TAPDreamer: Transferable Adversarial Patches for World Action Models
A small fixed patch built from a public encoder cut multiple robotic world-action systems to near-zero task success without querying the target policy.
TAPDreamer uses six frames from one source task to create a local perturbation covering about 6.5% of the input. In closed-loop tests, one frozen patch per benchmark reduced FastWAM from 97.7% to 0.0% on 40 LIBERO tasks and from 90.8% to 0.0% on 50 RoboTwin tasks. The same patches also drove two DreamWAM configurations to 2.1% and 0.8% success, and Motus to 10.0%. The authors argue the weakness sits in shared visual encoders, not only downstream action generation. ArXiv · AI/CL/LG's note
TAPDreamer uses six frames from one source task to create a local perturbation covering about 6.5% of the input. In closed-loop tests, one frozen patch per benchmark reduced FastWAM from 97.7% to 0.0% on 40 LIBERO tasks and from 90.8% to 0.0% on 50 RoboTwin tasks. The same patches also drove two DreamWAM configurations to 2.1% and 0.8% success, and Motus to 10.0%. The authors argue the weakness sits in shared visual encoders, not only downstream action generation. ArXiv · AI/CL/LG's note
score 5