Random smoothing-based track prediction algorithm verification method

By extending the random smoothing framework and combining the Monte Carlo algorithm and Neiman-Pearson lemma, the smoothing function models go and gA are constructed, and the problem of insufficient accuracy of the trajectory prediction model under extreme adversarial attacks is solved, and the accurate robustness evaluation and flexible applicability of the trajectory prediction algorithm are achieved.

CN120561535APending Publication Date: 2025-08-29重庆中科汽车软件创新中心
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510700883.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

The existing trajectory prediction model cannot accurately capture all motion patterns under extreme adversarial attacks. The traditional trajectory prediction algorithm based on random smoothing is insufficient in accuracy and it is difficult to provide accurate robustness evaluation.

Method used

By extending the traditional stochastic smoothing framework, combining Monte Carlo algorithm and Neiman-Pearson lemma, two smoothing function models go and gA are constructed to realize verification and robustness evaluation of trajectory prediction algorithms, and provide accurate robust radius evaluation.

Benefits of technology

Improves the robust verification accuracy of the trajectory prediction model, ensures that all motion patterns can be accurately captured under extreme adversarial attacks, provides flexible and applicable smoothing methods, and enhances the robustness evaluation capabilities of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120561535A_ABST
    Figure CN120561535A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of trajectory prediction, and discloses a stochastic smoothing-based trajectory prediction algorithm verification method, which comprises the following steps of: 1, establishing a two-dimensional Euclidean space according to a target trajectory prediction model, and correspondingly analyzing space coordinates, trajectories and discrete probability distribution of the target trajectory prediction model; 2, expanding trajectory prediction according to the target trajectory prediction model, and generating a robustness definition of optimal prediction and robustness definitions of all possible predictions; step 3, two types of smooth function models go and gA are constructed through TrajRS according to the target trajectory prediction model; and step 4, according to Gaussian distribution of different mean values of the target trajectory prediction model, introducing a Neman-Pearson's lemma, deducing theorems corresponding to the smooth function models go and gA, and independently evaluating the robustness of the smooth function models go and gA by using a Monte Carlo algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of trajectory prediction, and in particular to a trajectory prediction algorithm verification method based on random smoothing. Background Art

[0002] Deep neural networks (DNNs) are a core component of deep learning. By simulating the human brain's neuronal connections and information processing, they are able to learn and recognize complex data patterns. The basic structure of a DNN consists of an input layer, one or more hidden layers, and an output layer. Each layer consists of multiple neurons connected by weights, which process and transmit information. DNNs have demonstrated outstanding performance in numerous supervised learning tasks, but they also have vulnerabilities. They are susceptible to adversarial perturbations that are imperceptible to the human eye. This vulnerability has spurred extensive research aimed at enhancing DNNs' adversarial robustness. Growing interest in adversarial attacks and defenses in trajectory prediction has further fueled research on the robustness radius of smooth trajectory prediction models. To counter adversarial attacks, current trajectory prediction models employ empirical defense methods to enhance their robustness. Only through a rigorous verification process can such robustness algorithms be guaranteed to resist any attack within a specified perturbation radius, effectively establishing model security. Significant progress has been made in developing techniques for computing verified robustness radii for DNNs, such as robustness verification for symbol substitution via interval-bounded propagation, Reluplex, and TrajPAC. Robustness verification for symbol substitution via interval-bounded propagation is a new approach to authenticated robustness that, by introducing interval-bounded propagation into a model, can, to a certain extent, protect the model from symbol substitution attacks.

[0003] Robustness verification method for symbol replacement via interval bound propagation:

[0004] Interval boundary propagation methods typically assume a linear model structure or linear approximation, whereas trajectory prediction often involves nonlinear models. Therefore, these methods may not accurately capture the complexity of trajectory prediction models. Trajectory prediction involves various uncertainties and noise, which the interval boundary propagation method may not handle well, thus affecting the accuracy of the verification results.

[0005] Reluplex robustness verification method:

[0006] Efficient SMT solvers can effectively verify the correctness of deep neural networks, especially for models using the Relu activation function. Similar to the robustness verification of symbol replacement via interval-bound propagation, the Reluplex algorithm is designed to be more suitable for linear models or models with a small amount of nonlinear structure. Trajectory prediction algorithms typically need to consider the impact of dynamic environments and time series data, but Reluplex focuses primarily on static conditions in the input space and has difficulty capturing the impact of time series information and dynamic changes on trajectory prediction results. Because Reluplex may encounter local optimal solutions or incomplete search spaces when searching in high-dimensional space, there is a certain degree of uncertainty in the verification results, which may affect the accuracy and reliability of the verification.

