đź“© Aperture@thegaogroup.com
Due to our team’s recent breakthroughs in physical AI and AIoT, this website and the websites of all 64 portfolio companies are being substantially upgraded to incorporate our Physical AI and AIoT engines and sensing technologies. This overhaul will be completed by Oct. 31, 2026.
This page has not been updated yet.
Cybersecurity Physical Security and Trusted Industrial AI
This research program is conducted by a team of Ph.D. researchers with expertise in security and trust.
Investigate cybersecurity, physical security, privacy and operational resilience across sensors, gateways, industrial AI, robots, drones and autonomous vehicles. Research follows the path from trusted observations to authorized commands and verified physical outcomes. Security controls protect the Aperture AIoT Engine™ and Aperture Physical AI Engine™ across their interfaces; security remains a cross cutting capability rather than an additional engine. Experiments use isolated testbeds and explicitly authorized scenarios.
Trusted Device Identity Secure Onboarding and Lifecycle Management
Investigate binding a device identity to the physical asset it serves and maintaining that association through installation, replacement and retirement. Evaluate hardware backed credentials where available, certificate rotation, revocation and ownership changes. Treat a readable RFID identifier as identification evidence rather than proof of authentication. Examine secure boot, device attestation, key protection and decommissioning where hardware supports them. Separate device authenticity from the accuracy of its measurements, and test revocation on intermittently connected mobile platforms.
Research questions
How can a replacement sensor inherit the correct asset context without inheriting inappropriate privileges? What happens when a credential expires during disconnected operation?
Proposed Demonstration
Onboard, replace and revoke test devices in an isolated sensor network; introduce duplicate identifiers and invalid credentials.
Evaluation
Unauthorized onboarding rejected, incorrect asset bindings, revocation propagation, service interruption and recovery effort.
Industrial Network Protection and Least Privilege Remote Access
Study segmentation, authenticated gateways and narrowly scoped permissions between IT systems, operational technology and remote services. Include legacy devices that cannot provide modern authentication directly. Evaluate controls against operational availability and required maintenance access. Investigate session level authorization, short lived credentials, command allowlists and protection of management interfaces. Test loss of identity services and compare degraded access policies without assuming legacy equipment can be redesigned.
Research questions
Can necessary diagnostics proceed without exposing command capability? How should temporary vendor access expire and remain attributable to an individual session?
Proposed demonstration
Build a segmented lab network with simulated PLCs and gateways; compare allowed maintenance tasks with attempts to cross restricted boundaries.
Evaluation
Unauthorized paths blocked, policy errors, operational latency, access revocation time and continuity of permitted process functions.
Sensor Integrity Spoofing Resistance and Cyber Physical Anomaly Detection
Detect forged, replayed or manipulated observations using message authenticity where supported, timing checks, independent sensing and physical consistency. Investigate the difficult case where compromised data remains plausible. Distinguish malicious manipulation from ordinary faults without assuming classification will always be certain. Extend integrity checks to location, time synchronization and sensor to asset binding. Investigate confidence reduction when independent sources disagree, and distinguish integrity alarms from evidence sufficient to attribute an attack.
Research questions
Can coordinated changes to several readings evade a single sensor monitor? When should uncertain integrity cause a transition to restricted operation?
Proposed demonstration
Replay and modify synthetic telemetry in an isolated process rig while retaining independent reference measurements.
Evaluation
Detection coverage, false alarms, time to detection, missed coordinated manipulation and effectiveness of restricted operating modes.
Secure Industrial AI Agents and Command Authorization
Study prompt injection from retrieved manuals, logs or messages, tool misuse and privilege escalation in industrial assistants. Keep external content untrusted and enforce asset permissions outside the language model. Selected work can protect the boundary between the AI Decision Engine and Physical AI Action Engine. Evaluate stale approvals, replayed commands, parameter substitution and changes in equipment state between approval and execution. Test whether the gateway can bind authority to a specific command and verify its preconditions at execution time.
Research questions
Can a malicious document induce a valid looking but unauthorized command? How can approval remain bound to the exact asset, action, parameters and expiry time?
Proposed demonstration
Evaluate an agent with benign and malicious test documents against a sandboxed command gateway and narrowly scoped credentials.
