Search papers, labs, and topics across Lattice.
This paper surveys the security vulnerabilities associated with world-model-based embodied AI, emphasizing how threats can propagate through the entire lifecycle of these models鈥攆rom data collection to execution. It identifies various attack vectors, such as poisoning and adversarial examples, that uniquely impact the integrity of world states and learned dynamics. The study also reveals a critical duality where world models can act as safety shields but may create false security if compromised or over-relied upon, leading to predictive safety illusions.
Compromised world models can create dangerous predictive safety illusions, exposing embodied AI to a lifecycle of unique security threats.
World models give embodied AI a predictive core: they compress observations into states, simulate action-conditioned futures, and enable planning beyond reactive control. This predictive layer, however, opens a new security boundary-compromise can propagate from data, sensors, prompts, or feedback into physical action. Rather than treating world models as an isolated component, this survey traces threats across their entire lifecycle-from data construction and representation learning, through state grounding and imagination, to trajectory evaluation, execution, and long-term adaptation via memory and tools. We show that familiar attack families: poisoning, backdoors, adversarial examples, sensor spoofing, prompt injection, trajectory manipulation, and supply-chain attacks take on distinct meanings when they corrupt world states, learned dynamics, affordance estimates, or safety costs. We also highlight a duality: world models can serve as runtime safety shields, yet when compromised or over-trusted they generate predictive safety illusions. The survey offers a lifecycle taxonomy, maps existing attacks to world-model security properties, outlines evaluation protocols for safety failures, and structures defenses across provenance, robust grounding, uncertainty-aware prediction, trajectory gating, feedback auditing, and deployment assurance.