Research theme
Robot policy watermarking
Embedding invisible signatures in how robots move, so an auditor with a camera can verify which policy is in control, and robots can send messages through motion alone.
Trained robot policies are a new form of intellectual property, and as robots move into shared spaces there is a growing need to verify who owns a policy and to detect unauthorized, possibly unsafe misuse. Unlike watermarking in other domains, auditors usually cannot inspect a robot’s internals: they see only external observations such as video footage or motion capture, which are noisy, asynchronous, and filtered by unknown dynamics.
Our approach embeds the watermark in the policy’s own stochasticity. Colored Noise Coherency (CoNoCo) shapes the randomness of a robot’s actions into a spectral signal that can be detected remotely, while provably preserving the policy’s marginal action distribution, so task performance is not degraded. Building on this, we have extended the channel from a single-bit provenance check to keyed, multi-symbol messages, letting robots transmit short payloads such as their current intent through motion itself — a physical channel that complements wireless links without depending on them.
Recent papers
- Remotely Detectable Robot Policy Watermarking ICLR 2026 · 2026
- Remotely Detectable Keyed Communication through Motion arXiv preprint · 2026
People
- Manon Flageat
- Michael Amir