arXiv:2601.11781cs.AIcs.CV2026-01

自动驾驶遇异常时自动调用人类干预,实时评估风险并动态响应。

Risk-Aware Human-in-the-Loop Framework with Adaptive Intrusion Response for Autonomous Vehicles

  • 通过三类信号融合生成入侵风险分,触发分级应对策略。
  • 在真实场景中成功降低攻击成功率至11%,安全违规减少97%。
  • 适合高安全性要求的自动驾驶系统,尤其关注对抗攻击防护。

自动驾驶车辆在面对罕见长尾场景或网络物理攻击时需保持安全与高效。本文提出RAIL框架,将运行时异构信号转化为校准的控制调整与聚焦学习。该框架通过加权噪声或门融合曲率执行完整性、碰撞时间接近度与观测一致性三类线索,生成入侵风险评分(IRS)。当风险超过阈值时,采用基于线索特性的防御屏障与学习到的控制权限混合执行动作,同时保留人类干预能力;低风险时则执行默认策略。上下文强化学习机制根据线索向量在线优化防御选择。RAIL结合软演员-评论家算法(SAC)与风险优先重放及双重奖励机制,使接管行为和近失事件驱动学习,而正常驾驶仍被覆盖。在MetaDrive上,测试回报(TR)达360.65,成功率(TSR)为0.85,安全违规(TSV)为0.75,扰动率(DR)仅0.0027,训练期间仅发生29.07次安全违规,优于强化学习、安全强化学习、离线/模仿学习及先前人机共控基线。在控制器局域网(CAN)注入与激光雷达欺骗攻击下,成功率分别提升至0.68和0.80,攻击下的断开率降至0.37和0.03,攻击成功率降至0.34和0.11。在CARLA环境中,实现TR=1609.70,TSR=0.41,仅需8000步训练。

原文摘要 · Abstract (English)

Autonomous vehicles must remain safe and effective when encountering rare long-tailed scenarios or cyber-physical intrusions during driving. We present RAIL, a risk-aware human-in-the-loop framework that turns heterogeneous runtime signals into calibrated control adaptations and focused learning. RAIL fuses three cues (curvature actuation integrity, time-to-collision proximity, and observation-shift consistency) into an Intrusion Risk Score (IRS) via a weighted Noisy-OR. When IRS exceeds a threshold, actions are blended with a cue-specific shield using a learned authority, while human override remains available; when risk is low, the nominal policy executes. A contextual bandit arbitrates among shields based on the cue vector, improving mitigation choices online. RAIL couples Soft Actor-Critic (SAC) with risk-prioritized replay and dual rewards so that takeovers and near misses steer learning while nominal behavior remains covered. On MetaDrive, RAIL achieves a Test Return (TR) of 360.65, a Test Success Rate (TSR) of 0.85, a Test Safety Violation (TSV) of 0.75, and a Disturbance Rate (DR) of 0.0027, while logging only 29.07 training safety violations, outperforming RL, safe RL, offline/imitation learning, and prior HITL baselines. Under Controller Area Network (CAN) injection and LiDAR spoofing attacks, it improves Success Rate (SR) to 0.68 and 0.80, lowers the Disengagement Rate under Attack (DRA) to 0.37 and 0.03, and reduces the Attack Success Rate (ASR) to 0.34 and 0.11. In CARLA, RAIL attains a TR of 1609.70 and TSR of 0.41 with only 8000 steps.

自动驾驶人机协同安全防护风险评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。