用大模型生成自动驾驶对抗场景,自动找攻击者并迭代优化。
LLM-attacker: Enhancing Closed-loop Adversarial Scenario Generation for Autonomous Driving with Large Language Models
- 用多个大模型代理协作识别最危险的交通参与者。
- 生成的对抗场景使自动驾驶碰撞率降低50%。
- 适合自动驾驶安全测试与强化学习研究者使用。
确保自动驾驶系统(ADS)的安全性对高度自动化车辆的部署至关重要,尤其在安全关键事件中。为应对事件稀少的问题,现有对抗场景生成方法通过操控交通参与者行为来诱发安全关键事件。然而,当前方法仍存在两个局限:首先,对抗参与者的识别直接影响生成效果,但真实场景中参与者众多、行为多样,识别难度大;其次,生成场景持续提升ADS性能的潜力尚未充分探索。为此,本文提出LLM-attacker:一种基于大语言模型(LLMs)的闭环对抗场景生成框架。具体地,设计多个LLM代理并协调其行为以识别最优攻击者,并优化其轨迹生成对抗场景。这些场景根据ADS表现迭代优化,形成反馈回路以持续改进系统。实验结果表明,相较于其他方法,LLM-attacker能生成更危险的场景,且使用其训练的ADS碰撞率仅为正常场景训练的半数,证明其在测试和增强ADS安全性与鲁棒性方面的有效性。视频演示见:https://drive.google.com/file/d/1Zv4V3iG7825oyiKbUwS2Y-rR0DQIE1ZA/view。
原文摘要 · Abstract (English)
Ensuring and improving the safety of autonomous driving systems (ADS) is crucial for the deployment of highly automated vehicles, especially in safety-critical events. To address the rarity issue, adversarial scenario generation methods are developed, in which behaviors of traffic participants are manipulated to induce safety-critical events. However, existing methods still face two limitations. First, identification of the adversarial participant directly impacts the effectiveness of the generation. However, the complexity of real-world scenarios, with numerous participants and diverse behaviors, makes identification challenging. Second, the potential of generated safety-critical scenarios to continuously improve ADS performance remains underexplored. To address these issues, we propose LLM-attacker: a closed-loop adversarial scenario generation framework leveraging large language models (LLMs). Specifically, multiple LLM agents are designed and coordinated to identify optimal attackers. Then, the trajectories of the attackers are optimized to generate adversarial scenarios. These scenarios are iteratively refined based on the performance of ADS, forming a feedback loop to improve ADS. Experimental results show that LLM-attacker can create more dangerous scenarios than other methods, and the ADS trained with it achieves a collision rate half that of training with normal scenarios. This indicates the ability of LLM-attacker to test and enhance the safety and robustness of ADS. Video demonstrations are provided at: https://drive.google.com/file/d/1Zv4V3iG7825oyiKbUwS2Y-rR0DQIE1ZA/view.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。