Task Conditions Tell More Than the Task: Dataset-Property Leakage and Private Release in World Action Models
Abstract
Robot policies often compress private demonstrations into reusable task conditions. Even when trajectories remain hidden, a released condition may expose a dataset property such as collection-domain composition. We introduce \method, a release-time framework that measures dataset-property leakage against adaptive attackers and tests whether protected conditions still control robot behavior. Across multiple manipulation tasks, attacks reliably distinguish and estimate demonstration mixtures, and the signal persists across visual representations and an implicit VLA state. Common perturbation and linear erasure defenses either remain vulnerable after attacker retraining or damage control utility. We therefore construct a record-level differentially private release constrained by public task semantics. It reduces adaptive inference to near-chance behavior while preserving closed-loop task performance. Matched-state interventions further show that the protected condition retains task-specific control rather than merely accompanying success from the policy prior. Together, these results identify a privacy boundary in robot task conditioning and show that formal protection can coexist with behavioral utility.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.