[0007] TrajPAC robustness verification method:

[0008] By sampling and learning a replacement model, the robustness of the replacement model is verified, providing a probabilistic robustness guarantee for the original model.

[0009] Currently, traditional random smoothing-based trajectory prediction algorithm verification methods typically use the TrajPAC robustness verification method. In actual use, the TrajPAC robustness verification method can only determine the lower bound of the robust radius of the evaluation model, and the verification accuracy is lacking. When dealing with extreme adversarial attacks, it may not be able to accurately capture all motion patterns.

[0010] The present invention develops an innovative random smoothing framework TrajRS by extending the traditional random smoothing framework and combining it with the concept of Monte Carlo algorithm, thereby realizing the verification of the smooth trajectory prediction algorithm and providing a verified robust radius as a quantifiable assessment of the model robustness. Summary of the Invention

[0011] (1) Technical problems solved

[0012] In response to the shortcomings of the existing technology, the present invention provides a trajectory prediction algorithm verification method based on random smoothing, which has the advantages of flexible applicability of random smoothing verification and more accurate prediction authentication robust radius. It solves the problem that the traditional trajectory prediction algorithm verification method based on random smoothing lacks accuracy and cannot accurately capture all motion patterns under extreme adversarial attacks.

[0013] (2) Technical solution

[0014] To achieve the above object, the present invention provides the following technical solution: a trajectory prediction algorithm verification method based on random smoothing, comprising the following steps:

[0015] Step 1: Establish a two-dimensional Euclidean space based on the target trajectory prediction model, and analyze the spatial coordinates, trajectory, and discrete probability distribution of the target trajectory prediction model accordingly;

[0016] Step 2: Expand the trajectory prediction based on the target trajectory prediction model and generate the robustness definition of the optimal prediction and the robustness definition of all possible predictions;

[0017] Step 3: Construct two types of smooth function models g through TrajRS according to the target trajectory prediction model o and g A ;

[0018] Step 4: Introduce the Neyman-Pearson lemma based on the Gaussian distribution of different means of the target trajectory prediction model and derive the smoothing function model g o and g A The corresponding theorem uses the Monte Carlo algorithm to independently evaluate the smooth function model g o and g A Robust.

[0019] Preferably, the two-dimensional Euclidean space is marked as The spatial coordinates of the target trajectory prediction model are marked as x, the trajectories of the target trajectory prediction model are marked as X and Y, and the vectorization of multiple trajectory matrices of the target trajectory prediction model is marked as , the discrete probability of the target trajectory prediction model is marked as

[0020] Preferably, the two-dimensional Euclidean space middle, is the spatial coordinate of the agent at timestamp t, where Indicates the horizontal position, Indicates the vertical position, timestamp T=T p +T f , T p Indicates the past timestamp, T f Represents a future timestamp, a matrix represents the vectorization of the past trajectory of the i-th agent, Indicates the i-th agent at timestamp (-T p +1), Indicates T p The Cartesian product of the two-dimensional space within a time period, represents the trajectory of the agent to be predicted, represents the future trajectory of vectorized prediction, X1,...,X N is the past trajectory of N adjacent agents, Indicates that the target prediction model is trained by trajectory prediction, and the , argmin represents the parameter value of the training function, so that the loss function Reaching the minimum value, Vectorization of the representation matrix, target trajectory prediction model Output Borel represents measurable space If the discrete probability distribution on judge yes One of multiple predicted trajectories.

[0021] Preferably, the target trajectory prediction model uses the L2 norm to describe the robustness region, where: For a given input trajectory, if any spatial coordinate x of the trajectory (t) All in x (t) Entering a closed L2 norm sphere with radius r>0 and being disturbed, define for The set of all perturbation trajectories derived, represents the trajectory before the disturbance, and X represents the trajectory after the disturbance.

[0022] Preferably, the robustness of the optimal prediction of the target trajectory prediction model is defined as follows: given a set of past trajectories of the target agent and its N neighboring agents, represents the true future trajectory of the target agent, f represents the specified target trajectory prediction model, D represents the evaluation index, s represents the predefined safety threshold, if any , the optimal predicted trajectory Satisfy D(Y o ,Y0)≤s, the target trajectory prediction model f is defined as is robust to perturbation radius r>0, where Represents past trajectory The trajectory set after perturbation, argmin Y∈f(X) D(Y,Y0) represents the optimal prediction of the model.

