BadWAM: Right Mind but Wrong Action
Qi Li · hf · 2026-07-17
BadWAM: World-Action Models Can "Think Right, Act Wrong"
This paper investigates the adversarial vulnerability of World-Action Models (WAMs). WAMs couple action generation with future world prediction, making them often perceived as more robust, interpretable, and safe; however, the authors point out that this "imagination-execution consistency" is actually quite fragile.
Proposed Attacks
BadWAM uniformly describes and evaluates a class of World-Action Drift Attacks against WAMs:
- Action-only attack: Prioritizes disrupting the task by directly pushing the model towards failed actions
- Imagination-preserving attack: Pursues stealth, making the model still predict plausible futures on the surface while actions drift during execution
Results
- Significantly reduces closed-loop execution success rates across different WAM variants
- In the provided examples, the action-only attack dropped the success rate from 96.5% to 43.1%
- Even with some future-grounding regularization, strong attack effects can still be maintained
Conclusion: A WAM "thinking correctly" does not equate to "acting safely".
More from Embodied
- ECCV26 Oral: Flow Matching Enables Single-Stage Multi-View Point Cloud Registration — ducha_aiki · 2026-09-11
- Polish developers build iPhone app that detects nearby Meta smart glasses — Low-Honeydew6483 · 2026-09-11
- Ant's Afu health AI hits 150M users, unveils AI+hardware health alliance at Bund Summit — APPSO · 2026-09-11
- Johns Hopkins Launches Full-Stack Hands-on Robot Learning Class with SO-101 Arm Kits — _krishna_murthy · 2026-09-11
- SyncWorld: In-Context Robot World Model Simulates Unseen Views and Embodiments Zero-Shot — ChongZzZhang · 2026-09-11
- A 3D Pose Dataset for Dogs Released — ducha_aiki · 2026-09-11