提出可验证行人轨迹预测的鲁棒性保障方法
TrajRS: Towards Certified Robustness in Pedestrian Trajectory Prediction

- 基于随机平滑扩展出TrajRS框架,实现轨迹预测的可认证鲁棒性
- 在多种攻击下仍能保证预测轨迹的误差在安全范围内
- 适合对安全性要求高的自动驾驶系统开发人员
轨迹预测模型的鲁棒性对构建安全的自动驾驶系统至关重要。针对轨迹预测的对抗攻击会显著降低预测准确性,导致危险驾驶行为。尽管已有启发式防御策略提升鲁棒性,但对更复杂的定向攻击仍易失效。因此亟需为轨迹预测模型建立可验证的安全保障。本文将传统随机平滑框架拓展为TrajRS,为平滑后的轨迹预测器提供可认证的鲁棒半径。我们明确了轨迹预测鲁棒性的形式化定义,并针对性设计了适用于“最优预测鲁棒性”和“所有可能预测鲁棒性”的实用方案。大量实验表明,TrajRS能有效为本研究中所有平滑后的行人轨迹预测器实现鲁棒性认证。
原文摘要 · Abstract (English)
The robustness of trajectory prediction models is crucial for developing safe autonomous driving systems. Adversarial attacks on trajectory prediction can significantly impair the accuracy of predicted trajectories, leading to hazardous driving behaviors. While heuristic defense strategies have been implemented to enhance the robustness of trajectory prediction models, these measures often fail against more sophisticated, targeted adversarial attacks. Hence, there is a pressing need to establish verifiable safety assurances for trajectory prediction models. In this paper, we extend the traditional Randomized Smoothing framework to "TrajRS", which provides a certified robust radius for smoothed trajectory predictors. We clarify and expand the formal definitions of robustness in trajectory prediction and tailor the practical TrajRS scheme specifically to "robustness for the optimal prediction" and "robustness for all possible predictions". An extensive set of experiments demonstrates that TrajRS effectively achieves robustness certification for all smoothed pedestrian trajectory predictors in this work.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。