BadDreamer: Backdoor Attacks on Video World Models for Autonomous Driving
Abstract
Driving world models anticipate traffic dynamics, making the persistence of nearby road users a safety-relevant prediction target. We present BadDreamer, a data-poisoning backdoor that pairs rider-visible context with future supervision lacking that rider, while leaving ego-trajectory labels unchanged. We evaluate separately adapted VaViM/VaVAM, DriveDreamer-2, and VISTA systems, spanning autoregressive and diffusion generation and including multi-view inputs. Matched clean/poisoned comparisons show triggered future-omission rates rising from 15.4–18.8% to 91.7–94.1%. With downstream planning and control fixed within each system, simulated collision rates increase by 36.6–41.5 percentage points. Ordinary-input video-quality metrics change modestly, while appearance controls reveal strong target preference with partial selectivity. These results establish a system-level vulnerability to poisoned adaptation and identify conditional road-user persistence as a diagnostic beyond aggregate video quality.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.