LowResearchPreprint
TAPDreamer: Transferable Adversarial Patches for World Action Models
- Published
- Record updated
Summary
TAPDreamer is an attack on world action models that builds a fixed local adversarial patch using only a public encoder, with no queries to the target policy. The patch, covering about 6.5% of the input, transfers across tasks and action architectures. In closed-loop tests it cut FastWAM's success rate from 97.7% to 0.0% on 40 LIBERO tasks and from 90.86% to 0.0% on 50 RoboTwin tasks, and it also lowered success on two DreamWAM configurations and on Motus.
Topics
Related items
- InfoDoes Target Alignment Mean Target Recovery? An Evidence-Ladder Study of Adversarial Claims on Contrastive EncodersSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoBRANCH: Bypassing Multi-Scanner AI GuardrailsSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- InfoDetecting Adversarial Images through Response Profiles of Vision-Language ModelsSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoGraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural NetworksSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoVCR-Bench: A Modular Open-Source Benchmark for Video Classification RobustnessSimilar attack · Arxiv (cs.RO + cs.CV security)