Small, fixed adversarial patches can severely degrade world action models across multiple robotic tasks by exploiting how visual encoders process information, highlighting that securing shared visual components is critical for robust robotic control systems.
This paper presents TAPDreamer, an attack method that uses small visual patches to fool world action models—AI systems that predict how robotic environments will change. Unlike previous attacks, TAPDreamer works without accessing the target model, instead using a public encoder to create a single patch that transfers across different tasks and robot policies.