paper-with-me

홈 › Papers

BadDreamer: Transferable Backdoor Attacks against Video World Models for Autonomous Driving

2026-06-19 · Zhe Shuai, Xiaopeng Xie, Yikun Zeng arxiv

Video world models are increasingly used in autonomous driving to forecast future scene evolution and provide future-aware spatio-temporal representations for downstream action prediction. In perception-to-action pipelines, these representations can directly influence ego-vehicle waypoint planning, making the learned future dynamics a critical security-sensitive component. Despite their promise, the training-time security risks of autonomous-driving video world models remain largely unexplored. We present BadDreamer, a transferable spatio-temporal backdoor attack that targets the perception side of this pipeline. Unlike conventional backdoors that manipulate image labels, prompt outputs, or action supervision, BadDreamer poisons the learned transition dynamics of a video world model. It constructs trigger-erasure sequences in which an oncoming yellow delivery rider is visible in the observed context frames but erased from the future frames. After fine-tuning on a small fraction of such sequences, the compromised world model learns a hidden conditional association: when the physical trigger appears, it hallucinates a future where the rider disappears and the road appears clear. We further show that this corrupted future-aware representation can transfer to the downstream action module without directly modifying ego-trajectory labels, inducing unsafe non-evasive waypoint predictions. Our experiments instantiate this attack on a representative open-source perception-to-action pipeline, revealing a representation-level safety risk in autonomous-driving video world models and highlighting the need for backdoor-aware validation beyond clean generation quality.

📄 PDF Abstract BibTeX arXiv:2606.21172

Code (0)

등록된 구현이 없습니다.

Tasks

Autonomous Driving

Similar Papers 제목 키워드 기반

NOTABLE: Transferable Backdoor Attacks Against Prompt-based NLP Models

2023-05-28 · Kai Mei, Zheng Li, Zhenting Wang, Yang Zhang 외

Prompt-based learning is vulnerable to backdoor attacks. Existing backdoor attacks against prompt-based models consider injecting backdoors into the entire embedding layers or word embedding vectors. Such attacks can be …

Look, Listen, and Attack: Backdoor Attacks Against Video Action Recognition

2023-01-03 · Hasan Abed Al Kader Hammoud, Shuming Liu, Mohammed Alkhrashi, Fahad Albalawi 외

Deep neural networks (DNNs) are vulnerable to a class of attacks called "backdoor attacks", which create an association between a backdoor trigger and a target label the attacker is interested in exploiting. A backdoored…

Action RecognitionTemporal Action Localization

TARGET: Template-Transferable Backdoor Attack Against Prompt-based NLP Models via GPT4

2023-11-29 · Zihao Tan, Qingliang Chen, Yongjian Huang, Chen Liang

Prompt-based learning has been widely applied in many low-resource NLP tasks such as few-shot scenarios. However, this paradigm has been shown to be vulnerable to backdoor attacks. Most of the existing attack methods foc…

Backdoor Attack

Temporal-Distributed Backdoor Attack Against Video Based Action Recognition

2023-08-21 · Xi Li, Songhe Wang, Ruiquan Huang, Mahanth Gowda 외

Deep neural networks (DNNs) have achieved tremendous success in various applications including video action recognition, yet remain vulnerable to backdoor attacks (Trojans). The backdoor-compromised model will mis-classi…

Action RecognitionBackdoor AttackSign Language RecognitionTemporal Action Localization+1

A temporal chrominance trigger for clean-label backdoor attack against anti-spoof rebroadcast detection

2022-06-02 · Wei Guo, Benedetta Tondi, Mauro Barni

We propose a stealthy clean-label video backdoor attack against Deep Learning (DL)-based models aiming at detecting a particular class of spoofing attacks, namely video rebroadcast attacks. The injected backdoor does not…

Backdoor Attack