[0023] Preferably, the robustness of all trajectory predictions of the target trajectory prediction model is defined as follows: given a set of past trajectories of the target agent and its N neighboring agents, Y0 represents the true future trajectory of the target agent. And any When D(Y,Y0)≤s, the target trajectory prediction model f is It is robust to disturbance radius r>0.

[0024] Preferably, the TrajRS adopts a random smoothing method, given the input X and the basis function f, to construct a new smooth function g through random smoothing, and correspondingly constructs two types of smooth function models g o and g A , where when Gaussian noise is added to X, the smoothing function g returns the optimal prediction result of the basis function f, and the smoothing function g of the target trajectory prediction model has verifiable robustness to X;

[0025] The robustness definition of the optimal prediction of the target trajectory prediction model, given the trajectory , g o Returns a binary number, which is calculated as follows:

[0026]

[0027] In the formula, Represents a smooth function defined for the robustness of the optimal prediction of the target trajectory prediction model. The number 1 indicates that when On When Gaussian smooth noise is used, the BoN prediction Y of the target trajectory prediction model f is o The probability of falling within the safe distance of the ground truth trajectory is greater than 0.5, and the number 0 means that when On When Gaussian smooth noise is used, the BoN prediction Y of the target trajectory prediction model f is o The probability of falling within a safe distance of the ground truth trajectory is less than or equal to 0.5, Represents the discrete probability of the target trajectory prediction model;

[0028] The robustness definition of all trajectory predictions for the target trajectory prediction model is given by , g A Returns a binary number, which is calculated as follows:

[0029]

[0030] In the formula, Represents a smooth function defined for the robustness of all trajectory predictions of the target trajectory prediction model. The number 1 indicates that when Exposure When Gaussian smooth noise is used, the predictions of the target trajectory prediction model f all fall within the safe distance of the ground truth trajectory. The number 0 indicates that when Exposure When Gaussian smoothed noise is used, the prediction of the target trajectory prediction model f does not fall within the safe distance of the ground truth trajectory. Represents the discrete probability of the target trajectory prediction model;

[0031] The smoothing model is g o and g A At radius l2 and The X inside is robust, where φ -1 is the inverse of the standard Gaussian CDF, and σ represents the standard deviation.

[0032] Preferably, the Neyman-Pearson lemma is and make is any deterministic function, if exist but like exist but in, Indicates that X has a mean of x and a covariance matrix of σ 2 The multivariate normal distribution of I, Indicates that Y has a mean of x+δ and a covariance matrix of σ 2 Multivariate normal distribution of I, δ T z represents linear transformation, and β represents the change threshold;

[0033] For simplicity, the random variables are expressed as follows:

[0034]

[0035] In order to prove that g o To ensure the robustness of , it is necessary to prove that it is still robust after being disturbed by δ in the closed L2 norm ball;

[0036]

[0037] like satisfy Then we get:

[0038]

[0039] Let the half space be defined as follows:

[0040]

[0041]

[0042] Algebraic operations show that and In summary, and

[0043] By Lemma and h(K)=1[Y o ∈f(K), D(Y o ,Y0)≤s] and h(K′)=1[Y o ∈f(K′), D(Y o ,Y0)>s], K and K′ represent X and Y in the lemma and we conclude that:

[0044]

[0045]

[0046] Then calculated:

[0047]

[0048] Finally, algebraic reasoning shows that And ||δ||<σφ -1 ( p ), we get

[0049] In order to prove that g A To ensure robustness, use replace correspond and

[0050] Preferably, the derivation smooth function model g o The corresponding theorem is as follows:

[0051] represents the target trajectory prediction model, let g o Defined as the equation:

[0052]

[0053] like satisfy For all , all have ||δ||2<R o , where R o =σφ -1 ( p ), δ represents the perturbation in the L2 norm ball, that is,

[0054] The derived smooth function model g A The corresponding theorem is as follows:

[0055] represents the target trajectory prediction model, let g A Defined as the equation:

[0056]

[0057] like satisfy For all , all have ||δ||2<R A , where R A =σφ -1 ( p ).

