arXiv:2606.14238cs.ROcs.AI2026-06

为自动驾驶视觉语言模型构建分场景安全边界,揭示单一阈值不足。

When and How Severely: Scenario-Specific Safety Envelopes for Driving VLAs

论文配图:When and How Severely: Scenario-Specific Safety Envelopes for Driving VLAs
图 1 · 摘自论文原文
  • 通过扰动实验分析不同场景下的失效严重度,发现相同平均误差下严重故障比例差异大。
  • 在15,968组测试中发现,σ≤50的保守阈值掩盖了部分可容忍高噪声的场景(σ=70)。
  • 提出二维安全边界:既需考虑失效何时发生,也需评估失效多严重,适合部署前验证。

自动驾驶视觉-语言-动作(VLA)规划器的安全性认证基于ISO 21448(SOTIF)标准,需明确两个核心问题:规划器在何时开始失效,以及一旦失效会有多严重。我们对一个100亿参数的开源驾驶VLA模型Alpamayo R1,在15,968组(片段,攻击)数据上进行了评估。结果显示存在保守的聚合差距:在平均位移误差(ADE)预算为15%的前提下,聚合安全阈值σ≤50掩盖了大量能承受最高测试网格σ=70的优质场景。对变化解释子集使用高斯混合模型(GMM)分析后,识别出六个离散的严重度等级(BIC最优k=6),表明即使平均误差相同,不同扰动条件下高严重度(C4/C5)失败的比例可能显著不同。将两类分析结合于同一数据集时,发现抗干扰能力最强的场景并非高严重度故障最少的场景——例如,STOP_SIGNAL场景的高严重度故障占比是LANE_KEEPING的约4倍,尽管其允许更大的σ值。因此,针对驾驶VLA的可部署SOTIF ODD规范必须采用二维安全包络,而非单一危险的聚合阈值。

原文摘要 · Abstract (English)

Safety certification of Vision-Language-Action (VLA) driving planners under ISO 21448 (SOTIF) rests on an Operational Design Domain (ODD) specification that answers two complementary questions: when does the planner start to fail, and how severely does it fail once it does? We evaluate Alpamayo R1, a 10B-parameter open-weight driving VLA, on 15,968 (clip, attack) pairs. We find a conservative-aggregate gap: an aggregate safe threshold of $σ\leq 50$ under a 15% average displacement error (ADE) budget masks well-sampled scenarios that tolerate the top of the tested grid ($σ= 70$). A Gaussian Mixture Model (GMM) on the changed-explanation subset identifies six discrete severity bands (BIC-optimal $k{=}6$), so two perturbation conditions with the same mean error can differ materially in their share of high-severity (C4/C5) failures. Joining the two analyses on the same corpus surfaces a finding neither yields in isolation: the scenarios with the loosest noise thresholds are not those with the lowest high-severity rate: STOP_SIGNAL concentrates roughly $4\times$ the C4/C5 share of LANE_KEEPING despite tolerating a larger $σ$. A deployable SOTIF ODD specification for driving VLAs therefore requires a two-dimensional safety envelope, not a single aggregate value per hazard.

自动驾驶安全评估VLASOTIF

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。