Artificial Intelligence (Embodied AI) integrates perception, cognition, planning, and interaction into agents that operate in open-world, safety-critical environments. As these systems gain autonomy and enter domains such as transportation, healthcare, and industrial or assistive robotics, ensuring their safety becomes both technically challenging and socially indispensable. Unlike digital AI systems, embodied agents must act under uncertain sensing, incomplete knowledge, and dynamic human-robot interactions, where failures can directly lead to physical harm. This survey provides a co","authors_text":"Bo Li, Chaowei Xiao, Cong Wang, Hanxun Huang, James Bailey, Jianping Wang, Jiayu Li, Jingjing Chen, Jun Sun, Kun Wang, Ming Wen, Qi Zhang, Ran He, Sarah Erfani, Tao Gui, Tiehua Zhang, Xiang Zheng, Xiao Li, Xinfeng Li, Xingjun Ma, Xin Wang, Xinyu Xia, Xipeng Qiu, Xuanjing Huang, Xun Gong, Ye Sun, Yifeng Gao, Yige Li, Yi Liu, Yixin Cao, Yixu Wang, Yu-Gang Jiang, Yunhan Zhao, Yutao Wu, Zhineng Chen, Zhipeng Wei, Zixing Chen, Zuxuan Wu","cross_cats":["cs.AI","cs.CV","cs.RO"],"headline":"Embodied AI requires safety measures that span the full pipeline from perception and planning to physical action and human interaction.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-03-28T13:21:44Z","title":"Safety in Embodied AI: A Survey of Risks, Attacks, and Defenses"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.02900","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-14T22:17:29.123090Z","id":"00c7b152-3f48-4965-b79b-c7f9c4a3c79a","model_set":{"reader":"grok-4.3"},"one_line_summary":"The survey organizes over 400 papers on embodied AI safety into a multi-level taxonomy and flags overlooked issues such as fragile multimodal fusion and unstable planning under jailbreaks.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Embodied AI requires safety measures that span the full pipeline from perception and planning to physical action and human interaction.","strongest_claim":"This survey provides a comprehensive and structured review of safety research in embodied AI, examining attacks and defenses across the full embodied pipeline, from perception and cognition to planning, action and interaction, and agentic system, while revealing several overlooked challenges.","weakest_assumption":"The assumption that the selection and synthesis of over 400 papers accurately captures the current state of the field and that the proposed multi-level taxonomy meaningfully unifies previously fragmented research lines."}},"verdict_id":"00c7b152-3f48-4965-b79b-c7f9c4a3c79a"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:41e9378ee3080169b47e1257d1c25a38d14c3c6beeb8f186f0073a6e81cff349","target":"record","created_at":"2026-05-26T02:03:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"95677cc6f92838b71d5d662528f81f56195befbeae360d181fa791961da08934","cross_cats_sorted":["cs.AI","cs.CV","cs.RO"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-03-28T13:21:44Z","title_canon_sha256":"13530b6cd35985836d725a6950c5d0acaa6e3f0846ee747cd820daf0c872bf96"},"schema_version":"1.0","source":{"id":"2605.02900","kind":"arxiv","version":2}},"canonical_sha256":"aa05643858ff2d788a88d09171b1de1c702e246d4ada8313d05d54db1da9e1b2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"aa05643858ff2d788a88d09171b1de1c702e246d4ada8313d05d54db1da9e1b2","first_computed_at":"2026-05-26T02:03:14.108584Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:03:14.108584Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"SdWTlyLpbDKLFlg4R/aORXd24b/cXVbclsZWEjzphQNxxHz5OWhN61R7Ifj6Ukjkv8g5HSQhx7K9rqz1wZ+7Cw==","signature_status":"signed_v1","signed_at":"2026-05-26T02:03:14.109402Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.02900","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:41e9378ee3080169b47e1257d1c25a38d14c3c6beeb8f186f0073a6e81cff349","sha256:e3eed99e00aa1c755d9e8157e51a89988b11715479b91d80ee625658999dbd34"],"state_sha256":"b76ba94e1f18784c7ea07624f8544ab2de88b7b10783e3c01e1f25df599e6f6e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PwxvuRGE7G0YHo6NmbMQQx9nzneB11TA3NDB2Fl5jeu2H5DVv+j7e6XxVLk2UYwTW4syL30P2WNdI160FEbFAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T11:08:32.052920Z","bundle_sha256":"22c22cbca4127a0fabe4aa38b543604efdc864761572c09e84ad497046a3c729"}}