When World Models Lie: Adaptive Safety Analysis Under Wrong Imaginations

John Cao, Somil Bansal
Stanford University

Abstract

World models offer a powerful substrate for safety reasoning in high-dimensional robotic systems, but they are also fallible: their predictions can be biased, miscalibrated, or confidently wrong. This creates a central challenge for latent-space safety filters, which often learn Hamilton-Jacobi safety value functions on the dynamics of a world model. If the world model is incorrect, the resulting value function can inherit its errors and produce overconfident safety estimates. Existing latent safety filters often rely on auxiliary signals such as ensemble disagreement or value-target consistency residuals for adaptation, but these signals can remain small even when the world model's predictions deviate from observations.

We propose an adaptive latent safety filter that calibrates safety reasoning using directly observed world-model error. Our method uses Adaptive Conformal Inference to construct online uncertainty sets from discrepancies between predicted and observation-inferred latent states, then evaluates safety pessimistically by minimizing the learned value function over these sets. This allows the filter to remain minimally conservative when the world model is accurate, while becoming more cautious when observations reveal model mismatch. We provide a finite-time coverage guarantee for the adaptive uncertainty radius. Through simulation and hardware experiments, we show that our method significantly reduces failures relative to state-of-the-art latent safety filters while preserving task completion.

Key Takeaways

  • Wrong world models can degrade safety reasoning. Incorrect world models can lead to overconfident safety estimates when used in latent safety filters, resulting in unsafe behavior.
  • Auxiliary signals do not always reveal an errenous world model. Existing methods use auxiliary signals such as ensemble disagreement or Bellman consistency scores to robustify latent safety filters, but these signals can remain small even under large model mismatch.
  • Fewer failures without sacrificing the task. By using world model prediction errors to reason pessimically about safety, our method drastically reduces failures while maintaining high task performance.