[0058] Preferably, in step 4, the smoothing function model g o and g A The evaluation method is as follows:

[0059] Multiple predictions are performed for the target trajectory prediction model, and the safe prediction data is recorded. That is, the distance from the actual situation is less than the safety threshold s. First, the corresponding lower limit of the probability of safe prediction is calculated. If the calculated lower limit exceeds the safety requirement, it is considered that all trajectory predictions made by the model have a safe probability guarantee.

[0060] Compared with the prior art, the present invention provides a trajectory prediction algorithm verification method based on random smoothing, which has the following beneficial effects:

[0061] 1. This paper establishes a two-dimensional Euclidean space through the target trajectory prediction model, and correspondingly analyzes the spatial coordinates, trajectory and discrete probability distribution of the target trajectory prediction model. According to the target trajectory prediction model, the trajectory prediction is expanded and the robustness definition of the optimal prediction and the robustness definition of all trajectory predictions are generated. The framework combines the concept of Monte Carlo algorithm to develop an innovative random smoothing framework TrajRS. TrajRS constructs two types of smoothing function models g o and g A , thereby realizing the verification of the smooth trajectory prediction algorithm and providing a verified robust radius as a quantifiable assessment of the model robustness. Due to the inherent black-box nature of random smoothing, TrajRS has developed a smoothing method applicable to any trajectory prediction model, thereby providing accurate robustness guarantees. Random smoothing verification is flexible and highly applicable.

[0062] 2. The present invention introduces the Neyman-Pearson lemma based on the Gaussian distribution of different means of the target trajectory prediction model and derives the smoothing function model g o and g A The corresponding theorem uses the Monte Carlo algorithm to independently evaluate the smooth function model g o and g A With robustness, TrajRS not only helps the model enhance robustness improvements in terms of the best prediction, but also provides a certified robust radius applicable to all possible predictions, and the predicted certified robust radius is more accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a step diagram of the method of the present invention;

[0064] Figure 2 The prediction robustness of the two smooth function models;

[0065] Figure 3 It is an extension of traditional random smoothing in TrajRS;

[0066] Figure 4 g O (X) and g A (X) Corresponding algorithm flow chart;

[0067] Figure 5 is the certified security rate obtained by the smoothed MID model on the ETH / UCY dataset when s = 2 and s = 0.5;

[0068] Figure 6 The certified security rates for Trajectron++, MemoNet, and AgentFormer smoothing on the ETH / UCY dataset, and for MID and MemoNet smoothing on the SDD dataset;

[0069] Figure 7 is the certified robust radius of various smoothing models under the “robustness to all possible forecasts” criterion on ETH / UCY;

[0070] Figure 8 is the certified robust radius of the MID under the “robustness to all possible predictions” criterion on the SDD. DETAILED DESCRIPTION

[0071] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0072] See also Figure 1-8 ,The trajectory prediction algorithm verification method based on random smoothing, includes the following steps:

[0073] Step 1: Establish a two-dimensional Euclidean space based on the target trajectory prediction model, and analyze the spatial coordinates, trajectory, and discrete probability distribution of the target trajectory prediction model accordingly;

[0074] The two-dimensional Euclidean space is marked as The spatial coordinates of the target trajectory prediction model are marked as x, the trajectories of the target trajectory prediction model are marked as X and Y, and the vectorization of multiple trajectory matrices of the target trajectory prediction model is marked as , the discrete probability of the target trajectory prediction model is marked as dimensional Euclidean space middle, is the spatial coordinate of the agent at timestamp t, where Indicates the horizontal position, Indicates the vertical position, timestamp T=T p +T f , T p Indicates the past timestamp, T f Represents a future timestamp, a matrix represents the vectorization of the past trajectory of the i-th agent, Indicates the i-th agent at timestamp (-T p +1), Indicates T p The Cartesian product of the two-dimensional space within a time period, represents the trajectory of the agent to be predicted, represents the future trajectory of vectorized prediction, X1,...,X N is the past trajectory of N adjacent agents, Indicates that the target prediction model is trained by trajectory prediction, and the , argmin represents the parameter value of the training function, so that the loss function Reaching the minimum value, Representation matrix vectorization, current trajectory prediction models have combined random prediction techniques to explain the inherent multimodality of future motion. Therefore, these models produce probabilistic rather than deterministic outputs. Target trajectory prediction model Output Borel represents measurable space If the discrete probability distribution on judge yes One of multiple predicted trajectories;

[0075] Step 2: Since the interpretation and emphasis of robustness in trajectory prediction are very different from its classical understanding, it is necessary to first identify and expand the formal definition of trajectory prediction robustness, expand trajectory prediction based on the target trajectory prediction model, and generate the robustness definition of the optimal prediction and the robustness definition of all possible predictions;

