acceptodds
Under review as a conference paper at ICLR 2027

Latent Interface Purification for Robust World Action Models

Abstract

World-Action Models and vision-language-action policies transform visual observations into robot actions through learned visual latents. This latent interface is a vulnerable point: small visual perturbations can shift the representation consumed by the action expert, causing errors to compound during closed-loop control. Existing defenses commonly require retraining the full policy or transform inputs in pixel space, which can be costly or disrupt task-relevant visual information. We introduce Latent Interface Purification, a plug-and-play defense inserted between a frozen visual encoder and a frozen action expert. LIP learns bounded, input-conditioned residual corrections in the native latent space while leaving the underlying policy unchanged. Its scale-normalized multi-scale architecture is initialized as an exact identity map and is trained to recover clean representations while preserving clean inputs. Across diverse world-action-model backbones and two closed-loop manipulation benchmarks, LIP substantially improves task success under universal visual attacks, with limited loss of nominal performance. It also transfers zero-shot across distinct environments and robotic embodiments, while adding minimal isolated preprocessing overhead of 1.26 ms. These results establish latent-interface purification as an effective, practical direction for improving the adversarial robustness of generative robot policies.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.