Poster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving

📅 2026-09-24
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the threat of “imagination poisoning” in federated world models for autonomous driving (FedWM-AD), wherein malicious clients compromise the model’s long-horizon predictive capabilities through corrupted updates. To mitigate this vulnerability, we propose FedWM-Guard, the first defense framework that innovatively computes anomaly scores within the update-induced imagination space rather than the conventional parameter space. This mechanism integrates rollout planning monitoring, hidden canary scenario detection, and prediction consistency auditing to construct an independent security shield against adversarial manipulation. Our primary contribution lies in formally defining and systematically defending against imagination poisoning attacks in FedWM-AD, thereby exposing a novel threat surface in federated driving learning. Future work will further validate the robustness of FedWM-Guard under non-IID data distributions and adaptive attack scenarios.
📝 Abstract
Federated learning (FL) can improve world model (WM)-based autonomous driving (AD) without centralizing raw private vehicle data, but it also turns model aggregation into a safety-critical integrity boundary. We introduce a new threat in federated WM-AD, namely \emph{imagination poisoning}: compromised vehicles submit bounded WM updates that preserve benign short-horizon predictions yet corrupt long-horizon rollouts (e.g., trigger-conditioned) during training, thereby misleading a downstream planner. We present \emph{FedWM-Guard}, to the best of our knowledge, the first defense to characterize planner-facing rollouts in federated WM-AD, screen authenticated updates in hidden-canary scenarios, audit predicted futures against later observations, and invoke a WM-independent safety shield when persistent inconsistency is detected. Unlike parameter-space defenses, it scores what an update makes the model \emph{imagine}, not only how the update looks. We also outline how we plan to evaluate it under non-IID (not independent and identically distributed) data, adaptive attacks, and benign distribution shift. This work highlights an unexplored domain, federated WM-AD, and its threat surface and potential countermeasures.
Problem

Research questions and friction points this paper is trying to address.

Federated Learning
World Model
Autonomous Driving
Imagination Poisoning
Adversarial Attack
Innovation

Methods, ideas, or system contributions that make the work stand out.

Federated World Model
Imagination Poisoning
Autonomous Driving
Rollout Auditing
Safety Shield