
Yuval Elovici
SoK
Cybersecurity Assessment of Humanoid Ecosystem
Humanoids are moving toward practical deployment in healthcare, industrial environments, defense, and public services. Their integration of networked artificial intelligence (AI), physical actuation, and close human interaction introduces security challenges that conventional cyber-physical system (CPS) models do not fully capture. Existing security frameworks often overlook cross-layer vulnerabilities that arise from interactions among hardware, middleware, autonomous decision-making, and human-robot interfaces. We conduct a systematic review of 140 peer-reviewed works published between 2015 and 2025. The analysis shows that most research examines isolated layers, with limited attention to how threats propagate across the humanoid system stack. To address this gap, we introduce a seven-layer security architecture tailored to humanoid platforms and map 39 attack vectors and 35 defense approaches across natural system boundaries. We extend established risk assessment standards (NIST SP 800-30, ISO 27005) with the RISK-MAP framework. RISK-MAP provides a quantitative basis for cross-layer vulnerability analysis and defines two metrics, Cascade Residual Risk (CRR) and Cascade Coverage Index (CCI), validated through Monte Carlo simulation. Empirical evaluation of commercial humanoids shows consistent architectural patterns, with the sensing, processing, and decision-making path forming a dominant channel for cascading vulnerabilities. Our results show that targeted defenses at key layer boundaries reduce systemic risk more effectively than uniform protection strategies. The proposed framework advances humanoid security assessment from qualitative checklists to quantitative, architecture-aware analysis.
| Publication language | English |
| Pages | 319-340 |
| Publication status | Published - 01.01.2026 |