Modeling Latent Disturbances for Robust Decision-Making in World Models

Junwon Seo, Andrea Bajcsy

Carnegie Mellon University

Robust decision-making in the latent space of world models, by modeling latent-space disturbances.

Method

Latent disturbances perturb the learned dynamics within a calibrated uncertainty set of plausible transitions, solved via efficient game-theoretic optimization.

Robust Policy Steering

54%→15% failure rate with a robust latent safety filter and 35%→70% success rate with sample-and-verify in contact-rich manipulation.

Robust Optimization in World Model Latent Space

Robust decision-making directly in the latent space of world models, validated against ground-truth robust solutions when system dynamics and disturbances are known.

Benchmarks

Three vision-based tasks in simulation and the real world: Dubins’ car, block pouring, and egg serving with a Franka robot.

LUCID: Latent-space Uncertainty-Calibrated In-distribution Disturbance

Serve a sunny-side-up egg without flipping it.

Egg on the spatula before serving

Click a trajectory to explore its imagined outcome.

Predicted next latent state distributionCalibrated uncertainty setOut-of-distribution

World Model Latent Space

Uncertainty Set of Latent Dynamics

ACTION 1 / PESSIMISTIC

Current state

WM imaginations

Generated by the world model.

How can we make robust decisions in a world model’s learned latent space?

What is robust optimization?

The same serving motion can place the egg on the plate or flip it, depending on unobserved friction or oil on the spatula. Robust optimization selects an action that remains effective under the worst-case disturbance in a specified set. This is a game: the disturbance maximizes the cost of the outcome, while the robot chooses an action that minimizes this worst-case cost.

πrob(s)=arg⁡min⁡a∈A⏟choose an action  max⁡d∈D  C ⁣(f(s,a,d))⏟worst-case cost\pi_{\mathrm{rob}}(s)=\underbrace{\underset{a\in\mathcal A}{\arg\min}}_{\text{choose an action}}\;\underbrace{\colorbox{#FFCC80}{$\displaystyle\max_{d\in\mathcal D}\;C\!\left(f(s,a,d)\right)$}}_{\text{worst-case cost}}

How do we do this in latent space?

A world model learns compact latent states and their dynamics from observations. It does not explicitly represent disturbances such as friction or the amount of oil. Instead, uncertainty about these factors is reflected in its distribution of predicted next states.

Key idea: model a latent-space disturbance as a perturbation to the predicted next-state distribution. Optimize this disturbance within an uncertainty set of plausible latent dynamics to induce pessimistic world-model imaginations.

πrob(z)=arg⁡min⁡a∈A  max⁡fzd(z,a)∈F(z,a)  Ez′∼fzd(⋅∣z,a)⏟worst-case latent disturbance ⁣[C(z′)]\pi_{\mathrm{rob}}(z)=\underset{a\in\mathcal A}{\arg\min}\;\underbrace{\colorbox{#FFCC80}{$\displaystyle\max_{f_z^d(z,a)\in\colorbox{#79D8C4}{$\scriptstyle\mathcal F(z,a)$}}\;\mathbb E_{z'\sim f_z^d(\cdot\mid z,a)}$}}_{\text{worst-case latent disturbance}}\!\left[C(z')\right]

Here, the disturbance picks the most adverse latent dynamics within the uncertainty set, so that the world model imagines futures in which the action is most likely to fail, while the robot chooses the action that performs best even under these pessimistic imaginations. The uncertainty set must therefore include diverse transitions that are plausible under the system, while excluding implausible ones.

Challenge: Overly pessimistic disturbances. A nearby or high-likelihood latent state need not represent a physically feasible outcome. The disturbance can exploit these model errors and imagine impossible failures, making the robot overly conservative. The uncertainty set must cover adverse transitions while constraining implausible, out-of-distribution outcomes.

How to construct an uncertainty set over latent dynamics?

Current StateCurrent StateNext StateNext StateNext StateNext State

KL divergence from the predicted next-state distribution

Application: Robust Policy Steering

This latent-space robust optimization can be used to steer a task policy πtask at runtime, preventing hard-to-model failures under uncertainty. We instantiate it for two policy-steering paradigms, replacing nominal world-model imaginations with pessimistic yet plausible ones.

Latent Safety Filtering

Safeguard πtask with least-restrictive filtering: evaluate the safety of the action proposed by the task policy, and intervene with the robust safety policy only when that action is doomed to fail.

