VicOne Corporation (VicOne, Shibuya, Tokyo; CEO Max Chen), a subsidiary of Trend Micro Inc. (Shinjuku, Tokyo; CEO Eva Chen), will launch the 'Robotic Hacking Community (RHC)' at DEF CON 34, the world's largest hacker conference, to be held in Las Vegas, USA, from August 6 (Thu) to 9 (Sun), 2026 (local time).
RHC is a community dedicated to the security of robots and physical AI. Building on threat research conducted at LAB R7—an innovation research lab established in 2025—VicOne plans and operates RHC as a platform where researchers, developers, and security researchers can examine and share security challenges related to robot perception, decision-making, and motion.
RHC will feature hands-on workshops and research presentations, with a primary focus on the 'Safety Stress Test,' a Capture The Flag (CTF)-style challenge targeting AI robots. Participants will access a digital twin environment via a challenge API, enabling practical learning in robotics security from both offensive and defensive perspectives.
Expanding Physical AI and Increasingly Complex Safety Risks
Physical AI systems, such as robots, drones, and humanoids, are increasingly being deployed beyond controlled demo environments into factories, warehouses, public spaces, and operational sites. These systems now depend on diverse components—not only mechanical design and control logic, but also sensors, APIs, firmware, AI models, and cloud-connected services—leading to safety risks that cannot be explained by traditional mechanical failures alone. AI robots may follow incorrect instructions, trust tampered AI models, or execute unintended control paths, thereby affecting their perception, decision-making, and motion, even when mechanical components are intact.
Over the past 18 months, LAB R7 has identified over 20 publicly disclosed security incidents and vulnerabilities in the physical AI domain, highlighting the rapid expansion of the attack surface due to increasing robot autonomy, connectivity, and AI integration.
Evaluating Cyber Risks Across Six Domains
The 'Safety Stress Test,' a flagship component of RHC, was developed to evaluate emerging safety risks in physical AI within a controlled digital twin environment. Participants will experience how cyberattacks impact a robot’s perception, decision-making, and motion through a CTF-style format, solving missions on robot models recreated in the digital twin.
Anticipated attack scenarios are categorized into six safety-related domains:
Prompt injection targeting AI robot reasoning
Poisoned AI Policy Models that alter task execution behavior
Adversarial Visual Inputs that deceive AI robot perception
Vulnerabilities in cloud and API environments
Vulnerabilities in robotics communication protocols such as ROS 2 and DDS
Vulnerabilities in the trust chain of embedded firmware
This test leverages Real2Sim, a digital twin built on a physics-based robotics simulator, to recreate the open-source robot 'Reachy Mini Lite' and the mobile manipulator 'LeKiwi.' Participants are provided with individually isolated experimental environments via the challenge API, enabling safe validation of attack scenarios without endangering physical hardware.
Such validation is also valuable for manufacturers and operators seeking to include cyber risks in safety assessments. For manufacturers, this expands the scope of product safety evaluation, pre-deployment testing, and post-market monitoring. For operators, it facilitates linking cyber risks to operational safety when ensuring on-site safety, managing restricted access zones, maintaining system uptime, responding to incidents, and assessing the reliability of AI robots operating near personnel and equipment.
By enabling repeated validation of new attack scenarios in digital twin environments, VicOne applies its expertise in automotive cybersecurity, vulnerability research, and cyber-physical risk assessment to strengthen AI robot security and support the expansion of safety evaluations by manufacturers and operators.
Comment from Max Chen, CEO of VicOne
As large language models (LLMs) and vision-language models (VLMs) are integrated into robots as their 'brains,' prompt injection evolves from merely causing AI to generate incorrect outputs to posing risks where erroneous robot behavior can impact people and surroundings. The safety of AI robots cannot be discussed solely in terms of mechanical reliability. As physical AI systems increasingly perceive their environment, reason, and act, cybersecurity becomes a critical pillar supporting safety.
Overview of 'Robotic Hacking Community' Event
[Conference Name] DEF CON 34
[Dates] August 6 (Thu) – 9 (Sun), 2026 (local time)
[Venue] Las Vegas Convention Center (Las Vegas, Nevada, USA)
[Community Name] Robotic Hacking Community (RHC)
[RHC Venue] West Hall 4, Level 1, Room 1309
[Special Website (English only)] https://robotichackingcommunity.com/
※ Participation in the 'Safety Stress Test' is limited to a maximum of 80 teams.
About VicOne
Established as a subsidiary of Trend Micro, VicOne operates under the vision of securing the future of mobility. The company provides cybersecurity software and services for the increasingly digitalized mobility sector, including connected cars and software-defined vehicles (SDVs), supporting the establishment of comprehensive security frameworks.
Leveraging its technical expertise and threat intelligence from the automotive sector, VicOne is expanding its business into the physical AI domain, including robots, drones, and humanoids. As AI increasingly assumes roles in device decision-making and control, VicOne conducts threat research and develops security technologies for AI robotics through its innovation research lab, LAB R7.
FACT BOX
- Source: PR TIMES
- Category: Event
- Products / services: Robotic Hacking Community / LAB R7