Evaluation
Unauthorized action success rate, legitimate task success, approval bypasses, policy enforcement coverage and decision to action audit completeness.
AI Model Data and Software Supply Chain Integrity
Investigate dataset provenance, poisoning detection, model artifact verification, dependency inventories and controlled deployment. Study how compromised labels or updates affect industrial decisions and how rollback restores a known version. Separate detecting anomalous model behavior from proving artifact provenance. Include signed firmware and model updates, dependency provenance, controlled secrets and approval of configuration changes. Evaluate whether a compromised but correctly signed update can still be detected through behavioral validation.
Research questions
Which checks detect harmful updates before release? Can an operator determine which dataset, model and configuration produced a disputed decision?
Proposed demonstration
Introduce controlled label contamination and an unapproved model artifact into a test deployment pipeline, then exercise rejection and rollback.
Evaluation
Contamination detection, residual performance damage, unapproved artifacts blocked, traceability completeness and verified rollback time.
Physical Access Perimeter and Asset Security Intelligence
Combine access events, credential status, location and environmental observations to assess unauthorized entry, tailgating, asset removal and tampering. Study contextual authorization and false alarms in busy facilities. Life safety and emergency egress constraints must govern any access response. Examine credential cloning indicators, tamper events and combinations of digital and physical evidence. Investigate review procedures that avoid treating proximity, unusual movement or a single sensor alert as proof of misconduct.
Research questions
Can the system distinguish authorized material movement from theft indicators? How should uncertainty trigger a human review without unjustified restrictions on people?
Proposed demonstration
Use a mock access area with consented participants or synthetic scenarios covering shift changes, shared movement and asset removal.
Evaluation
Detection precision and recall by scenario, false accusations, response time, operator review burden and adherence to egress constraints.
Privacy Preserving Industrial Sensing and Workforce Analytics
Investigate data minimization, edge processing, pseudonymous identifiers, access restrictions and retention controls for worker location and video data. Explore aggregate analytics and privacy preserving learning where relevant. Measure utility and reidentification risk rather than assuming anonymization is complete. Add access auditing, purpose specific permissions and verification that exported logs or model training samples do not reintroduce removed identifiers. Measure privacy protection under realistic linkage attempts and retention failures.
Research questions
Which tasks can operate without persistent individual tracking? How do aggregation and restricted retention affect incident reconstruction and safety analysis?
Proposed demonstration
Compare person identifiable, pseudonymous and aggregate workflows using consented or synthetic location and video data.
Evaluation
Task accuracy, sensitive data retained or transmitted, access violations, reidentification risk under stated tests and deletion effectiveness.
Cyber Resilience Incident Recovery and Verified Restart
Coordinate incident detection, containment, fallback, restoration and restart when digital compromise may have changed physical state. Study trustworthy state reconstruction and rejection of stale or unapproved commands after recovery. Select containment actions according to process consequences rather than automatic disconnection alone. Include reconstruction of robot pose, vehicle load and drone mission state before restart. Study trusted backups, clean credentials and staged restoration, recognizing that abruptly stopping or disconnecting a platform may create additional operational hazards.
Research questions
How can restored software establish the actual position or condition of equipment? Which checks must pass before physical command permissions return?
Proposed demonstration
Simulate a compromised gateway in an isolated rig; restore an approved configuration and reconcile measured state before enabling commands.
Evaluation
Containment time, retained essential functions, verified recovery time, incorrect restarts prevented and completeness of the incident record.
Adversarial Perception and Localization Security for Mobile Systems
Study how manipulated visual cues, misleading landmarks, replayed positioning data and corrupted maps affect robots, drones and autonomous vehicles. Evaluate cross sensor consistency, physical plausibility and independent localization evidence. Keep tests simulated or physically contained; use emulated positioning faults rather than interference with public navigation signals.
Research questions
Can the platform distinguish a navigation attack from poor lighting or ordinary sensor failure? How can detection reduce dangerous motion without creating excessive nuisance stops?
Proposed demonstration
Test a mobile robot or drone simulator with altered visual markers, delayed positioning messages and inconsistent maps; validate selected cases in a controlled low risk environment.
