TAPDreamer: Transferable Adversarial Patches for World Action Models
TAPDreamer crafts transferable adversarial patches that drop world-action robot success to near zero without querying policies.
Researchers introduce TAPDreamer, an attack that builds a fixed adversarial patch from a public visual encoder without querying the victim policy. The patch covers about 6.5% of the input and is trained on six frames from one source task so it transfers across tasks and action architectures. In closed-loop tests it cuts FastWAM success from 97.7% to 0.0% on 40 LIBERO tasks and from 90.8% to 0.0% on 50 RoboTwin tasks, while matched random patches retain about 80% success. The same patches reduce two DreamWAM configurations to 2.1% and 0.8% and Motus to 10.0%.