通过扰动未来轨迹,更真实地测试自动驾驶预测模型的鲁棒性。
Realistic Adversarial Attacks for Robustness Evaluation of Trajectory Prediction Models via Future State Perturbation
- 在历史轨迹基础上,同时扰动未来状态生成更具现实性的对抗攻击。
- 实验显示攻击下预测误差和碰撞率显著上升,暴露模型致命缺陷。
- 适合自动驾驶安全评估、模型鲁棒性研究者参考。
轨迹预测是自动驾驶系统的核心,使车辆能够预判并响应其他交通参与者的行为。评估预测模型对对抗攻击的鲁棒性对确保其在真实交通中的可靠性至关重要。然而,现有方法多聚焦于扰动周围车辆的历史位置,易生成不现实场景,忽略关键漏洞,导致对模型性能的评估过于乐观。本文证明,不仅扰动历史,还扰动对抗目标的未来状态,可揭示此前未被发现的弱点,实现更严格的鲁棒性评估。所提方法引入动态约束并保留战术行为,使攻击更有效且真实。我们设计新指标衡量对抗轨迹的现实性与影响。在一款前沿预测模型上测试发现,对抗条件下预测误差与碰撞率显著升高。定性分析表明,攻击能暴露模型在看似安全预测中未能识别潜在碰撞的缺陷。结果强调需更全面的对抗测试以提升自动驾驶轨迹预测模型的可靠性。
原文摘要 · Abstract (English)
Trajectory prediction is a key element of autonomous vehicle systems, enabling them to anticipate and react to the movements of other road users. Evaluating the robustness of prediction models against adversarial attacks is essential to ensure their reliability in real-world traffic. However, current approaches tend to focus on perturbing the past positions of surrounding agents, which can generate unrealistic scenarios and overlook critical vulnerabilities. This limitation may result in overly optimistic assessments of model performance in real-world conditions. In this work, we demonstrate that perturbing not just past but also future states of adversarial agents can uncover previously undetected weaknesses and thereby provide a more rigorous evaluation of model robustness. Our novel approach incorporates dynamic constraints and preserves tactical behaviors, enabling more effective and realistic adversarial attacks. We introduce new performance measures to assess the realism and impact of these adversarial trajectories. Testing our method on a state-of-the-art prediction model revealed significant increases in prediction errors and collision rates under adversarial conditions. Qualitative analysis further showed that our attacks can expose critical weaknesses, such as the inability of the model to detect potential collisions in what appear to be safe predictions. These results underscore the need for more comprehensive adversarial testing to better evaluate and improve the reliability of trajectory prediction models for autonomous vehicles.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。