Ethics & SecurityOctober 05, 2026
17
🌱

One Sticker Kills Every Robot Policy

TAPDreamer patches drop world action model success rates from 97.7% to 0%.

#adversarial patches#robotics#world models#security#transferability
Ein Aufkleber legt Roboter lahm
Share Article
šŸ”„ What happened University of Maryland researchers unveiled TAPDreamer, a frozen adversarial patch that drops FastWAM's success rate from 97.7% to 0.0% across 40 LIBERO tasks. The patch covers just 6.5% of the camera input and needs zero queries against the target policy. šŸ’” Why it matters Prior attacks required constant access to the victim model. TAPDreamer uses only a public encoder and transfers across tasks and architectures — DreamWAM falls to 2.1%, Motus to 10.0%. Random patches of the same size leave 81.5% success intact, proving this is a targeted representation shift, not noise. ⚔ Our take Securing robot policies while leaving the shared vision encoder exposed is a lock without a door. World models need encoder hardening now — before the first physical attack writes the lesson for them.
The title, summary and analysis of this item were produced automatically by an AI system and have not been editorially reviewed. They may contain errors, bias or omissions — when in doubt, read the linked original source.