BadWAM: Right Mind but Wrong Action
Qi Li · hf · 2026-07-17
BadWAM: World-Action Models Can "Think Right, Act Wrong"
This paper investigates the adversarial vulnerability of World-Action Models (WAMs). WAMs couple action generation with future world prediction, making them often perceived as more robust, interpretable, and safe; however, the authors point out that this "imagination-execution consistency" is actually quite fragile.
Proposed Attacks
BadWAM uniformly describes and evaluates a class of World-Action Drift Attacks against WAMs:
- Action-only attack: Prioritizes disrupting the task by directly pushing the model towards failed actions
- Imagination-preserving attack: Pursues stealth, making the model still predict plausible futures on the surface while actions drift during execution
Results
- Significantly reduces closed-loop execution success rates across different WAM variants
- In the provided examples, the action-only attack dropped the success rate from 96.5% to 43.1%
- Even with some future-grounding regularization, strong attack effects can still be maintained
Conclusion: A WAM "thinking correctly" does not equate to "acting safely".
More from Embodied
- Humanoid robots are moving from labs into public culture — Olivier__OG · 2026-07-21
- Polymarket puts Tesla’s California robotaxi launch odds at 16% this year — Polymarket · 2026-07-21
- Tesla expands robotaxi service to Orlando and Tampa — Polymarket · 2026-07-21
- Humanoid robots are approaching a deeper uncanny valley — GlenBradley · 2026-07-21
- Polymarket gives Tesla’s Optimus just a 17% chance of debuting this year — Polymarket · 2026-07-21
- UK robotics startup Humanoid raises $152 million at a $1.35 billion valuation — Polymarket · 2026-07-21