[0076] according to Figure 2,The robustness of the best prediction (top) focuses on the robustness of the N best predicted trajectories, which also applies to the most likely trajectory. The robustness of all possible predictions (bottom) describes the robustness of the entire output distribution. The safe region represents the area where the distance between the predicted trajectory and the ground truth does not exceed a safety threshold s;

[0077] The target trajectory prediction model uses the L2 norm to describe the robustness region, where For a given input trajectory, if any spatial coordinate x of the trajectory ( t) are all in x ( t) enters a closed L2 norm sphere with radius r>0 and is disturbed, and is defined as for The set of all perturbation trajectories derived, represents the trajectory before the disturbance, and X represents the trajectory after the disturbance;

[0078] The robustness of the optimal prediction of the target trajectory prediction model is defined as follows: given a set of past trajectories of the target agent and its N neighboring agents, represents the true future trajectory of the target agent, f represents the specified target trajectory prediction model, D represents the evaluation index, s represents the predefined safety threshold, if any , the optimal predicted trajectory Satisfy D(Y o ,Y0)≤s, the target trajectory prediction model f is defined as is robust to perturbation radius r>0, where Represents past trajectory The trajectory set after perturbation, argmin Y∈f(X) D(Y,Y0) represents the optimal prediction of the model;

[0079] The robustness of all trajectory predictions of the target trajectory prediction model is defined as follows: given a set of past trajectories of the target agent and its N neighboring agents, Y0 represents the true future trajectory of the target agent. And any When D(Y,Y0)≤s, the target trajectory prediction model f is It is robust to disturbance radius r>0;

[0080] Both definitions of robustness have their advantages. First, BoN remains the main evaluation metric in the field, representing the upper limit of the model's predictive ability. As a generally accepted standard and reference point, it facilitates comparisons between different methods. On the other hand, if the robustness of the entire distribution can be evaluated to some extent, this will enhance our confidence in the security of the model.

[0081] Step 3: Construct two types of smooth function models g through TrajRS according to the target trajectory prediction model o and g A ;

[0082] According to the attached Figure 3 , when inputting TrajRS is evaluated at the top of the figure. Gaussian perturbations are added to To form a smooth area, and predicted by the basis function f, the lower part of the figure is about The distribution of whether the predicted trajectory in falls within the safe area, where the distance between the predicted trajectory and the ground truth does not exceed the safety threshold s, p express The lower bound of the probability that the prediction falls into the safe area;

[0083] Random smoothing is a black box method. TrajRS uses random smoothing method. Given input X and basis function f, random smoothing constructs a new smooth function g and constructs two types of smooth function models g accordingly. o and g A , where when Gaussian noise is added to X, the smoothing function g returns the optimal prediction result of the basis function f, and the smoothing function g of the target trajectory prediction model has verifiable robustness to X;

[0084] The robustness definition of the optimal prediction of the target trajectory prediction model, given the trajectory , g o Returns a binary number, which is calculated as follows:

[0085]

[0086] In the formula, Represents a smooth function defined for the robustness of the optimal prediction of the target trajectory prediction model. The number 1 indicates that when On When Gaussian smooth noise is used, the BoN prediction Y of the target trajectory prediction model f is o The probability of falling within the safe distance of the ground truth trajectory is greater than 0.5, and the number 0 means that when On When Gaussian smooth noise is used, the BoN prediction Y of the target trajectory prediction model f is o The probability of falling within a safe distance of the ground truth trajectory is less than or equal to 0.5, Represents the discrete probability of the target trajectory prediction model;

[0087] The robustness definition of all trajectory predictions for the target trajectory prediction model is given by , g AReturns a binary number, which is calculated as follows:

[0088]

[0089] In the formula, Represents a smooth function defined for the robustness of all trajectory predictions of the target trajectory prediction model. The number 1 indicates that when Exposure When Gaussian smooth noise is used, the predictions of the target trajectory prediction model f all fall within the safe distance of the ground truth trajectory. The number 0 indicates that when Exposure When Gaussian smoothed noise is used, the prediction of the target trajectory prediction model f does not fall within the safe distance of the ground truth trajectory. Represents the discrete probability of the target trajectory prediction model;

[0090] The smoothing model is g o and g A At radius l2 and The X inside is robust, where φ -1 is the inverse of the standard Gaussian CDF, and σ represents the standard deviation;

