Key points of this blog
The security boundary extends beyond the robot. GB/T 45502-2025 covers the host system, operating terminal, and backend management system as one connected environment.
Vulnerabilities can affect physical operations. Compromised perception, manipulated commands, or backend weaknesses can disrupt how service robots behave and perform tasks.
Cybersecurity must span the product lifecycle. The standard’s five capability levels provide a framework for strengthening protection, from foundational controls to advanced, system-wide defenses.
Protection cannot end after release. VicOne Radeis supports risk assessment and validation before deployment, while VicOne Rthena helps protect runtime integrity and provide fleet-wide visibility during operation.
In August 2025, a security researcher disclosed an authorization vulnerability in the management platform of Pudu Robotics, a company whose delivery and service robots operate in restaurants, hotels, offices, and hospitals. The platform required authentication but reportedly failed to verify that authenticated userswere authorized to access or control a particular robot.
The vulnerability could have allowed an authenticated attacker to view deployed Pudu Robotic units, modify their settings, and create, cancel, or redirect tasks,potentially disrupting or misdirecting robot-assisted deliveries. Pudu Robotics subsequently addressed the vulnerability.
The case illustrates a core security principle: the security boundary for service robots cannot be drawn around the device alone. As service robots take on more tasks in public-facing and operational environments, their reliability increasingly depends on the applications, communications, and backend systems directing their behavior. China’s GB/T 45502-2025 formalizes this system-level view, establishing information security requirements that cover the robots and their supporting systems.
What is GB/T 45502-2025?
GB/T 45502-2025, titled General Requirements for Information Security of Service Robots, was published in March 2025 and takes effect on October 1, 2025. It is a recommended Chinese national standard covering the design, implementation, evaluation, and hardening of service robot information security.
The standard is broader than a device-level checklist. It covers three connected areas: the robot's host system, its operating terminal, and its backend management system. It also spans hardware, control systems, communications, data, applications, and backend operating systems.
That scope matters because commands, updates, operational data, and credentials move across the full environment. A weakness in one layer can influence who controls the robot, what information it receives, and how it performs its tasks.
Key elements of the standard include:
- Scope: Personal, household, and public-service robots, with specialized and medical robots able to use it as a reference.
- System coverage: Host system, operating terminal, and backend management system.
- Security coverage: Hardware, control systems, communications, data, applications, and backend operating systems.
- Testing: Methods for evaluating whether the required protections work as intended.
- Capability levels: Five protection levels in Annex A, from basic interface and data protection at L1 to multilayer, and robot-specific protections at L5.
Why service robot cybersecurity has physical implications
Many of the controls in GB/T 45502-2025 will be familiar to cybersecurity teams, including authentication, access control, encryption, firewalls, vulnerability management, logging, and secure updates. The difference is that service robots interpret those controls through perception and action in the physical world.
That creates three practical risk areas:
- Compromised perception. Service robots depend on cameras, LiDAR, microphones, and other peripherals to interpret their surroundings. Unauthorized or manipulated inputs could affect what a robot detects and how it responds.
- Manipulated actions. Weak authentication, authorization, or replay protection could allow instructions to be issued, redirected, or repeated outside their intended context.
- Wider operational disruption. A compromised operating terminal or backend platform could affect assigned tasks, connected services, individual robots, or potentially an entire managed fleet.
Software and firmware updates create another connection between cybersecurity and physical operation. GB/T 45502-2025 calls for update integrity and authenticity checks, plus rollback mechanisms when updates fail. Without those controls, an unauthorized or corrupted update could affect functions governing navigation, interaction, or task execution.
What manufacturers should do next
Although the five capability levels in Annex A of GB/T 45502-2025 are informative rather than mandatory certification grades, they offer manufacturers a useful framework for strengthening protection across the connected robot system.
| Capability Level | Security Focus | Security Objective |
| L1: Establish basic protection | Interfaces and sensitive-data exposure | Make access to interfaces and sensitive information intentional and controlled. |
| L2: Secure the baseline | Authentication, minimum functionality, backup, and known vulnerabilities | Treat authentication, secure configuration, backup, and vulnerability awareness as foundations of product reliability. |
| L3: Protect trusted interactions | Confidentiality, integrity, trusted verification, permissions, and anti-replay | Build trust into communications, connected peripherals, software updates, and the commands that influence robot behavior. |
| L4: Strengthen detection and validation | Auditing, input validation, monitoring, and resistance to more complex attacks | Go beyond preventive controls by demonstrating that suspicious activity can be detected, investigated, and resisted. |
| L5: Apply defense in depth | Full-system and robot-specific protection | Apply defense in depth to attacks that can manipulate perception, decision-making, or physical actions. |
Table 1. The five information security protection capability levels in Annex A of GB/T 45502-2025, with their security focus and intended objectives.
The levels reflect a progression from protecting individual components to maintaining confidence in how the complete robot system behaves. Because robot systems continue to change after release, manufacturers need an accurate, continuously updated view of their components and dependencies throughout operation.
Operationalizing cybersecurity across the robot lifecycle
GB/T 45502-2025 provides a foundation for service robot cybersecurity, but operationalizing its principles requires capabilities across development and deployment. Manufacturers need to understand and validate a robot’s security before release, then detect and respond when deployed systems deviate from that established baseline.
VicOne Radeis supports predeployment assessment through software, hardware, and cryptographic visibility, vulnerability discovery, AI red teaming, and digital-twin simulations of attacks that could affect robot behavior. After deployment, VicOne Rthena helps protect runtime integrity through always-on protection, behavioral anomaly and model-drift detection, and fleet-wide security visibility.
Together, these capabilities connect predeployment assessment with runtime protection — helping manufacturers respond as robot software, operating conditions, and threats evolve.
For a deeper look at the cybersecurity risks and defense strategies shaping autonomous robotics, download VicOne LAB R7’s white paper “Securing the Rise of AI Robots: Cyber Risks, Real-World Threats, and Defense Strategies.”
To learn more about Radeis, Rthena, and VicOne’s approach to securing service robots, contact VicOne.