NOTAS DE CAMPO / LDM ZARAGOZA / CALATAYUD · 2026
RESEARCH IA/PAPER 15

MULTIMODAL

BadWAM: When World-Action Models Dream Right but Act Wrong

VigilarLectura primaria completa

Cuestiona la idea de que un World-Action Model es seguro porque podemos inspeccionar el futuro que imagina.

AUTHORS / LABQi Li, Xingyi Yang, Xinchao Wang
FECHA16 JULIO 2026.
LECTURALectura primaria completa
LECTURA DE 60 SEGUNDOS

Lo esencial antes de invertir más tiempo.

HALLAZGO

Cuestiona la idea de que un World-Action Model es seguro porque podemos inspeccionar el futuro que imagina. Introduce ataques que, mediante pequeñas perturbaciones visuales, desacoplan la predicción del mundo futuro de la acción que finalmente ejecuta el robot.

EVIDENCIA DISPONIBLE

As \lambda increases, future distance generally decreases, showing that the preservation term actively shapes the search rather than merely changing the reported metric.

Resultado reportado con fuente enlazada · 5 localizadores disponibles.
LÍMITE

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 5 Evaluation.

SIGUIENTE PRUEBA

Comparar la métrica principal de la fuente junto con calidad, coste, latencia y tasa de errores.

EN UNA FRASE

Cuestiona la idea de que un World-Action Model es seguro porque podemos inspeccionar el futuro que imagina. Introduce ataques que, mediante pequeñas perturbaciones visuales, desacoplan la predicción del mundo futuro de la acción que finalmente ejecuta el robot.

SEÑALrobótica · automoción
EVIDENCIAResultado reportado con fuente enlazada
CONFIANZA EDITORIALMedia
RESULTADOS / PROCEDENCIA

Qué está reportado y qué conviene comprobar.

Hay resultado reportado con fuente enlazada.
RESULTADO REPORTADO

As \lambda increases, future distance generally decreases, showing that the preservation term actively shapes the search rather than merely changing the reported metric.

contexto: 5 Evaluation

RESULTADO REPORTADO

For the joint WAM, increasing \lambda from 0 to 0.015 reduces D_{\mathrm{img}} from 14.70 to 14.34 and lowers task success from 61.7% to 56.7%.

61.7% · contexto: 5 Evaluation

RESULTADO REPORTADO

For the IDM WAM, the same setting reduces D_{\mathrm{img}} from 15.36 to 15.13 and lowers success from 55.0% to 51.7%.

55.0% · contexto: 5 Evaluation

RESULTADO REPORTADO

At the default \epsilon=0.06 , success drops to 56.7% and 51.7% on the balanced subset.

56.7% · contexto: 5 Evaluation

LECTURA DEL PAPER / SÍNTESIS EDITORIAL

Qué estudiaron y qué cambia.

La síntesis está separada de los resultados reportados y de las inferencias.

PROBLEMA / La señal entra en el radar porque «El modelo imagina un futuro razonable» no garantiza «el robot hará algo coherente con ese futuro».

MÉTODO / La lectura de 3 Threat Model describe la intervención y su construcción: We study inference-time attacks against deployed WAM-based robot policies. Following the notation introduced above, the robot observes o_{t} and receives an instruction or goal g at each replanning step. The WAM then outputs an action chunk a_{t:t+H-1} and, depending on the model interface, may also expose an imagined future in latent form z_{t+1:t+K} or decoded video form v_{t+1:t+K} . The robot executes part of the predicted action chunk, observes the environment again, and repeats this process in closed loop. Adversarial capability. The adversary can perturb the visual observation before it is processed by… [Fuente: https://arxiv.org/html/2607.15207#S3]

RESULTADO / La sección 5 Evaluation informa: As \lambda increases, future distance generally decreases, showing that the preservation term actively shapes the search rather than merely changing the reported metric. For the joint WAM, increasing \lambda from 0 to 0.015 reduces D_{\mathrm{img}} from 14.70 to 14.34 and lowers task success from 61.7% to 56.7%. For the IDM WAM, the same setting reduces D_{\mathrm{img}} from 15.36 to 15.13 and lowers success from 55.0% to 51.7%. [Fuente: https://arxiv.org/html/2607.15207#S5]

LÍMITE / El cierre de la fuente señala: For repeated-trial evaluation, we use pass@ k . For a fixed task, pass@ k is the fraction of successful executions among the first k trials. We then average this quantity across tasks. This metric shows whether an attack only causes isolated unlucky failures or consistently lowers reliability as more trials are considered. La transferencia a red-teaming robótico requiere repetir la comparación con datos y criterios propios [Fuente: https://arxiv.org/html/2607.15207#S6].