πrob(z)={πtask(z),if Ez′∼fz⋆(⋅∣z,πtask(z))[Vrobsafe(z′)]>0,πrobsafe(z),otherwise.\pi_{\mathrm{rob}}(z)=\begin{cases} \pi^{\mathrm{task}}(z), & \text{if }\colorbox{#FFCC80}{$\mathbb E_{z'\sim f_z^{\star}(\cdot\mid z,\pi^{\mathrm{task}}(z))}$}\big[V^{\mathrm{safe}}_{\mathrm{rob}}(z')\big]>0,\\[.4em] \pi^{\mathrm{safe}}_{\mathrm{rob}}(z), & \text{otherwise}. \end{cases}

The robust safety value and safety policy are learned with pessimistic imaginations induced by the latent disturbance:

Vrobsafe(z)=min⁡{ℓz(z),  max⁡a∈A  min⁡fzd∈F(z,a)Ez′∼fzd(⋅∣z,a)[Vrobsafe(z′)]}V^{\mathrm{safe}}_{\mathrm{rob}}(z)=\min\Big\{\ell_z(z),\;\max_{a\in\mathcal A}\;\colorbox{#FFCC80}{$\displaystyle\min_{f_z^d\in\colorbox{#79D8C4}{$\scriptstyle\mathcal F(z,a)$}}\mathbb E_{z'\sim f_z^d(\cdot\mid z,a)}$}\big[V^{\mathrm{safe}}_{\mathrm{rob}}(z')\big]\Big\}

Sample-and-Verify

Samples K candidate action sequences a(k) ∼ πtask(z), evaluates each with world-model imaginations, and executes the one with the lowest expected cost.

πrob(z)=arg⁡min⁡a∈{a(k)}k=1K  Ez′∼fz⋆(⋅∣z,a)[C(z′)]\pi_{\mathrm{rob}}(z)=\underset{\mathbf a\in\{\mathbf a^{(k)}\}_{k=1}^{K}}{\arg\min}\;\colorbox{#FFCC80}{$\displaystyle\mathbb E_{\mathbf z'\sim f_z^{\star}(\cdot\mid z,\mathbf a)}$}\big[C(\mathbf z')\big]

The learned latent disturbance generates adverse futures for each candidate, so action selection accounts for calibrated system uncertainty.

1) Real-World Results: Serving Sunny-Side-Up Fried Eggs

Robust latent safety filtering

Trajectory 1 / …

Loading trajectory…

Not FilteredRobust Safety Filter Active··· Zero threshold

Rollouts safeguarded by the robust safety filter. Orange marks steps where the filter overrides the task-policy action because its robust safety value becomes non-positive.

Why does the nominal safety filter fail?

Trajectory 1 / …

Loading trajectory…

Not FilteredNominal Safety Filter ActiveRobust Safety Value (Reference)··· Zero threshold

Rollouts safeguarded by the nominal safety filter. The dotted orange line evaluates the same rollout with the robust safety value for reference.

Does latent disturbance induce pessimistic yet plausible imaginations?

Example 1 / 10

Example 1

Nominal imagination

Camera 1Camera 2

Pessimistic imagination

Camera 1Camera 2
0.00 / 2.00 s

Both videos are generated by the world model.

Nominal (left) and pessimistic (right) world-model imaginations for the same real-world observation and action.

Robust to disturbances: different spatula surfaces

No tape

Failure rate ↓ · n = 30

95% Wilson intervals
No tape
MethodRate95% CICount
Base Policy0.63330.4551–0.781319 / 30
Nominal0.33330.1923–0.512210 / 30
Ours0.06670.0185–0.21322 / 30

Heavy-duty tape

Failure rate ↓ · n = 30

95% Wilson intervals
Heavy-duty tape
MethodRate95% CICount
Base Policy0.90000.7438–0.965427 / 30
Nominal0.60000.4232–0.754118 / 30
Ours0.13330.0531–0.29684 / 30

Scotch tape

Failure rate ↓ · n = 30

95% Wilson intervals
Scotch tape
MethodRate95% CICount
Base Policy0.83330.6644–0.926625 / 30
Nominal0.70000.5212–0.833421 / 30
Ours0.26670.1418–0.44458 / 30

Across all surfaces

Robust rate ↑ · n = 30

95% Wilson intervals
Across all surfaces
MethodRate95% CICount
Base Policy0.10000.0346–0.25623 / 30
Nominal0.16670.0734–0.33565 / 30
Ours0.66670.4878–0.807720 / 30

We replay 30 failure and 20 success trajectories on three spatula surfaces while safeguarding them. The robust rate is the fraction of trajectories that remain safe across all surfaces.

  • Ours consistently reduces failures and achieves a higher robust rate, so its interventions do not depend on a favorable surface.
  • The Nominal filter is effective only under certain surfaces: its fallback actions break down once the unobserved contact properties change.

