π€ AI Summary
This work addresses the emerging security challenges posed by world models in embodied intelligence, which introduce new safety boundaries yet remain vulnerable to diverse attacks throughout their lifecycle, potentially compromising physical actions. The study presents the first lifecycle-based taxonomy for world model security, systematically analyzing threats across all stagesβfrom data construction and state representation to imagination-based simulation, trajectory execution, and long-term adaptation. It reveals how conventional attacks manifest in predictive state spaces and elucidates the dual role of world models as both protective mechanisms and sources of risk illusions. To counter these threats, the paper proposes an integrated defense framework encompassing threat modeling, robust state grounding, uncertainty-aware prediction, trajectory gating, and feedback auditing, along with a comprehensive evaluation protocol. This establishes a closed-loop pipeline linking threats, defenses, and assessments, clarifying how attacks impact world states, dynamics models, and safety costs, thereby offering foundational insights and practical guidance for secure embodied intelligence.
π Abstract
World models give embodied AI a predictive core: they compress observations into states, simulate action-conditioned futures, and enable planning beyond reactive control. This predictive layer, however, opens a new security boundary-compromise can propagate from data, sensors, prompts, or feedback into physical action. Rather than treating world models as an isolated component, this survey traces threats across their entire lifecycle-from data construction and representation learning, through state grounding and imagination, to trajectory evaluation, execution, and long-term adaptation via memory and tools. We show that familiar attack families: poisoning, backdoors, adversarial examples, sensor spoofing, prompt injection, trajectory manipulation, and supply-chain attacks take on distinct meanings when they corrupt world states, learned dynamics, affordance estimates, or safety costs. We also highlight a duality: world models can serve as runtime safety shields, yet when compromised or over-trusted they generate predictive safety illusions. The survey offers a lifecycle taxonomy, maps existing attacks to world-model security properties, outlines evaluation protocols for safety failures, and structures defenses across provenance, robust grounding, uncertainty-aware prediction, trajectory gating, feedback auditing, and deployment assurance.