提出黑盒攻击方法DTP-Attack,可隐蔽干扰自动驾驶轨迹预测
DTP-Attack: A decision-based black-box adversarial attack on trajectory prediction
- 仅依赖模型输出决策,无需梯度或内部结构
- 扰动小于0.45米时,攻击成功率41%-81%
- 适用于意图误导和精度降低,适合安全测试场景
轨迹预测系统对自动驾驶安全至关重要,但易受对抗攻击导致严重误判。现有方法需白盒访问且依赖刚性物理约束,难以实际应用。本文提出DTP-Attack,一种面向轨迹预测系统的决策型黑盒攻击框架。该方法仅基于二元决策输出,无需模型内部信息或梯度,具备现实可行性。DTP-Attack采用新型边界行走算法,在无固定约束条件下导航,通过保持轨迹邻近性自然维持真实性。不同于以往方法,本方案支持意图误分类与预测精度下降双重攻击。在nuScenes与Apolloscape数据集上,对Trajectron++和Grip++等先进模型的评估表明:对于意图误导攻击,扰动低于0.45米时成功率可达41%–81%;对于精度降低攻击,预测误差提升1.9–4.2倍。该方法显著优于现有黑盒攻击,且在多种场景下保持高可控性与可靠性。结果揭示当前轨迹预测系统存在根本性漏洞,凸显安全驾驶应用中亟需强化防御机制。
原文摘要 · Abstract (English)
Trajectory prediction systems are critical for autonomous vehicle safety, yet remain vulnerable to adversarial attacks that can cause catastrophic traffic behavior misinterpretations. Existing attack methods require white-box access with gradient information and rely on rigid physical constraints, limiting real-world applicability. We propose DTP-Attack, a decision-based black-box adversarial attack framework tailored for trajectory prediction systems. Our method operates exclusively on binary decision outputs without requiring model internals or gradients, making it practical for real-world scenarios. DTP-Attack employs a novel boundary walking algorithm that navigates adversarial regions without fixed constraints, naturally maintaining trajectory realism through proximity preservation. Unlike existing approaches, our method supports both intention misclassification attacks and prediction accuracy degradation. Extensive evaluation on nuScenes and Apolloscape datasets across state-of-the-art models including Trajectron++ and Grip++ demonstrates superior performance. DTP-Attack achieves 41 - 81% attack success rates for intention misclassification attacks that manipulate perceived driving maneuvers with perturbations below 0.45 m, and increases prediction errors by 1.9 - 4.2 for accuracy degradation. Our method consistently outperforms existing black-box approaches while maintaining high controllability and reliability across diverse scenarios. These results reveal fundamental vulnerabilities in current trajectory prediction systems, highlighting urgent needs for robust defenses in safety-critical autonomous driving applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。