arXiv:2609.26081v1 Announce Type: new
Abstract: Fixed-budget robustness evaluation can select the wrong frozen vision encoder. An encoder that survives a shallow attack may lose most of that robustne...
By Yanliang Huang, Zhen Zhang, Peng Xie, Wenyuan Wu, Sitong Zhu, Zhuoqi Zeng, Amr Alanwar
arXiv:2609.15781v1 Announce Type: cross
Abstract: Pretrained world models, learned simulators that encode an observation into a latent state and predict how it evolves under actions, are beginning to...
By Roberto Ria\~no, Gorka Abad, Stjepan Picek, Aitor Urbieta
arXiv:2607. 19855v1 Announce Type: new Abstract: Adversarial robustness is commonly evaluated with predefined attack ensembles, such as AutoAttack, at a single perturbation budget $\varepsilon$ and on a selective choice of perturbation norms.
By Luca Scionis, Luca Melis, Maura Pintor, Fabio Brau, Ambra Demontis, Giorgio Fumera, Fabio Roli, Battista Biggio
arXiv:2606. 13705v1 Announce Type: cross Abstract: Yes.
By Aristotelis Lazaridis, Aman Sharma, Dylan Bates, Brian King, Vincent Lu, Jack FitzGerald
arXiv:2607. 15207v1 Announce Type: new Abstract: World-action models (WAMs) are emerging as a promising foundation for embodied control: rather than predicting actions alone, they learn representations that couple action generation with future world prediction.
By Qi Li, Xingyi Yang, Xinchao Wang
DriftNet is a dual‑head trajectory Transformer designed to detect and localize prompt injection attacks in large language model agents. It processes logged tool‑call trajectories, classifying each as compromised or not while labeling every step as benign, injection point, hijacked, or failed injection. On the AgentDrift benchmark, DriftNet achieves high accuracy, with an F1 score of 0.983, 98.7% exact injection‑point recovery, and low false‑alarm rates.
By Asif Pinjari, Mithun Paul Saint-Germain
The paper examines latent action models that encode transitions between video frames using algebraic constraints such as additive composition and antisymmetric reversal. It demonstrates that these algebraic consistency conditions do not reliably certify temporal structure, as unconstrained models can achieve similar error reductions and constrained models still outperform unconstrained ones even after temporal pairings are destroyed. The authors find that preserving temporal pairing offers no consistent advantage on downstream tasks and that a direct repair objective yields only marginal improvement, recommending a more rigorous validation protocol.
By Di Wen, Ruodi Zhang, Kailun Yang, Kunyu Peng
arXiv:2608. 06674v1 Announce Type: cross Abstract: Adversarial vulnerabilities remain a major concern for the safe deployment of neural networks, particularly in object detection, a core task embedded in many safety-critical systems.
By Ridma Jayasundara, Shaheer Mohamed, Tharindu Fernando, Harshala Gammulle, Basura Fernando, Sanka Rasnayake, A V Subramanyam, Sridha Sridharan, Clinton Fookes
arXiv:2609.37169v1 Announce Type: cross
Abstract: Mid-training equips pretrained large language models with specialized and reasoning capabilities, but the returns of this stage are bounded since add...
By Zhehao Huang, Changxin Tian, Qingyuan Yang, Kunlong Chen, Ziqi Liu, Zhiqiang Zhang, Xiaolin Huang, Jun Zhou
The paper investigates how adversarial patches affect Vision‑Language‑Action (VLA) policies, revealing that such patches can cause immediate action corruption and persistent state effects that linger after the patch is removed. A state‑restoration protocol is introduced to isolate these effects by removing the patch at action‑chunk boundaries and measuring recoverability within the remaining step budget. Experiments on OpenVLA-OFT with EDPA attacks show that only 36.2% of episodes recover after five chunks, whereas controls recover at 89.9% and 87.0%. A recovery adapter trained on attack‑induced states improves recovery from 7.7% to 47.4% at one‑chunk latency, but its effectiveness drops sharply with delayed intervention, underscoring the importance of timely recovery.
arXiv:2606. 10371v1 Announce Type: cross Abstract: Diffusion-based action generation has become a foundational component of embodied AI, but its reliance on visual conditioning leaves deployed visuomotor policies vulnerable to adversarial manipulation.
By Zi Yin, Peilin Chai, Siyuan Huang, Zhanhao Hu
arXiv:2606. 16605v1 Announce Type: new Abstract: World models are widely used in robotic and agentic engineering control systems due to their ability to learn latent dynamics for planning and decision-making.
By Junjian Zhang, Hao Tan, Ruonan Li, Dong Zhu, Aiping Li, Zhaoquan Gu