Security design questions for federated world-model autonomous driving

Investigate which planner-facing representation is sufficiently interpretable and independent for semantic canaries, determine how to calibrate imagination-reality audits across heterogeneous benign vehicles without rejecting rare safety-critical clients, establish whether per-candidate rollout scoring can be reconciled with secure aggregation while preserving gradient confidentiality at acceptable cost, and determine how to mitigate the counterfactual blind spot in deployment-time auditing.

Background

The paper identifies several unresolved design problems for securing federated world-model-based autonomous driving (WM-AD). FedWM-Guard screens client updates using planner-facing imagined futures and audits deployed predictions against independently observed sensor evidence, but the appropriate representation for semantic canaries remains unsettled: it must be interpretable to support safety analysis while sufficiently independent to provide meaningful detection.

The proposed defense also faces calibration and systems challenges. Audit thresholds must account for heterogeneous benign vehicles and rare safety-critical driving conditions; candidate-model scoring may conflict with secure aggregation and gradient confidentiality; and deployment-time imagination-reality audits cannot directly observe counterfactual futures, creating a blind spot that requires mitigation.

References

There are several open questions for federated WM-AD security. Which planner-facing representation is interpretable yet independent enough for semantic canaries? How to calibrate audits across heterogeneous benign vehicles without rejecting rare safety-critical clients? Can D2's per-candidate scoring be reconciled with secure aggregation (inspecting gradients), while recovering gradient confidentiality at acceptable cost? How can the counterfactual blind spot in D3 be mitigated?

— Poster: FedWM-Guard: Thwarting Imagination Poisoning in Federated World Model-based Autonomous Driving  (2609.29178 - Liu et al., 24 Sep 2026) in Section Discussion