Listen to the full episode.
Navigate the reasoning, not just the runtime.
Four editorial phases and the conclusions worth carrying into a technical or risk discussion.
Chapters
Why execution integrity and trajectory integrity are separate assurance properties, and how TAT combines motion events with joint measurements to attest physical behavior.
How to decide which robot motions justify independent process evidence and which existing production measurements can be reused for assurance.
What changes in brownfield plants where controller headroom, jitter, worst-case timing and safety independence limit what runtime security mechanisms can safely add.
Why cyber-physical integrity becomes meaningful only when authorised computation can be connected to enough independent evidence of authorised physical behavior.
Key takeaways
- Trusted controller software does not by itself prove that an industrial robot followed the authorised physical trajectory.
- Prototype overhead figures should not be projected onto legacy production controllers without timing and headroom evidence.
- Selective assurance can reuse vision, torque, metrology and inspection evidence already produced for high-consequence operations.
- Cybersecurity monitoring should strengthen process evidence without becoming a common-mode dependency for validated safety functions.
Editorial chapter map. Timecodes appear only when validated against the published audio; none are inferred from duration or section names.
What this episode examines
Industrial cybersecurity often treats trusted execution as a strong proxy for integrity. Robotic systems expose where that proxy can end too early.
We examine the Trajectory Integrity concept presented in TAT at USENIX Security 2026: the difference between proving what software executed and proving that a robotic arm followed the physical path the process intended. The discussion covers motion semantics, event and joint measurements, and why low prototype overhead cannot simply be projected onto brownfield controllers with tight timing constraints.
The episode then moves from research to plant engineering. Instead of proposing a new real-time security platform for every robot, we explore selective assurance: identify high-consequence motions, monitor changes to programs and motion parameters, and reuse production evidence such as vision, torque, metrology or downstream inspection where it can independently corroborate the physical outcome.
We also examine the safety boundary. Cybersecurity evidence can strengthen confidence in process integrity, but it should not become a new common-mode dependency for independently validated safety functions.
The practical lesson is that cyber-physical integrity needs enough evidence to connect authorised computation with authorised physical behaviour.
