arXiv · 2609.29178
Poster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving
Abstract
Federated learning (FL) can improve world model (WM)-based autonomous driving (AD) without centralizing raw private vehicle data, but it also turns model aggregation into a safety-critical integrity boundary. We introduce a new threat in federated WM-AD, namely \emph{imagination poisoning}: compromised vehicles submit bounded WM updates that preserve benign short-horizon predictions yet corrupt long-horizon rollouts (e.g., trigger-conditioned) during training, thereby misleading a downstream planner. We present \emph{FedWM-Guard}, to the best of our knowledge, the first defense to characterize planner-facing rollouts in federated WM-AD, screen authenticated updates in hidden-canary scenarios, audit predicted futures against later observations, and invoke a WM-independent safety shield when persistent inconsistency is detected. Unlike parameter-space defenses, it scores what an update makes the model \emph{imagine}, not only how the update looks. We also outline how we plan to evaluate it under non-IID (not independent and identically distributed) data, adaptive attacks, and benign distribution shift. This work highlights an unexplored domain, federated WM-AD, and its threat surface and potential countermeasures.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Sheng Liu, Panos Papadimitratos. 2026-09-24. Poster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving. https://arxiv.org/abs/2609.29178
Cite the original work for its findings. Save a collection to share your selection of sources.