In autonomous driving, behavior prediction is fundamental for safe motion planning, hence the security and robustness of prediction models against adversarial attacks are of paramount importance. We propose a novel adversarial backdoor attack against trajectory prediction models as a means of studying their potential vulnerabilities. Our attack affects the victim at training time via naturalistic, hence stealthy, poisoned samples crafted using a novel two-step approach. First, the triggers are crafted by perturbing the trajectory of attacking vehicle and then disguised by transforming the scene using a bi-level optimization technique. The proposed attack does not depend on a particular model architecture and operates in a black-box manner, thus can be effective without any knowledge of the victim model. We conduct extensive empirical studies using state-of-the-art prediction models on two benchmark datasets using metrics customized for trajectory prediction. We show that the proposed attack is highly effective, as it can significantly hinder the performance of prediction models, unnoticeable by the victims, and efficient as it forces the victim to generate malicious behavior even under constrained conditions. Via ablative studies, we analyze the impact of different attack design choices followed by an evaluation of existing defence mechanisms against the proposed attack.
翻译:在自动驾驶中,行为预测是实现安全运动规划的基础,因此预测模型针对对抗性攻击的安全性与鲁棒性至关重要。我们提出一种新型的对抗性后门攻击方法,专门针对轨迹预测模型,旨在研究其潜在脆弱性。该攻击通过一种新颖的两阶段方法在训练阶段使用自然、隐蔽的投毒样本影响受害者模型。首先,通过扰动攻击车辆的轨迹生成触发器,随后利用双层优化技术变换场景对触发器进行伪装。所提出的攻击不依赖特定模型架构,且以黑盒方式运行,因此无需了解受害者模型即可生效。我们采用两个基准数据集,利用专为轨迹预测定制的评价指标,基于最先进的预测模型开展了广泛实证研究。结果表明:该攻击具有高效性,能显著削弱预测模型性能且不被受害者察觉;同时具备有效性,即使在受限条件下也能迫使受害者生成恶意行为。通过消融研究,我们分析了不同攻击设计选择的影响,并评估了现有防御机制对抗该攻击的效果。