arXiv:2608.04065cs.CRcs.AI2026-08

为智能交通中的大模型设计实时安全防护架构,防止恶意指令渗透。

An Inline Control Architecture for Language Models in Intelligent Transportation Systems

  • 在语言模型输入端部署规则过滤+轻量分类器+可信检索等多层防护
  • 对抗测试中零接受危险输出,两轮攻击下入侵成功率显著下降
  • 适合需要低延迟且高安全性的车路协同系统开发者使用

车载万物互联(V2X)系统越来越多地在路边单元和边缘节点中引入大语言模型(LLMs),用于消息摘要、操作辅助和决策支持等语义任务。尽管这些组件不直接参与安全控制回路,但其提示层仍存在攻击面,传统基于认证与消息完整性的安全机制无法覆盖。本文提出Guarded-V2X,一种面向实时约束的内联语义防护架构,用于保障启用大模型的V2X服务安全。该系统集成规则化入站过滤、轻量级安全分类器、策略约束的结构化生成、仅限可信源的检索以及事后决策裁决,确保下游执行前具备可机器验证的安全边界。通过四阶段实验流程评估:漏洞分析、校准与延迟基准测试、防护有效性验证及对抗压力下的鲁棒性测试。实验基于从路侧单元告警、操作员消息和标注的V2X摘要中提取的对齐模拟数据集进行。结果表明,未加防护和仅依赖提示的基线在多轮对抗测试中仍存残余漏洞,而Guarded-V2X在两轮场景中持续降低入侵接受率,并消除所有观察到的不安全输出,同时未超出V2X语义告警路径的延迟预算。

原文摘要 · Abstract (English)

Vehicle-to-everything (V2X) systems increasingly incorporate large language models (LLMs) for semantic tasks such as message summarization, operator assistance, and decision support at roadside units and edge nodes. Although these components are not part of safety-critical control loops, they introduce prompt-level attack surfaces that are not addressed by traditional V2X security mechanisms focused on authentication and message integrity. This paper presents Guarded-V2X, an inline semantic guardrail architecture for securing LLM-enabled V2X services under real-time constraints. The proposed system integrates rule-based ingress filtering, a lightweight safety classifier, policy-constrained structured generation, trusted-only retrieval, and post-decision adjudication to enforce machine-checkable safety boundaries prior to downstream execution. Guarded-V2X is evaluated using a four-stage experimental pipeline encompassing intrusion vulnerability analysis, calibration and latency benchmarking, guardrail validation, and robustness under adversarial stress. Experiments are conducted on a V2X-aligned simulated dataset derived from RSU advisories, operator messages, and annotated V2X message summaries. Results show that unguarded and prompt-only baselines retain residual vulnerability under multi-turn adversarial trials, while Guarded-V2X consistently reduces intrusion acceptance success rates and eliminates observed unsafe completions in two-turn settings, without exceeding latency budgets for V2X semantic advisory paths.

智能交通大模型安全语义防护V2X

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。