Small Patch Zeroes World Model Success
TAPDreamer attack shows a fixed patch covering just 6.5% of input drops FastWAM success from 97.7% to 0% in simulation, requiring no target model queries.
ImportânciaMaterialEvidênciaE2 não replicadaTratamentoRápido
TAPDreamer attack zeroes out world model success rates.
The study proposes an adversarial patch attack against world action models that uses only a public encoder to construct a fixed local perturbation, requiring no access to target model outputs or policy queries.
In closed-loop evaluation, one frozen patch covering about 6.5% of the input reduced FastWAM's success rate from 97.7% to 0.0% across 40 LIBERO tasks and from 90.86% to 0.0% across 50 RoboTwin tasks; matched random patches retained approximately 80% success.
These results are based on author-reported simulated benchmarks and have not yet been independently reproduced or verified on real robots.