Effective Adversarial Attack Approach to Assess the Vulnerability of Autonomous Vehicle Trajectory Prediction Models

Xinyu Wang, Chengchuan An, Jingxin Xia, Zhenbo Lu · IEEE Transactions on Intelligent Transportation Systems · 2025

Trajectory prediction is crucial for autonomous vehicle (AV) trajectory planning. The deep learning based trajectory prediction models are easily manipulated by cyber attack such as adversarial attack or confidential information tampering. Current research in adversarial attack typically relies on vehicle physical motion boundaries to conduct linear search, which limits the diversity of samples and covers up the vulnerabilities of model. Moreover, the reckless driving behaviors underlying the generated trajectory samples can be easily detected and smoothed. In this study, a dual constraint optimization framework for adversarial attack is developed. The proposed framework integrates hard constraint of physical boundary with soft constraint of driving risk map to simulate the actual vehicles interaction. Subsequently, Stochastic Gradient Descent (SGD) incorporates Hard-Soft constraint to increase the search space of local optimal solution. The high-precision vehicle trajectory data (sampling interval 0.1s) from the Next Generation Simulation (NGSIM) dataset supports microscopic traffic flow analysis and is used for validating our methods. The vulnerability of the prediction model is revealed from number of attack frames and input features. Results show that our proposed method increases the Average Displacement Errors (ADE) by 42.04% and Final Displacement Error (FDE) by 24.19% compared to the state-of-the-art method.

Read the paper · More papers on PaperTik