arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Poster: FedWM-Guard: 在基于联邦世界模型的自动驾驶中挫败想象投毒

Poster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving

Sheng Liu, Panos Papadimitratos

arXiv 2609.29178首次发表:更新:

发表机构

KTH Royal Institute of Technology(皇家理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对联邦世界模型自动驾驶中的想象投毒攻击,提出FedWM-Guard防御方法,通过金丝雀场景筛选和未来审计保护规划器安全。

AI 中文摘要

联邦学习(FL)可以在不集中原始私有车辆数据的情况下改进基于世界模型(WM)的自动驾驶(AD),但它也将模型聚合转变为安全关键的完整性边界。我们在联邦WM-AD中引入了一种新的威胁,即“想象投毒”:受损车辆提交有界的WM更新,这些更新保留了良性的短视界预测,但在训练期间破坏长视界展开(例如,触发条件),从而误导下游规划器。我们提出了FedWM-Guard,据我们所知,这是第一个在联邦WM-AD中表征面向规划器的展开、在隐藏金丝雀场景中筛选认证更新、根据后续观察审计预测未来,并在检测到持续不一致时调用独立于WM的安全盾牌的防御方法。与参数空间防御不同,它对更新使模型“想象”的内容进行评分,而不仅仅是更新看起来如何。我们还概述了计划如何在非IID(非独立同分布)数据、自适应攻击和良性分布偏移下评估它。这项工作突出了一个未被探索的领域,即联邦WM-AD,及其威胁面和潜在对策。

英文摘要

Federated learning (FL) can improve world model (WM)-based autonomous driving (AD) without centralizing raw private vehicle data, but it also turns model aggregation into a safety-critical integrity boundary. We introduce a new threat in federated WM-AD, namely \emph{imagination poisoning}: compromised vehicles submit bounded WM updates that preserve benign short-horizon predictions yet corrupt long-horizon rollouts (e.g., trigger-conditioned) during training, thereby misleading a downstream planner. We present \emph{FedWM-Guard}, to the best of our knowledge, the first defense to characterize planner-facing rollouts in federated WM-AD, screen authenticated updates in hidden-canary scenarios, audit predicted futures against later observations, and invoke a WM-independent safety shield when persistent inconsistency is detected. Unlike parameter-space defenses, it scores what an update makes the model \emph{imagine}, not only how the update looks. We also outline how we plan to evaluate it under non-IID (not independent and identically distributed) data, adaptive attacks, and benign distribution shift. This work highlights an unexplored domain, federated WM-AD, and its threat surface and potential countermeasures.

CommentsTo appear in the 2026 ACM Conference on Computer and Communications Security (CCS)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