Security design questions for federated world-model autonomous driving
Investigate which planner-facing representation is sufficiently interpretable and independent for semantic canaries, determine how to calibrate imagination-reality audits across heterogeneous benign vehicles without rejecting rare safety-critical clients, establish whether per-candidate rollout scoring can be reconciled with secure aggregation while preserving gradient confidentiality at acceptable cost, and determine how to mitigate the counterfactual blind spot in deployment-time auditing.
References
There are several open questions for federated WM-AD security. Which planner-facing representation is interpretable yet independent enough for semantic canaries? How to calibrate audits across heterogeneous benign vehicles without rejecting rare safety-critical clients? Can D2's per-candidate scoring be reconciled with secure aggregation (inspecting gradients), while recovering gradient confidentiality at acceptable cost? How can the counterfactual blind spot in D3 be mitigated?