English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

Phantom Force: EMI Attack Fools Robot Tactile Sensors with 9x Forged Grip Force

Forum topic · 二一 · 2026-05-14

Summary

A new attack called "Phantom Force" targets Hall-effect-based tactile sensors used in embodied AI robots. By injecting directed electromagnetic interference, attackers can create phantom force perceptions that are physically indistinguishable from real contact forces. Experiments show the perceived force can be amplified over 9x, the inferred force direction can deviate by 65 degrees, and learning-based tactile classification models can be completely disabled. In practical scenarios, a robot could crush a fragile component while believing it is holding gently, or relax its grip on a hazardous container and drop it. Because both real forces and injected magnetic fields appear as identical magnetic field changes at the sensor level, no hardware-level defense exists yet. The paper, "Phantom Force: Injecting Adversarial Tactile Perceptions into Embodied Intelligence via EMI" by Zirui Kong, Youqian Zhang, and Sze Yiu Chau, was accepted to ACM ASIA CCS 2026 (arXiv:2605.13492), highlighting physical attack surfaces of embodied intelligence beyond model alignment and jailbreaks.

Most AI safety discussions focus on jailbreaks making models say dangerous things. This post argues the scarier attacks target the physical layer: a new attack injects "phantom forces" into robot tactile systems via electromagnetic interference (EMI), making a robot believe it is gently holding an egg while actually squeezing with 9 times the intended force.

The vulnerability: Hall-effect tactile sensors

Many fingertip sensors in embodied AI robots are based on the Hall effect: a small magnet embedded in flexible material shifts slightly on contact, and the sensor measures magnetic field changes to compute force magnitude and direction. These sensors are cheap, durable, and sensitive — but they work by measuring magnetic fields, and magnetic fields can be injected externally.

Researchers show that directed EMI signal injection can make Hall sensors perceive forces that do not exist — "phantom forces."

Attack effects

Experiments demonstrate:

  • Perceived force amplified by more than 9x
  • Inferred force direction deviating by 65 degrees
  • Learning-based tactile classification models fully disabled
  • Robots performing dangerous actions in response to forces that do not exist
  • Example scenarios:

  • A robot arm grips a precision electronic component. An attacker injects signals from several meters away. The sensor reports enormous pressure, so the robot tightens with 9x normal force — crushing the component.
  • A robot carries a hazardous chemical container. Interference makes the sensor report a feather-light force; the robot loosens its grip and drops the container.

Why this went unnoticed

Adversarial attacks on vision (fooling cameras, autonomous driving perception, face recognition) have been studied for years, but tactile attacks were assumed impractical because touch seemed like an inherently "physical" process. That assumption is wrong: if the sensor works on electromagnetic fields and attackers can inject artificial fields, real and phantom forces are indistinguishable at the physics level — both are just magnetic field changes.

Takeaways

This is a physical attack exploiting physics to attack a physical sensor, with no existing defense. AI safety must extend beyond model alignment and jailbreaks: any sensor based on external fields — capacitive, inductive, magnetic — is theoretically vulnerable. The paper's acceptance at ACM ASIA CCS 2026 shows the security community is taking embodied intelligence's physical attack surface seriously.

Reference paper

Zirui Kong, Youqian Zhang, Sze Yiu Chau. "Phantom Force: Injecting Adversarial Tactile Perceptions into Embodied Intelligence via EMI." ACM ASIA CCS 2026, arXiv:2605.13492.

Tags

#robot-security#tactile-sensing#electromagnetic-interference#hall-effect#embodied-ai#adversarial-attack#hardware-security#asia-ccs-2026

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/177620031