DECISIÓN RÁPIDAProbar la propuesta en red-teaming robótico reproduciendo primero la comparación y registrando calidad, coste, latencia y errores.
NO LO SOBREINTERPRETES

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 5 Evaluation.

PROBLEMA
«El modelo imagina un futuro razonable» no garantiza «el robot hará algo coherente con ese futuro».
MÉTODO
La lectura de 3 Threat Model describe la intervención y su construcción: We study inference-time attacks against deployed WAM-based robot policies. Following the notation introduced above, the robot observes o_{t} and receives an instruction or goal g at each replanning step. The WAM then outputs an action chunk a_{t:t+H-1} and, depending on the model interface, may also expose an imagined future in latent form z_{t+1:t+K} or decoded video form v_{t+1:t+K} . The robot executes part of the predicted action chunk, observes the environment again, and repeats this process in closed loop. Adversarial capability. The adversary can perturb the visual observation before it is processed by…
TIPO DE EVIDENCIA
La sección 5 Evaluation informa 4 hallazgo(s) extraído(s) desde la fuente. El resultado principal se conserva con el localizador de sección https://arxiv.org/html/2607.15207#S5.
LÍMITE
La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 5 Evaluation.
FIELD NOTES / ANOTACIONES

La lectura también deja rastro.

Guarda una observación junto a la evidencia. Tú escribes aquí; los agentes pueden añadir notas por MCP y aparecerán identificados.

MEMORIA PRIVADAEntra para anotar este paper y conectarlo con otros.
Entrar con ChatGPT
LECTURA AMPLIADAMetodología, implicaciones y preguntas para volver al paper.+
LECTURA EN 90 SEGUNDOSLo que conviene llevarse antes de abrir el PDF.
QUÉ HACE

La lectura de 3 Threat Model describe la intervención y su construcción: We study inference-time attacks against deployed WAM-based robot policies. Following the notation introduced above, the robot observes o_{t} and receives an instruction or goal g at each replanning step. The WAM then outputs an action chunk a_{t:t+H-1} and, depending on the model interface, may also expose an imagined future in latent form z_{t+1:t+K} or decoded video form v_{t+1:t+K} . The robot executes part of the predicted action chunk, observes the environment again, and repeats this process in closed loop. Adversarial capability. The adversary can perturb the visual observation before it is processed by…

QUÉ APORTA

Es un fallo de seguridad conceptualmente importante para world models y robótica agentic: la supervisión visual de una predicción futura puede crear una falsa sensación de seguridad.

QUÉ NO PRUEBA

La lectura primaria permite comprobar método y resultados en el HTML, pero no convierte sus conclusiones en validación independiente. La ficha no demuestra transferencia fuera de los datasets, modelos, herramientas y condiciones descritos en 5 Evaluation.

Cómo lo llevaría a un proyecto

Probar la propuesta en red-teaming robótico reproduciendo primero la comparación y registrando calidad, coste, latencia y errores.

red-teaming robóticovalidación de WAM/VLAsafety monitoring.

Preguntas que conviene probar

  • ¿La mejora se mantiene cuando red-teaming robótico cambia de dominio o distribución?
  • ¿Qué componente del método explica la mayor parte del resultado y qué baseline lo pone realmente a prueba?
PLANTILLA DE PRUEBA / INFERENCIA EDITORIAL

Si tuviera que convertirlo en una prueba mañana.

ENTRADAred-teaming robótico con un conjunto pequeño de casos representativos y la misma métrica o protocolo que la fuente cuando sea reproducible.
PREGUNTA¿La propuesta mejora red-teaming robótico frente a la línea base actual?
MÉTRICAComparar la métrica principal de la fuente junto con calidad, coste, latencia y tasa de errores.
PARADAParar si no aparece una mejora reproducible o si aumenta el riesgo, la complejidad o el coste sin compensación.

Mi lectura

La pregunta operativa es si red-teaming robótico puede medirse con una línea base y un criterio de parada claros.

Esta última frase es una inferencia editorial a partir del paper y de sus posibles implicaciones; no es una afirmación de los autores.