arXiv:2605.03491cs.AI2026-05中稿 · IEEE ITSC 2026被引 1

用真实路口数据评估自动驾驶模型抗干扰能力,发现结构设计比精度更重要

Real-Time Evaluation of Autonomous Systems under Adversarial Attacks

论文配图:Real-Time Evaluation of Autonomous Systems under Adversarial Attacks
图 1 · 摘自论文原文
  • 基于真实驾驶数据训练三种轨迹模型,对比其对抗攻击下的表现
  • 同一精度下(ADE<0.08),攻击可导致最大8米的最终误差
  • 首次构建真实场景下离线轨迹学习的鲁棒性评估框架,适合安全研究者

当前自动驾驶策略在对抗条件下的评估多依赖仿真,但纯虚拟测试无法捕捉真实数据中的结构不一致、监督约束和状态表征效应,这些因素直接影响策略鲁棒性。本文提出一种基于真实路口驾驶数据的离线轨迹学习与对抗鲁棒性评估框架。在受控数据协议下,训练并比较三种轨迹学习范式:基于MLP的行为克隆(BC)、基于Transformer的对象标记式BC,以及在生成对抗模仿学习(GAIL)框架下的逆强化学习(IRL)。采用平均位移误差(ADE)和最终位移误差(FDE)进行评估。通过梯度类对抗扰动在多个路口场景中测试推理时鲁棒性,构建结构化评估矩阵。结果显示,状态结构设计与架构归纳偏置对对抗稳定性有决定性影响,即使名义预测精度相近(ADE < 0.08),鲁棒性表现差异显著。推理时投影梯度下降(PGD)攻击可引发最高约8米的最终位移误差。该框架为真实世界自动驾驶中离线轨迹学习与对抗鲁棒性的研究提供了可扩展基准。

原文摘要 · Abstract (English)

Most evaluations of autonomous driving policies under adversarial conditions are conducted in simulation, due to cost efficiency and the absence of physical risk. However, purely virtual testing fails to capture structural inconsistencies, supervision constraints, and state-representation effects that arise in real-world data and fundamentally shape policy robustness. This work presents an offline trajectory-learning and adversarial robustness evaluation framework grounded in real-world intersection driving data. Within a controlled data contract, we train and compare three trajectory-learning paradigms: Multi-Layer Perceptron (MLP)-based Behavior Cloning (BC), Transformer-based object-tokenized BC, and inverse reinforcement learning (IRL) formulated within a Generative Adversarial Imitation Learning (GAIL) framework. Models are evaluated using Average Displacement Error (ADE) and Final Displacement Error (FDE). Inference-time robustness is assessed by subjecting trained policies to gradient-based adversarial perturbations across multiple intersection scenarios, yielding a structured robustness evaluation matrix. Results show that state-structure design and architectural inductive biases critically influence adversarial stability, leading to markedly different robustness profiles despite comparable nominal prediction accuracy (ADE < 0.08). Inference-time Projected Gradient Descent (PGD) attacks induce final displacement errors of up to approximately 8 meters. The proposed framework establishes a scalable benchmark for studying offline trajectory learning and adversarial robustness in real-world autonomous driving settings.

自动驾驶对抗攻击轨迹学习鲁棒性评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。