用随机平滑提升轨迹预测模型抗对抗攻击能力。
Evaluating randomized smoothing as a defense against adversarial attacks in trajectory prediction
- 基于随机平滑构建防御机制,增强轨迹预测鲁棒性。
- 在多个数据集上显著提升模型抗攻击能力,且不影响正常精度。
- 方法简单高效,适合实际自动驾驶系统部署。
准确且鲁棒的轨迹预测对安全高效的自动驾驶至关重要,但现有先进预测模型极易受到轻微扰动的对抗攻击影响。尽管模型漏洞已被研究,有效的防御手段仍有限。本文提出并评估了一种基于随机平滑的新防御机制,该方法此前在其他领域表现成功。通过一系列实验测试不同随机平滑策略,结果表明,该方法能一致提升多种基础轨迹预测模型在多个数据集上的鲁棒性,且在非对抗场景下不损失准确性。研究表明,随机平滑是一种简单、计算成本低的对抗攻击缓解技术。
原文摘要 · Abstract (English)
Accurate and robust trajectory prediction is essential for safe and efficient autonomous driving, yet recent work has shown that even state-of-the-art prediction models are highly vulnerable to inputs being mildly perturbed by adversarial attacks. Although model vulnerabilities to such attacks have been studied, work on effective countermeasures remains limited. In this work, we develop and evaluate a new defense mechanism for trajectory prediction models based on randomized smoothing -- an approach previously applied successfully in other domains. We evaluate its ability to improve model robustness through a series of experiments that test different strategies of randomized smoothing. We show that our approach can consistently improve prediction robustness of multiple base trajectory prediction models in various datasets without compromising accuracy in non-adversarial settings. Our results demonstrate that randomized smoothing offers a simple and computationally inexpensive technique for mitigating adversarial attacks in trajectory prediction.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。