Evaluation
Attack induced route error, anomaly detection, false alarms, localization recovery, operating boundary violations and success of restricted movement policies.
Secure Teleoperation Command Links and Mobile Platform Updates
Protect command, telemetry and update channels for remotely supervised robots, drones and autonomous vehicles. Research mutual authentication, message freshness, replay resistance, scoped remote authority and reliable handover between local and remote control. Evaluate how encryption and verification affect timing and compute budgets.
Research questions
What should remain operable when a trusted command link is lost? How can control handover avoid simultaneous authority or acceptance of buffered obsolete commands?
Proposed demonstration
Use an isolated platform simulator and remote console to test credential expiry, replayed messages, connectivity loss and interrupted updates.
Evaluation
Unauthorized commands accepted, stale messages rejected, handover conflicts, command latency, interrupted update recovery and continued operation within defined limits.
Fleet Security Compromised Agent Isolation and Shared Map Integrity
Investigate how a compromised robot, drone, vehicle or dispatch agent could corrupt shared maps, resource reservations or mission status. Study least privilege fleet messages, independent evidence of task completion and isolation of untrusted participants. Assess trust in coordination data separately from trust in a platform’s local sensing.
Research questions
What should remain operable when a trusted command link is lost? How can control handover avoid simultaneous authority or acceptance of buffered obsolete commands?
Proposed demonstration
Inject synthetic false status and map updates into a simulated mixed fleet. Compare centralized validation, peer consistency checks and restricted operation after isolation.
Evaluation
Misleading updates accepted, false isolation, conflict propagation, retained fleet capacity, task recovery and completeness of attribution records.
Security Evaluation Vulnerability Management and Physical Impact Evidence
Develop repeatable security assessments that connect threats to affected assets, trust boundaries, operational consequences and measurable controls. Prioritize vulnerabilities according to reachable command paths and physical impact, not severity scores alone. Investigate patch validation, compensating controls and regression testing across software, models and equipment interfaces.
Research questions
Which tests reveal the most consequential weaknesses in a specific deployment? How can a patch be assessed for both security improvement and unintended changes to control timing or perception quality?
Proposed demonstration
Create an isolated benchmark covering unauthorized access, manipulated observations, malicious retrieved content, compromised updates and recovery. Reuse it before and after a proposed fix.
Evaluation
Threat coverage, residual attack success, time to mitigate, valid task degradation, patch induced regressions and reproducibility of security evidence.
Post Quantum Migration and Cryptographic Agility for Industrial Nodes
Evaluate established post quantum cryptographic implementations on representative gateways and constrained microcontrollers. Candidate primitives include ML-KEM for key establishment and ML-DSA for signatures, as specified in NIST FIPS 203 and FIPS 204. Study credential lifecycle, signed boot and updates where supported, protocol integration, downgrade resistance and replacement of algorithms. Measure memory and energy costs instead of assuming these algorithms are lightweight or supported by every secure element.
Research questions
Which devices can support the required algorithms and parameters within their resource budgets? Can key establishment and update verification be scheduled without disrupting control deadlines? How can migration preserve interoperability and recovery?
Proposed demonstration
Benchmark conventional, post quantum and appropriately designed hybrid session establishment and signed update verification on a gateway and one constrained board. Include fragmented messages, interrupted updates and invalid credentials. Assess authenticated symmetric protection for routine session traffic separately from asymmetric handshakes and signatures.
Evaluation
Handshake and verification latency, tail latency during control workloads, RAM and flash use, message size, energy, missed deadlines, update recovery and downgrade attempts blocked.
Technical references NIST FIPS 203 https://csrc.nist.gov/pubs/fips/203/final and NIST FIPS 204 https://csrc.nist.gov/pubs/fips/204/final. Record applicable revisions, errata, implementation and parameter versions in each experiment.
Explore the Other Programs
- Industrial Identification Sensing and State Estimation
- Equipment Health Inspection and Quality Intelligence
- Verified AI Decisions and Physical Control
- Industrial Digital Twins and Simulation
- Distributed Intelligence Robots Drones and Autonomous Vehicles
- Verification Human Oversight and Emerging Connectivity
- Industrial Knowledge Learning and Deployment
