Evaluating randomized smoothing as a defense against adversarial attacks in trajectory prediction

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Schumann, Julian F., Figueiredo, Eduardo, Mathiesen, Frederik Baymler, Laurenti, Luca, Kober, Jens, Zgonnikov, Arkady
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908879186558976
author Schumann, Julian F.
Figueiredo, Eduardo
Mathiesen, Frederik Baymler
Laurenti, Luca
Kober, Jens
Zgonnikov, Arkady
author_facet Schumann, Julian F.
Figueiredo, Eduardo
Mathiesen, Frederik Baymler
Laurenti, Luca
Kober, Jens
Zgonnikov, Arkady
contents Accurate and robust trajectory prediction is essential for safe and efficient autonomous driving, yet recent work has shown that even state-of-the-art prediction models are highly vulnerable to inputs being mildly perturbed by adversarial attacks. Although model vulnerabilities to such attacks have been studied, work on effective countermeasures remains limited. In this work, we develop and evaluate a new defense mechanism for trajectory prediction models based on randomized smoothing -- an approach previously applied successfully in other domains. We evaluate its ability to improve model robustness through a series of experiments that test different strategies of randomized smoothing. We show that our approach can consistently improve prediction robustness of multiple base trajectory prediction models in various datasets without compromising accuracy in non-adversarial settings. Our results demonstrate that randomized smoothing offers a simple and computationally inexpensive technique for mitigating adversarial attacks in trajectory prediction.
format Preprint
id arxiv_https___arxiv_org_abs_2603_10821
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Evaluating randomized smoothing as a defense against adversarial attacks in trajectory prediction
Schumann, Julian F.
Figueiredo, Eduardo
Mathiesen, Frederik Baymler
Laurenti, Luca
Kober, Jens
Zgonnikov, Arkady
Machine Learning
Accurate and robust trajectory prediction is essential for safe and efficient autonomous driving, yet recent work has shown that even state-of-the-art prediction models are highly vulnerable to inputs being mildly perturbed by adversarial attacks. Although model vulnerabilities to such attacks have been studied, work on effective countermeasures remains limited. In this work, we develop and evaluate a new defense mechanism for trajectory prediction models based on randomized smoothing -- an approach previously applied successfully in other domains. We evaluate its ability to improve model robustness through a series of experiments that test different strategies of randomized smoothing. We show that our approach can consistently improve prediction robustness of multiple base trajectory prediction models in various datasets without compromising accuracy in non-adversarial settings. Our results demonstrate that randomized smoothing offers a simple and computationally inexpensive technique for mitigating adversarial attacks in trajectory prediction.
title Evaluating randomized smoothing as a defense against adversarial attacks in trajectory prediction
topic Machine Learning
url https://arxiv.org/abs/2603.10821