[0091] Step 4: Introduce the Neyman-Pearson lemma based on the Gaussian distribution of different means of the target trajectory prediction model and derive the smoothing function model g o and g A The corresponding theorem uses the Monte Carlo algorithm to independently evaluate the smooth function model g o and g A Robustness;

[0092] Neyman-Pearson Lemma and make is any deterministic function, if exist but like exist but in, Indicates that X has a mean of x and a covariance matrix of σ 2 The multivariate normal distribution of I, Indicates that Y has a mean of x+δ and a covariance matrix of σ 2 Multivariate normal distribution of I, δ T z represents linear transformation, and β represents the change threshold;

[0093] For simplicity, the random variables are expressed as follows:

[0094]

[0095] In order to prove that g o To ensure the robustness of , it is necessary to prove that it is still robust after being disturbed by δ in the closed L2 norm ball;

[0096]

[0097] like satisfy Then we get:

[0098]

[0099] Let the half space be defined as follows:

[0100]

[0101]

[0102] Algebraic operations show that and In summary, and

[0103] By Lemma and h(K)=1[Y o ∈f(K), D(Y o ,Y0)≤s] and h(K′)=1[Y o ∈f(K′), D(Y o ,Y0)>s], K and K′ represent X and Y in the lemma and we conclude that:

[0104]

[0105] Then calculated:

[0106]

[0107] Finally, algebraic reasoning shows that And ||δ||<σφ -1 ( p ), we get

[0108] In order to prove that g A To ensure robustness, use replace correspond and

[0109] Derive the smooth function model g o The corresponding theorem is as follows:

[0110] represents the target trajectory prediction model, let g o Defined as the equation:

[0111]

[0112] like satisfy For all , all have ||δ||2<R o , where R o =σφ -1 ( p ), δ represents the perturbation in the L2 norm ball, that is,

[0113] Derive the smooth function model g A The corresponding theorem is as follows:

[0114] represents the target trajectory prediction model, let g A Defined as the equation:

[0115]

[0116] like satisfy For all , all have ||δ||2<R A , where R A =σφ -1 ( p );

[0117] Use the Monte Carlo algorithm to independently evaluate the smooth function model g o and g A as follows:

[0118] according to Figure 4 As shown, the overall approach of the two algorithms is similar, but due to g A The goal is to determine whether all predictions made by f for the same sample are at a safe distance from the ground truth, so the Monte Carlo algorithm concept is used again. Multiple predictions are performed for the target trajectory prediction model (the number of samples is represented as n p ), and record the safety prediction data, that is, the distance from the actual situation is less than the safety threshold s, first calculate the corresponding lower limit of the probability p of the safety prediction, if the calculated lower limit exceeds the safety requirement, the invention is set to 0.99 in the algorithm, and it is considered that all trajectory predictions made by the model have a safety probability guarantee;

[0119] To estimate p, it is necessary to calculate the one-sided (1-α) lower confidence interval of the binomial parameter p for a given sample k~Binomial(n,p), which is expressed as LOWERCONFBOUND(k,n,1-α) in the algorithm;

[0120] The effectiveness of TrajRS in verifying the robustness of trajectory prediction models is evaluated through experiments. The four trajectory prediction models Trajectron++, AgentFormer, MemoNet and MID are evaluated using two datasets: the public pedestrian trajectory prediction benchmark ETH / UCY and the Stanford UAV dataset SDD. The historical trajectory data spanning 8 time steps is analyzed and then the next 12 time steps are predicted, where each time step corresponds to an interval of 0.4 seconds. The most commonly used evaluation metric, average displacement error (ADE), is used as the evaluation metric D to measure the difference between the two trajectories. When analyzing the robustness of the best prediction, the best-of-k prediction setting is adopted, where the performance is measured based on the minimum ADE. The described LOWERCONFBOUND(k,n,1-α) uses k=20;

[0121] When evaluating the robustness of the smoothing models used for optimal trajectory prediction, the quality is assessed primarily through adversarial attack and defense methods. The pre-trained models - Trajectron++, MemoNet, Agentformer, and MID are tested on a random subset of 500 samples from the ETH / UCY dataset, and on a similar subset of MemoNet and MID from the SDD dataset. Different noise levels are established depending on the dataset (meters for ETH / UCY and pixels for SDD). For ETH / UCY, they are denoted as σ∈{0.1, 0.4, 0.7, 1.0} and for SDD as σ∈{1, 4, 7, 10}. N=104 Monte Carlo samples are used to estimate the smoothed predictions and generate certificates. The significance level is set to α=0.001. To reflect unit differences, different safety thresholds are specified: s=2 for ETH / UCY and s=50 for SDD. Figure 5 and attached Figure 6 It shows how the certified security rates of different smooth prediction models and datasets vary with the perturbation radius r;

