Score
Designs and analyzes methods that apply randomized-noise smoothing to multi-step sequence outputs (predicted trajectories) to produce smoothed trajectory predictors. Builds mechanisms and derives certified robustness radii and probabilistic bounds that quantify how input perturbations affect entire predicted trajectories.
Existing pedestrian trajectory prediction models are vulnerable to adversarial perturbations and lack verifiable safety guarantees. This work proposes TrajRS, the first framework to formally define and achieve certifiable robustness for trajectory prediction—covering both the “best prediction” and the entire set of “all possible predictions.” By extending the randomized smoothing framework and explicitly incorporating the temporal and spatial characteristics inherent in trajectory data, TrajRS introduces tailored smoothing and certification mechanisms. Experimental results demonstrate that TrajRS provides effective certified robustness radii for a variety of smoothed trajectory predictors, ensuring reliable predictions even under adversarial perturbations.
This work addresses the vulnerability of trajectory prediction models to minor adversarial perturbations, which can lead to catastrophic prediction failures. The study presents the first systematic evaluation of robustness in this domain and introduces a lightweight, general-purpose defense mechanism based on randomized smoothing. By integrating this approach with diverse base models across multiple benchmark datasets, the proposed method significantly enhances robustness against adversarial attacks while preserving original prediction accuracy on clean inputs. The results demonstrate that the technique offers an effective and practical solution for improving the safety and reliability of trajectory prediction systems without imposing substantial computational overhead.
This work addresses the challenge of mode collapse in randomized multimodal prediction, where conventional randomized smoothing fails to capture the true data distribution, thereby compromising robustness in safety-critical applications. The authors propose a clustered α-smoothing framework that first partitions noisy samples into clusters and then applies α-smoothing locally within each cluster, ultimately aggregating the results into a mixture distribution to preserve multimodal structure. This approach is the first to integrate clustering with local α-smoothing, effectively mitigating mode collapse through mixture-based modeling. The paper also provides a theoretical lower bound on the probability that predictions fall within multimodal regions. Empirical evaluations demonstrate significant improvements: a 27% reduction in Wasserstein distance for autonomous driving trajectory prediction and an 81% decrease in collision rates compared to existing methods in quadrotor control tasks.
To address the lack of robustness in human trajectory prediction models against adversarial perturbations and observational noise, this paper introduces the first provably robust certification framework for trajectory prediction. Methodologically, we design a novel certifiable robustness mechanism tailored to trajectory prediction, overcoming challenges posed by unbounded outputs and multimodality; integrate a differentiable joint denoising module; and unify randomized smoothing with multimodal probabilistic modeling. Evaluated under the ETH/UCY benchmark protocol, our framework achieves state-of-the-art certified robust radii across multiple mainstream baseline models—yielding an average 38% improvement in noise tolerance without sacrificing prediction accuracy. Key contributions include: (1) the first provably robust certification paradigm for trajectory prediction; (2) a theoretically grounded approach that jointly ensures robustness and preserves multimodal characteristics; and (3) a robustness-enhancing architecture that maintains original prediction fidelity.
Existing trajectory prediction methods for autonomous driving inadequately model uncertainty, particularly lacking interpretable decomposition into aleatoric (environmental stochasticity) and epistemic (model uncertainty) components. Method: We propose the first information-theoretic unified framework that quantifies total uncertainty via entropy and mutual information, and decouples aleatoric and epistemic uncertainties through Bayesian approximate inference. The framework is plug-and-play compatible with mainstream predictors, balancing theoretical rigor and engineering practicality. Contribution/Results: Extensive empirical analysis across multiple architectures on nuScenes reveals critical impacts of model architecture on uncertainty estimation bias and planning robustness. Experiments demonstrate significant improvements in high-risk scenario identification, enabling safety-critical decision-making with reliable, uncertainty-aware predictions.
该论文提出一种不确定性感知的轨迹预测方法,通过利用跟踪器提供的可靠性线索,改进了在不完美多目标跟踪下的轨迹预测准确性。
This study addresses the failure of randomized smoothing certification radii caused by feasibility filtering and the decision boundary risks introduced by conditional probability ratios. We propose an analytical framework that decouples geometric and certification analyses. By revealing the geometric deficiencies of conditional substitution, we establish a geometric control theory for convex and non-convex sets, and design a method combining retention-label probabilities with covariance bounds to obtain valid certification radii. Furthermore, this work integrates Rényi divergence bounds with adaptive Gaussian composition to optimize finite-sample certification bounds. Experiments demonstrate that our approach significantly outperforms existing union mass bounds on image classification tasks, successfully validating the effectiveness of non-convex filters while uncovering label-shifting phenomena in previously published filters.
This work investigates the theoretical underpinnings of memorization and overfitting in stochastic interpolation generative models. Focusing on continuous-time stochastic differential equations and their Euler discretization, it provides the first rigorous theoretical definitions of overfitting and underfitting in generative modeling and derives closed-form expressions for the optimal velocity field and score function. The analysis reveals that generated samples can be expressed as training samples perturbed by three controllable error terms, whose bias is jointly determined by the discretization step size and estimation error. Synthetic experiments corroborate the theoretical prediction that generated samples cluster around the training data distribution, highlighting the critical roles of error accumulation and noise modeling in the model’s reconstruction capability.
This work addresses the high computational cost and inflexibility of randomized smoothing (RS), which, despite offering rigorous robustness guarantees, requires a preset number of samples and is ill-suited for real-time or resource-constrained settings. The paper introduces anytime-valid robustness certification—a novel paradigm enabled by a meta-learning-based adaptive framework. A lightweight meta-learner predicts input-specific priors to guide a sequential estimation process that dynamically allocates sampling resources and supports early stopping. This approach preserves statistical validity while drastically reducing sampling complexity—by up to 20× compared to conventional RS—and enables risk-aware, tiered allocation of computation based on user-defined confidence thresholds. The method thus opens a new pathway toward efficient, real-time robustness certification in safety-critical applications.
This work addresses the vulnerability of large language models to traffic manipulation attacks in network intrusion detection by proposing a classifier-agnostic certified defense. The key innovation lies in restricting randomized smoothing to the attacker-controllable feature subspace and jointly optimizing robustness through noise-augmented fine-tuning and subspace alignment. This approach is the first to align the smoothing distribution with the actual threat model, overcoming the critical limitation of standard randomized smoothing—its extremely low certified accuracy on clean-trained models. Evaluated on the CIC-IDS-2018 and HIKARI-2021 datasets, the method achieves certified accuracies of 55%–100% and certified radii exceeding the L∞-equivalent thresholds by 1.8–5×, yielding up to a 72-percentage-point improvement over isotropic baselines.