월드 모델 기반 로봇 AI의 보안: 위협, 방어 및 평가의 라이프사이클
Security of World-Model-Based Embodied AI: A Lifecycle of Threats, Defenses, and Evaluation
월드 모델은 로봇 AI에게 예측 기능을 제공합니다. 월드 모델은 관찰 데이터를 상태로 압축하고, 행동에 따른 미래를 시뮬레이션하며, 반응적인 제어를 넘어선 계획을 가능하게 합니다. 그러나 이러한 예측 계층은 새로운 보안 취약점을 야기하며, 데이터, 센서, 프롬프트 또는 피드백으로부터 물리적 행동으로 보안 침해가 전파될 수 있습니다. 본 연구는 월드 모델을 독립적인 구성 요소로 간주하는 대신, 데이터 구축 및 표현 학습부터 상태 인식 및 상상력, 경로 평가, 실행, 그리고 메모리와 도구를 통한 장기 적응에 이르기까지 전체 라이프사이클에 걸쳐 위협을 분석합니다. 익숙한 공격 유형(데이터 오염, 백도어, 적대적 예제, 센서 스푸핑, 프롬프트 주입, 경로 조작 및 공급망 공격)이 월드 모델의 상태, 학습된 역학 관계, 활용 가능성 추정 또는 안전 비용을 손상시킬 때 독특한 의미를 갖는다는 것을 보여줍니다. 또한, 월드 모델은 런타임 안전 장치 역할을 할 수 있지만, 손상되거나 과신될 경우 예측적인 안전 착각을 유발할 수 있다는 이중성을 강조합니다. 본 연구는 라이프사이클 분류 체계를 제시하고, 기존 공격을 월드 모델의 보안 속성에 매핑하며, 안전 실패에 대한 평가 프로토콜을 개략적으로 설명하고, 출처 관리, 강력한 상태 인식, 불확실성 기반 예측, 경로 제한, 피드백 감사 및 배포 보증을 통해 방어를 구조화합니다.
World models give embodied AI a predictive core: they compress observations into states, simulate action-conditioned futures, and enable planning beyond reactive control. This predictive layer, however, opens a new security boundary-compromise can propagate from data, sensors, prompts, or feedback into physical action. Rather than treating world models as an isolated component, this survey traces threats across their entire lifecycle-from data construction and representation learning, through state grounding and imagination, to trajectory evaluation, execution, and long-term adaptation via memory and tools. We show that familiar attack families: poisoning, backdoors, adversarial examples, sensor spoofing, prompt injection, trajectory manipulation, and supply-chain attacks take on distinct meanings when they corrupt world states, learned dynamics, affordance estimates, or safety costs. We also highlight a duality: world models can serve as runtime safety shields, yet when compromised or over-trusted they generate predictive safety illusions. The survey offers a lifecycle taxonomy, maps existing attacks to world-model security properties, outlines evaluation protocols for safety failures, and structures defenses across provenance, robust grounding, uncertainty-aware prediction, trajectory gating, feedback auditing, and deployment assurance.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.