[0122] In the robustness analysis of all trajectory predictions, three predicted trajectories are selected from the ETH / UCY and SDD datasets, identified by (frame ID, person ID). For the ETH / UCY dataset, the robustness of the Trajectron++, MemoNet, MID and AgentFormer smoothing models need to be evaluated, and the noise level σ is set to 0.3. For the SDD dataset, our focus is on the robustness of the smoothed MID model, and σ is set to 3. We use n = 1000 and np = 1000, keeping the confidence level as 0.001. Figure 7 and Figure 8 The performance of these models under different safety threshold settings is listed separately. As the safety threshold increases, the certified robustness radius provided by TrajRS also increases until it reaches a certain upper limit defined by the noise level σ and the number of samples n.

[0123] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A trajectory prediction algorithm verification method based on random smoothing, characterized by: The following steps are involved: Step 1: Establish a two-dimensional Euclidean space based on the target trajectory prediction model, and analyze the spatial coordinates, trajectory, and discrete probability distribution of the target trajectory prediction model accordingly; Step 2: Expand the trajectory prediction based on the target trajectory prediction model and generate the robustness definition of the optimal prediction and the robustness definition of all possible predictions; Step 3: Construct two types of smooth function models g through TrajRS according to the target trajectory prediction model o and g A ; Step 4: Introduce the Neyman-Pearson lemma based on the Gaussian distribution of different means of the target trajectory prediction model and derive the smoothing function model g o and g A The corresponding theorem uses the Monte Carlo algorithm to independently evaluate the smooth function model g o and g A Robust.

2. The trajectory prediction algorithm verification method based on random smoothing according to claim 1, characterized in that: The two-dimensional Euclidean space is marked as The spatial coordinates of the target trajectory prediction model are marked as x, the trajectories of the target trajectory prediction model are marked as X and Y, and the vectorization of multiple trajectory matrices of the target trajectory prediction model is marked as The discrete probability of the target trajectory prediction model is marked as 3. The trajectory prediction algorithm verification method based on random smoothing according to claim 2, characterized in that: The two-dimensional Euclidean space middle, is the spatial coordinate of the agent at timestamp t, where Indicates the horizontal position, Indicates the vertical position, timestamp T=T p +T f , T p Indicates the past timestamp, T f Represents a future timestamp, a matrix represents the vectorization of the past trajectory of the i-th agent, Indicates the i-th agent at timestamp (-T p +1), Indicates T p The Cartesian product of the two-dimensional space within a time period, represents the trajectory of the agent to be predicted, represents the future trajectory of vectorized prediction, X1,...,X N is the past trajectory of N adjacent agents, Indicates that the target prediction model is trained by trajectory prediction, and the argmin represents the parameter value of the training function so that the loss function Reaching the minimum value, Vectorization of the representation matrix, target trajectory prediction model Output Borel represents measurable space If the discrete probability distribution on judge yes One of the predicted multiple trajectories.

4. The trajectory prediction algorithm verification method based on random smoothing according to claim 3, characterized in that: The target trajectory prediction model uses the L2 norm to describe the robustness region, where For a given input trajectory, if any spatial coordinate x of the trajectory ( t) are all in x ( t) enters a closed L2 norm sphere with radius r>0 and is disturbed, and is defined as for The set of all perturbation trajectories derived, represents the trajectory before the disturbance, and X represents the trajectory after the disturbance.

5. The trajectory prediction algorithm verification method based on random smoothing according to claim 4, characterized in that: The robustness of the optimal prediction of the target trajectory prediction model is defined as follows: given a set of past trajectories of the target agent and its N neighboring agents, represents the true future trajectory of the target agent, f represents the specified target trajectory prediction model, D represents the evaluation index, s represents the predefined safety threshold, if any Optimal predicted trajectory Satisfy D(Y o ,Y0)≤s, the target trajectory prediction model f is defined as is robust to perturbation radius r>0, where Represents past trajectory The trajectory set after perturbation, argmin Y∈f(X) D(Y,Y0) represents the optimal prediction of the model.

