arXiv:2511.13753cs.LGcs.AI2025-11

研究大模型在车辆轨迹预测中的安全漏洞,发现微小干扰就能让预测失效。

Robustness of LLM-enabled vehicle trajectory prediction under data security threats

  • 用单特征差分进化攻击,黑盒下扰动周围车辆的运动参数
  • 高D数据集上微小扰动使预测准确率下降超40%
  • 揭示精度与鲁棒性矛盾,提醒自动驾驶系统需强化防御

将大语言模型(LLMs)融入自动驾驶系统,可通过将复杂驾驶场景转化为语言可理解表示,实现推理与决策。近期研究显示,微调后的LLM能基于周边车辆数据准确预测车辆轨迹与变道意图。然而,这类基于LLM的预测模型在安全关键系统中的鲁棒性尚未被充分探索,而对LLM可信度的担忧日益加剧。本研究通过系统性漏洞分析,揭示了LLM驱动车辆轨迹预测的脆弱性。我们提出一种单特征差分进化攻击,在黑盒环境下仅扰动输入提示中一个运动学特征。在highD数据集上的实验表明,即使微小且物理上合理的扰动,也能显著破坏模型输出,凸显其易受对抗攻击的影响。进一步分析揭示了精度与鲁棒性之间的权衡关系,探究了失败机制,并初步探索了缓解方案。研究成果首次揭示了车辆交互场景中基于LLM的自动驾驶模型的对抗脆弱性,强调未来智能交通系统应以鲁棒性为导向进行设计。

原文摘要 · Abstract (English)

The integration of large language models (LLMs) into automated driving systems has opened new possibilities for reasoning and decision-making by transforming complex driving contexts into language-understandable representations. Recent studies demonstrate that fine-tuned LLMs can accurately predict vehicle trajectories and lane-change intentions by gathering and transforming data from surrounding vehicles. However, the robustness of such LLM-based prediction models for safety-critical driving systems remains unexplored, despite the increasing concerns about the trustworthiness of LLMs. This study addresses this gap by conducting a systematic vulnerability analysis of LLM-enabled vehicle trajectory prediction. We propose a one-feature differential evolution attack that perturbs a single kinematic feature of surrounding vehicles within the LLM's input prompts under a black-box setting. Experiments on the highD dataset reveal that even minor, physically plausible perturbations can significantly disrupt model outputs, underscoring the susceptibility of LLM-based predictors to adversarial manipulation. Further analyses reveal a trade-off between accuracy and robustness, examine the failure mechanism, and explore potential mitigation solutions. The findings provide the very first insights into adversarial vulnerabilities of LLM-driven automated vehicle models in the context of vehicular interactions and highlight the need for robustness-oriented design in future LLM-based intelligent transportation systems.

大模型安全自动驾驶对抗攻击轨迹预测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。