Poisoning Robot Demonstrations with Hidden Physical Costs
Abstract
Robot learning pipelines increasingly rely on large-scale demonstration data aggregated from diverse sources, where task success is often the primary criterion for data validation and filtering. However, successful demonstrations can still encode physically costly execution patterns. We show that this creates a safety blind spot, where policies can complete tasks while systematically incurring hidden physical burden. To study this failure mode, we introduce Fatigue Injection, a diagnostic data-poisoning method that injects small, structured perturbations into successful demonstrations during data collection, targeting physical execution costs rather than task behavior. We quantify the resulting burden using cumulative fatigue damage and operating energy, two hardware-aware metrics that expose physical costs hidden behind successful executions. Across simulation and real-world manipulation tasks, policies trained on poisoned data achieve success rates comparable to clean baselines while incurring substantially higher cumulative fatigue damage and energy costs. Notably, this effect persists under partial poisoning and across diverse policy architectures, and cannot be easily mitigated by simple inference-time smoothing or identified by generic data-inspection baselines. Together, these results show that task success alone is an insufficient quality gate for safe robot learning, motivating hardware-aware auditing of execution-level dynamics and physical burden in demonstration data to support safe real-world deployment.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.