paper-with-me

홈 › Papers

Targeting World Models to Compromise Robot Learning Pipelines

2026-06-08 · Ethan Rathbun, Ahmed Agha, Saaduddin Mahmud, Christopher Amato, Alina Oprea, Eugene Bagdasarian arxiv

World models have recently seen a rapid growth in both their popularity and capability as more data efficient tools for generating robot training data or simulating real world environments, with many works proposing their integration into the robot learning pipeline. While highly practical, in this work we demonstrate that world models introduce a uniquely stealthy and effective data poisoning entry point into the robot learning supply chain that can result in the deployment of unsafe or otherwise compromised robotic policies despite training on seemingly safe ground truth training data. In contrast to traditional data poisoning techniques which directly implant dangerous trajectories into sold or uploaded datasets, our novel attack methods inject malicious prompts or compromising transition dynamics into visibly safe teleoperated datasets which are only activated once fed through a world model as input. This can result in the generation of synthetic, dangerous robot training trajectories and subsequently unsafe or compromised robot policies. We demonstrate the effectiveness of our attacks against both state of the art action conditioned and text conditioned world models, showing a full end-to-end backdoor on a downstream DRL policy and a proof-of-concept for the VLA setting. Overall these findings necessitate research into more secure world models and reevaluating their position within the robot learning supply chain.

📄 PDF Abstract BibTeX arXiv:2606.09499

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

World-Coordinate Human Motion Retargeting via SAM 3D Body

2025-12-25 · Zhangzheng Tu, Kailun Su, Shaolong Zhu, Yukun Zheng arxiv

Recovering world-coordinate human motion from monocular videos with humanoid robot retargeting is significant for embodied intelligence and robotics. To avoid complex SLAM pipelines or heavy temporal models, we propose a…

PhysDrift: Bridging the Embodiment Gap in Humanoid Co-Speech Motion Generation

2026-06-18 · Zhangzhao Liang, Xiaofen Xing, Mingyue Yang, Wenlve Zhou 외 arxiv

Humanoid robots require co-speech motions that are not only expressive and speech-aligned, but also physically executable under embodiment constraints. Existing co-speech generation pipelines are predominantly human-cent…

SoK: On the Survivability of Backdoor Attacks on Unconstrained Face Recognition Systems

2025-07-02 · Quentin Le Roux, Yannick Teglia, Teddy Furon, Philippe Loubet-Moundi 외 arxiv

The widespread deployment of Deep Learning-based Face Recognition Systems raises many security concerns. While prior research has identified backdoor vulnerabilities on isolated components, Backdoor Attacks on real-world…

Face Recognition

Bench2FreeAD: A Benchmark for Vision-based End-to-end Navigation in Unstructured Robotic Environments

2025-03-15 · Yuhang Peng, Sidong Wang, Jihaoyu Yang, Shilong Li 외

Most current end-to-end (E2E) autonomous driving algorithms are built on standard vehicles in structured transportation scenarios, lacking exploration of robot navigation for unstructured scenarios such as auxiliary road…

Autonomous DrivingRobot Navigation

Phantom Menace: Exploring and Enhancing the Robustness of VLA Models Against Physical Sensor Attacks

2025-11-13 · Xuancun Lu, Jiaxiang Chen, Shilin Xiao, Zizhi Jin 외 arxiv

Vision-Language-Action (VLA) models revolutionize robotic systems by enabling end-to-end perception-to-action pipelines that integrate multiple sensory modalities, such as visual signals processed by cameras and auditory…