6. The trajectory prediction algorithm verification method based on random smoothing according to claim 5, characterized in that: The robustness of all trajectory predictions of the target trajectory prediction model is defined as follows: given a set of past trajectories of the target agent and its N neighboring agents, Y0 represents the true future trajectory of the target agent. And any When D(Y,Y0)≤s, the target trajectory prediction model f is It is robust to perturbation radius r>

0.

7. The trajectory prediction algorithm verification method based on random smoothing according to claim 6, characterized in that: The TrajRS adopts a random smoothing method. Given the input X and the basis function f, it constructs a new smooth function g through random smoothing and constructs two types of smooth function models g accordingly. o and g A , where when Gaussian noise is added to X, the smoothing function g returns the optimal prediction result of the basis function f, and the smoothing function g of the target trajectory prediction model has verifiable robustness to X; The robustness definition of the optimal prediction of the target trajectory prediction model, given the trajectory g o Returns a binary number, which is calculated as follows: In the formula, Represents a smooth function defined for the robustness of the optimal prediction of the target trajectory prediction model. The number 1 indicates that when On When Gaussian smooth noise is used, the BoN prediction Y of the target trajectory prediction model f is o The probability of falling within the safe distance of the ground truth trajectory is greater than 0.5, and the number 0 means that when On When Gaussian smooth noise is used, the probability that the BoN prediction Y of the target trajectory prediction model f falls within the safe distance of the ground truth trajectory is less than or equal to 0.

5. Represents the discrete probability of the target trajectory prediction model; The robustness definition of all trajectory predictions for the target trajectory prediction model is given by g A Returns a binary number, which is calculated as follows: In the formula, Represents a smooth function defined for the robustness of all trajectory predictions of the target trajectory prediction model. The number 1 indicates that when Exposure When Gaussian smooth noise is used, the predictions of the target trajectory prediction model f all fall within the safe distance of the ground truth trajectory. The number 0 indicates that when Exposure When Gaussian smoothed noise is used, the prediction of the target trajectory prediction model f does not fall within the safe distance of the ground truth trajectory. Represents the discrete probability of the target trajectory prediction model; The smoothing model is g o and g A At radius l2 and It is robust around X within , where φ-1 is the inverse of the standard Gaussian CDF and σ represents the standard deviation.

8. The trajectory prediction algorithm verification method based on random smoothing according to claim 7, characterized in that: The Neyman–Pearson lemma states and make is any deterministic function, if exist but like exist but in, Indicates that X has a mean of x and a covariance matrix of σ 2 The multivariate normal distribution of I, Indicates that Y has a mean of x+δ and a covariance matrix of σ 2 Multivariate normal distribution of I, δ T z represents linear transformation, and β represents the change threshold; For simplicity, the random variables are expressed as follows: In order to prove that g o To ensure the robustness of , it is necessary to prove that it is still robust after being disturbed by δ in the closed L2 norm ball; like satisfy Then we get: Let the half space be defined as follows: Algebraic operations show that and In summary, and By Lemma and h(K)=1[Y o ∈f(K), D(Y o ,Y0)≤s] and h(K′)=1[Y o ∈f(K′), D(Y o ,Y0)>s], K and K′ represent X and Y in the lemma and we conclude that: Then calculated: Finally, algebraic reasoning shows that And ‖δ‖<σφ -1 ( p ), we get In order to prove that g A To ensure robustness, use replace correspond and 9. The trajectory prediction algorithm verification method based on random smoothing according to claim 8, characterized in that: The derived smooth function model g o The corresponding theorem is as follows: represents the target trajectory prediction model, let g o Defined as the equation: like satisfy For all Both have ‖δ‖2 <R o , where R o =σφ -1 ( p ), δ represents the perturbation in the L2 norm ball, that is, The derived smooth function model g A The corresponding theorem is as follows: represents the target trajectory prediction model, let g A Defined as the equation: like satisfy For all Both have ‖δ‖2 <R A , where R A =σφ -1 ( p ).

10. The trajectory prediction algorithm verification method based on random smoothing according to claim 8, characterized in that: In the step 4, the smoothing function model g o and g A The evaluation method is as follows: Multiple predictions are performed for the target trajectory prediction model, and the safe prediction data is recorded. That is, the distance from the actual situation is less than the safety threshold s. First, the corresponding lower limit of the probability of safe prediction is calculated. If the calculated lower limit exceeds the safety requirement, it is considered that all trajectory predictions made by the model have a safe probability guarantee.