{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T02:25:03Z","timestamp":1777775103921,"version":"3.51.4"},"reference-count":13,"publisher":"American Association for the Advancement of Science (AAAS)","issue":"113","content-domain":{"domain":["www.science.org"],"crossmark-restriction":true},"short-container-title":["Sci. Robot."],"published-print":{"date-parts":[[2026,4,29]]},"abstract":"<jats:p>Because AI-enabled robots can be tricked into taking unsafe actions, they require layered, context-aware safety guardrails.<\/jats:p>","DOI":"10.1126\/scirobotics.aef2191","type":"journal-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T18:01:01Z","timestamp":1777485661000},"update-policy":"https:\/\/doi.org\/10.34133\/aaas_crossmark","source":"Crossref","is-referenced-by-count":0,"title":["Beyond alignment: Why robotic foundation models need context-aware safety"],"prefix":"10.1126","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-5693-2819","authenticated-orcid":true,"given":"Alexander","family":"Robey","sequence":"first","affiliation":[{"name":"Machine Learning Department, Carnegie Mellon University, Pittsburgh, PA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-4380-3212","authenticated-orcid":true,"given":"Zachary","family":"Ravichandran","sequence":"additional","affiliation":[{"name":"Department of Electrical and Systems Engineering, University of Pennsylvania, Philadelphia, PA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eliot Krzysztof","family":"Jones","sequence":"additional","affiliation":[{"name":"Independent researcher, San Francisco, CA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jared","family":"Perlo","sequence":"additional","affiliation":[{"name":"Independent researcher, New York, NY, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-1889-6577","authenticated-orcid":true,"given":"Fazl","family":"Barez","sequence":"additional","affiliation":[{"name":"Oxford Martin School, University of Oxford, Oxford, UK."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3902-9391","authenticated-orcid":true,"given":"Vijay","family":"Kumar","sequence":"additional","affiliation":[{"name":"Department of Electrical and Systems Engineering, University of Pennsylvania, Philadelphia, PA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8106-5759","authenticated-orcid":true,"given":"J. Zico","family":"Kolter","sequence":"additional","affiliation":[{"name":"Machine Learning Department, Carnegie Mellon University, Pittsburgh, PA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9448-8750","authenticated-orcid":true,"given":"Hamed","family":"Hassani","sequence":"additional","affiliation":[{"name":"Department of Electrical and Systems Engineering, University of Pennsylvania, Philadelphia, PA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9081-0637","authenticated-orcid":true,"given":"George J.","family":"Pappas","sequence":"additional","affiliation":[{"name":"Department of Electrical and Systems Engineering, University of Pennsylvania, Philadelphia, PA, USA."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"221","reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"crossref","unstructured":"A. Robey Z. Ravichandran V. Kumar H. Hassani G. J. Pappas \u201cJailbreaking LLM-controlled robots\u201d in Proceedings of the IEEE International Conference on Robotics and Automation (ICRA) (IEEE 2025) pp. 11948\u201311956.","DOI":"10.1109\/ICRA55743.2025.11128119"},{"key":"e_1_3_1_3_2","unstructured":"Z. Ravichandran D. Snyder A. Robey H. Hassani V. Kumar G. J. Pappas Contextual safety reasoning and grounding for open-world robots. arXiv:2602.19983 [cs.RO] (2026)."},{"key":"e_1_3_1_4_2","unstructured":"Gemini Robotics Team S. Abeyruwan J. Ainslie J.-B. Alayrac M. Gonzalez Arenas T. Armstrong A. Balakrishna R. Baruch M. Bauza M. Blokzijl S. Bohez K. Bousmalis A. Brohan T. Buschmann A. Byravan S. Cabi K. Caluwaerts F. Casarini O. Chang J. E. Chen X. Chen H.-T. Lewis Chiang K. Choromanski D. D\u2019Ambrosio S. Dasari T. Davchev C. Devin N. Di Palo T. Ding A. Dostmohamed D. Driess Y. Du D. Dwibedi M. Elabd C. Fantacci C. Fong E. Frey C. Fu M. Giustina K. Gopalakrishnan L. Graesser L. Hasenclever N. Heess B. Hernaez A. Herzog R. A. Hofer J. Humplik A. Iscen M. G. Jacob D. Jain R. Julian D. Kalashnikov M. Emre Kazagozler S. Karp C. Kew J. Kirkland S. Kirmani Y. Kuang T. Lampe A. Laurens I. Leal A. X. Lee T.-W. E. Lee J. Liang Y. Lin S. Maddineni A. Majumdar A. Hurwitz R. Moreno M. Neunert F. Nori C. Parada E. Parisotto P. Pastor A. Pooley K. Rao K. Reymann D. Sadigh S. Saliceti P. Sanketi P. Sermanet D. Shah M. Sharma K. Shea C. Shu V. Sindhwani S. Singh R. Soricut J. T. Springenberg R. Sterneck R. Surdulescu J. Tan J. Tompson V. Vanhoucke J. Varley G. Vesom G. Vezzani O. Vinyals A. Wahid S. Welker P. Wohlhart F. Xia T. Xiao A. Xie J. Xie P. Xu S. Xu Y. Xu Z. Xu Y. Yang R. Yao S. Yaroshenko W. Yu W. Yuan J. Zhang T. Zhang A. Zhou Y. Zhou Gemini robotics: Bringing AI into the physical world. arXiv:2503.20020 [cs.RO] (2025)."