Robustly safeguarding and steering task policies

Diffusion Policy · safety filtering

Success rate ↑ · n = 20

95% Wilson intervals
Diffusion Policy · safety filtering
MethodRate95% CICount
Base Policy0.10000.0279–0.30102 / 20
Nominal0.50000.2993–0.700710 / 20
Ours0.75000.5313–0.888115 / 20

π₀.₅ · safety filtering

Success rate ↑ · n = 20

95% Wilson intervals
π₀.₅ · safety filtering
MethodRate95% CICount
Base Policy0.40000.2188–0.61348 / 20
Nominal0.45000.2582–0.65799 / 20
Ours0.70000.4810–0.854514 / 20

π₀.₅ · policy steering

Success rate ↑ · n = 20

95% Wilson intervals
π₀.₅ · policy steering
MethodRate95% CICount
Base Policy0.40000.2188–0.61348 / 20
Nominal0.35000.1812–0.56717 / 20
UnConf.0.30000.1455–0.51906 / 20
Ours0.70000.4810–0.854514 / 20

Left two panels: safety filtering over 20 trials with Scotch tape on the spatula. Right panel: sample-and-verify steering of π₀.₅, which evaluates 8 candidate action chunks in world-model imagination and executes the one with the best predicted outcome.

  • As a safety filter, Ours improves success more than Nominal for both a diffusion policy and a fine-tuned VLA.
  • In steering, Ours selects actions that remain favorable even under plausible worst-case futures.
  • Nominal steering imagines optimistic futures for risky actions, while UnConf. steering imagines implausible failures even for safe actions, weakening discrimination among candidates.

2) Simulation Results: Block Pouring

Same action · Different physics

Does the in-distribution constraint matter?

Imagination using latent disturbance optimized without the in-distribution constraint

Executed in simulation

Camera 1Camera 2

OOD imagination

Camera 1Camera 2
0.00 / 3.07 s

Right video is generated by the world model.

Left: the action executed in simulation. Right: the imagined outcome of the same action, using a latent disturbance optimized without the in-distribution constraint.

Does latent disturbance induce pessimistic yet plausible imaginations?

Imagination 1

Nominal imagination

Camera 1Camera 2

Pessimistic imagination

Camera 1Camera 2
0.00 / 17.23 s

Both videos are generated by the world model.

Nominal (left) and pessimistic (right) world-model imaginations for the same initial state and action.

Does the robust safety value avoid overestimating safety?

Trajectory 1 / …

Loading trajectory…

Not FilteredNominal Safety Filter ActiveRobust Safety Filter Active··· Zero threshold

Both filters safeguard the same base action sequence. The plots show when each filter intervenes; the videos show whether those actions prevent failure.

Can robust filtering prevent failures under uncertainty?

Base policy

Randomized physics

2,000 rollouts per method

Randomized physics
MethodRate
Base Policy0.4400
Nominal0.4500
Worst-of-100.4600
CVaR (0.1)0.3900
UnConf.0.0000
Ours0.7300

Each policy is rolled out for 2,000 trajectories with randomized initial states and physics. Success: Fraction of rollouts that complete the task.

  • Sampling-based (Worst-of-N) and risk-sensitive (CVaR) baselines are less effective: in high-dimensional latent spaces, sampling rarely finds meaningful worst cases, while extreme tails can include implausible states.
  • Ours optimizes against worst-case plausible latent dynamics, reducing failures while remaining far less conservative than UnConf., which drops the in-distribution constraint.
  • Its interventions yield positive safety gains, moving the system toward safer realized states, whereas Nominal gains are smaller or even negative.

Robustness under controlled uncertainty

Base policyTeleoperation trajectories

Controlled-physics replay

100 trajectories × 20 physics settings

Controlled-physics replay
MethodRate
Base Policy0.1000
Nominal0.1100
Worst-of-100.0700
CVaR (0.1)0.1000
UnConf.0.9000
Ours0.7700

We replay 100 successful teleoperation trajectories, each under 20 different physics settings. All-safe: Fraction of trajectories safe under all 20 physics settings.

  • Ours keeps most trajectories failure-free across all physics settings, with safety actions that remain effective across dynamics variations.
  • UnConf. also avoids failures, but only by rarely completing the task, since implausibly pessimistic imaginations make useful actions look unsafe.

Robustness under partial observability

Base policy

Fixed physics

2,000 rollouts per method

Fixed physics
MethodRate
Base Policy0.4300
Nominal0.6000
Worst-of-100.3400
CVaR (0.1)0.0000
UnConf.0.0000
Ours0.8100

The same task with fixed physics, so uncertainty arises only from partial observability and model approximation. Success: Fraction of rollouts that complete the task.

  • Even when the system is deterministic, the learned world model remains uncertain about future transitions due to partial observability.
  • Nominal filtering is more effective than under randomized physics, but Ours further reduces failures by accounting for this remaining uncertainty.

BibTeX

@article{seo2026modeling,
  title   = {Modeling Latent Disturbances for Robust Decision-Making in World Models},
  author  = {Seo, Junwon and Bajcsy, Andrea},
  journal = {arXiv preprint arXiv:2610.07599},
  year    = {2026}
}