arXiv:2603.15221cs.LGcs.AI2026-03被引 2

让自动驾驶在罕见高危场景下更安全,通过对抗训练动态优化防御策略。

ADV-0: Closed-Loop Min-Max Adversarial Training for Long-Tail Robustness in Autonomous Driving

  • 将驾驶策略与对抗生成视为零和博弈,闭环优化对抗过程。
  • 在真实场景测试中显著暴露多种高危失效模式,提升模型泛化能力。
  • 适合研究自动驾驶鲁棒性或对抗训练的从业者参考。

部署自动驾驶系统需具备对罕见但高危的长尾场景的鲁棒性。尽管对抗训练具有潜力,但现有方法通常将场景生成与策略优化解耦,并依赖启发式代理,导致目标错配,无法捕捉随策略演进而变化的失效模式。本文提出ADV-0,一种闭环最小-最大优化框架,将驾驶策略(防御者)与对抗智能体(攻击者)的交互建模为零和马尔可夫博弈。通过直接对齐攻击者的效用函数与防御者的目标,揭示了最优对抗智能体分布。为使该框架可计算,将动态对抗演化建模为迭代偏好学习,高效逼近最优解,提供算法无关的解决方案。理论上,ADV-0收敛至纳什均衡,并最大化真实世界性能的认证下界。实验表明,其能有效暴露多样化的安全关键失效,并显著增强学习策略与运动规划器对未见长尾风险的泛化能力。

原文摘要 · Abstract (English)

Deploying autonomous driving systems requires robustness against long-tail scenarios that are rare but safety-critical. While adversarial training offers a promising solution, existing methods typically decouple scenario generation from policy optimization and rely on heuristic surrogates. This leads to objective misalignment and fails to capture the shifting failure modes of evolving policies. This paper presents ADV-0, a closed-loop min-max optimization framework that treats the interaction between driving policy (defender) and adversarial agent (attacker) as a zero-sum Markov game. By aligning the attacker's utility directly with the defender's objective, we reveal the optimal adversary distribution. To make this tractable, we cast dynamic adversary evolution as iterative preference learning, efficiently approximating this optimum and offering an algorithm-agnostic solution to the game. Theoretically, ADV-0 converges to a Nash Equilibrium and maximizes a certified lower bound on real-world performance. Experiments indicate that it effectively exposes diverse safety-critical failures and greatly enhances the generalizability of both learned policies and motion planners against unseen long-tail risks.

自动驾驶对抗训练长尾鲁棒性强化学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。