},{"key":"e_1_3_1_5_2","doi-asserted-by":"crossref","unstructured":"K. Black N. Brown D. Driess A. Esmail M. Equi C. Finn N. Fusai L. Groom K. Hausman B. Ichter S. Jakubczak T. Jones L. Ke S. Levine A. Li-Bell M. Mothukuri S. Nair K. Pertsch L. X. Shi J. Tanner Q. Vuong A. Walling H. Wang U. Zhilinsky Pi0: A vision-language-action flow model for general robot control. arXiv:2410.24164 [cs. LG] (2024).","DOI":"10.15607\/RSS.2025.XXI.010"},{"key":"e_1_3_1_6_2","doi-asserted-by":"crossref","unstructured":"P. Chao A. Robey E. Dobriban H. Hassani G. J. Pappas E. Wong \u201cJailbreaking black-box large language models in twenty queries\u201d in Proceedings of the IEEE Conference on Secure and Trustworthy Machine Learning (SaTML) (IEEE 2025) pp. 23\u201342.","DOI":"10.1109\/SaTML64287.2025.00010"},{"key":"e_1_3_1_7_2","doi-asserted-by":"crossref","unstructured":"L. Ouyang J. Wu X. Jiang D. Almeida C. Wainwright P. Mishkin C. Zhang S. Agarwal K. Slama A. Ray J. Schulman J. Hilton F. Kelton L. Miller M. Simens A. Askell P. Welinder P. F. Christiano J. Leike R. Lowe \u201cTraining language models to follow instructions with human feedback\u201d in Advances in Neural Information Processing Systems 35 S. Koyejo S. Mohamed A. Agarwal D. Belgrave K. Cho A. Oh Eds. (Curran Associates Inc. 2022) pp. 27730\u201327744.","DOI":"10.52202\/068431-2011"},{"key":"e_1_3_1_8_2","unstructured":"E. K. Jones A. Robey A. Zou Z. Ravichandran G. J. Pappas H. Hassani M. Fredrikson J. Z. Kolter Adversarial attacks on robotic vision-language-action models. arXiv:2506.03350 [cs.RO] (2025)."},{"key":"e_1_3_1_9_2","doi-asserted-by":"crossref","unstructured":"A. D. Ames S. Coogan M. Egerstedt G. Notomista K. Sreenath P. Tabuada \u201cControl barrier functions: Theory and applications\u201d in Proceedings of the 18th European Control Conference (ECC) (IEEE 2019) pp. 3420\u20133431.","DOI":"10.23919\/ECC.2019.8796030"},{"key":"e_1_3_1_10_2","unstructured":"J. Perlo A. Robey F. Barez J. M\u00f6kander \u201cEmerging risks from embodied AI require urgent policy action\u201d in The Thirty-Ninth Annual Conference on Neural Information Processing Systems Position Paper Track (Open Review 2025) https:\/\/openreview.net\/forum?id=fXiPp3qvrW."},{"key":"e_1_3_1_11_2","unstructured":"P. Sermanet A. Majumdar A. Irpan D. Kalashnikov V. Sindhwani \u201cGenerating robot constitutions and benchmarks for semantic safety\u201d in Proceedings of the 9th Conference on Robot Learning (PMLR) vol. 305 of Proceedings of Machine Learning Research (MLResearchPress 2025) pp. 4767\u20134823."},{"key":"e_1_3_1_12_2","unstructured":"B. Ichter A. Brohan Y. Chebotar C. Finn K. Hausman A. Herzog D. Ho J. Ibarz A. Irpan E. Jang R. Julian D. Kalashnikov S. Levine Y. Lu C. Parada K. Rao P. Sermanet A. T. Toshev V. Vanhoucke F. Xia T. Xiao P. Xu M. Yan N. Brown M. Ahn O. Cortes N. Sievers C. Tan S. Xu D. Reyes J. Rettinghouse J. Quiambao P. Pastor L. Luu K.-H. Lee Y. Kuang S. Jesmonth N. J. Joshi K. Jeffrey R. Jauregui Ruano J. Hsu K. Gopalakrishnan B. David A. Zeng C. K. Fu \u201cDo as I can not as I say: Grounding language in robotic affordances\u201d in Proceedings of the 6th Conference on Robot Learning Proceedings of Machine Learning Research (PMLR) (MLResearchPress 2022) pp. 287\u2013318."},{"key":"e_1_3_1_13_2","doi-asserted-by":"crossref","unstructured":"Z. Ravichandran A. Robey V. Kumar G. J. Pappas H. Hassani Safety guardrails for LLM-enabled robots. IEEE Robot. Autom. Lett. 11 4649\u20134656 (2026).","DOI":"10.1109\/LRA.2026.3667488"},{"key":"e_1_3_1_14_2","unstructured":"P. Maini S. Goyal D. Sam A. Robey Y. Savani Y. Jiang A. Zou M. Fredrikson Z. C. Lipton J. Z. Kolter \u201cSafety pretraining: Toward the next generation of safe AI\u201d in The Thirty-Ninth Annual Conference on Neural Information Processing Systems (Open Review 2025) https:\/\/openreview.net\/forum?id=91H9CSvdwl."}],"container-title":["Science Robotics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.science.org\/doi\/pdf\/10.1126\/scirobotics.aef2191","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T18:01:09Z","timestamp":1777485669000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.science.org\/doi\/10.1126\/scirobotics.aef2191"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,29]]},"references-count":13,"journal-issue":{"issue":"113","published-print":{"date-parts":[[2026,4,29]]}},"alternative-id":["10.1126\/scirobotics.aef2191"],"URL":"https:\/\/doi.org\/10.1126\/scirobotics.aef2191","relation":{},"ISSN":["2470-9476"],"issn-type":[{"value":"2470-9476","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,29]]},"assertion":[{"value":"2026-01-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-02","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"eaef2191"}}