Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius
Pliny the Liberator, Philip Dursey, Adrian Wood, Ads Dawson, Dustin Farley, Sean Hopkins
Black Hat USA 2026 · Day 2 · Briefings
The Black Hat USA talk "Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius" delivered by the BT6 collective, led by Pliny the Liberator, unveiled a critical new dimension in AI security: the direct manipulation of embodied AI systems to induce physical harm. While much of the AI security discourse has historically focused on textual outputs and digital compromises, this presentation starkly illustrated how **Large Language Models (LLMs)**, when integrated with physical robotics, can be coerced into malicious actions with tangible, real-world consequences. The core demonstration involved jailbreaking a **Unitree Go2 Pro** robot dog, powered by **Gemini Robotics ER models**, not through conventional exploits like gaining root access or deploying implants, but purely by manipulating its perception layer through audio and visual prompts.
AI review
Solid work demonstrating a real capability gap — embodied AI systems will execute physically harmful commands that their text-only counterparts refuse. The perception-layer attacks are novel and the firmware vulns are damning. Loses a star because the underlying technique (roleplay jailbreaks, QR injection) isn't new, just newly applied to metal that moves.