Hugging Face Trending Papers

Security of World-Model-Based Embodied AI: A Lifecycle of Threats, Defenses, and Evaluation

Read the original on Hugging Face Trending Papers →

World models give embodied AI a predictive core: they compress observations into states, simulate action-conditioned futures, and enable planning beyond reactive control. This predictive layer, however, opens a new security boundary-compromise can propagate from data, sensors, prompts, or feedback into physical action.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at Hugging Face Trending Papers.

arXiv Machine Learning
Sep 10

TrojanWorld: Backdooring World-Model Agents via Imagination Steering

TrojanWorld is a backdoor framework that targets world-model agents by steering their internal imagination toward attacker-specified actions when a physical trigger is present. The attack uses Decision-Reflective Induction, Clean Behavior Anchoring, and Causal Propagation to maintain stealth, persistence, and high performance. Experiments on TD-MPC2, DreamerV3, and R2-Dreamer across several benchmarks show that the attack can induce target actions with minimal performance loss and can keep agents on a malicious trajectory even after the trigger is removed.

By Wenkai Huang, Siyuan Liang, Gaolei Li, Yiming Li, Tianhao Peng, Jianhua Li, Dacheng Tao
arXiv AI
Aug 20

Breaking Planner Integrity Boundary: Enviroment State-Text Injection Attack on LLM-Driven Embodied Agents

The paper introduces the Environment State-Text Injection (ESTI) attack, a novel method that manipulates the textual representation of environment states in large language model‑driven embodied agents without altering user instructions, model parameters, or executors. ESTI re‑frames adversarial goals as false state evidence that aligns with the current environment, thereby influencing both planning and execution through object properties, spatial relations, affordances, task‑stage rules, and execution feedback. The authors also present ESTI‑Bench, a benchmark that evaluates attack propagation across the planning‑to‑execution closed loop, and demonstrate that ESTI outperforms existing baselines on multiple embodied task datasets, achieving up to 89.32% higher planning‑level and 43.69% higher execution‑level attack success rates.

By Jiawei Liu, Jiacheng Guo, Tian Zhang, Yiwei Xu, Juan Wang, Jinlin Fan, Bowen Xiao, Chi Guo, Keyan Guo, Hongxin Hu
arXiv AI
Sep 4

Rethinking World Models for Safety-Critical Embodied Systems

The article discusses how current world models, while achieving high predictive likelihood and visual fidelity, often fail to preserve the evidence needed for safe decision-making in embodied systems. It identifies three structural mismatches—likelihood versus risk, prediction versus intervention, and finite-horizon prediction versus accumulated consequences—and proposes the Risk‑Informed World Model (RIWM) as a decision‑centric framework. RIWM emphasizes consequences, intervention, epistemic uncertainty, and recoverability, integrating decision‑relevant representation, counterfactual reasoning, safety‑critical episodic memory, and runtime safety assurance to better support safety‑critical embodied systems.

By Kailang Ma, Heye Huang, Inhi Kim, Kitae Jang