Robust trajectory predictions against adversarial attacks in autonomous machines and applications
In various examples, robust trajectory predictions against adversarial attacks in autonomous machines and applications are described herein. Systems and methods are disclosed that perform adversarial training for trajectory predictions determined using a neural network(s). In order to improve the training, the systems and methods may devise a deterministic attack that creates a deterministic gradient path within a probabilistic model to generate adversarial samples for training. Additionally, the systems and methods may introduce a hybrid objective that interleaves the adversarial training and learning from clean data to anchor the output from the neural network(s) on stable, clean data distribution. Furthermore, the systems and methods may use a domain-specific data augmentation technique that generates diverse, realistic, and dynamically-feasible samples for additional training of the neural network(s).
1 . A method comprising:
receiving input data representing one or more points associated with a past trajectory of an object through an environment;
receiving ground truth data associated with the input data, the ground truth data representing a future trajectory of the object through the environment;
generating, using a deterministic attack that creates a deterministic gradient path within a probabilistic generative model, training data representing an adversarial trajectory of the object, the deterministic gradient path guiding an obfuscation of at least a point of the one or more points associated with the past trajectory; and
training, based at least on the input data, the training data, and the ground truth data, one or more neural networks comprising the probabilistic generative model for determining future trajectories.
2 . The method of claim 1 , wherein the deterministic attack includes generating an adversarial perturbation using a deterministic latent code.
3 . The method of claim 1 , wherein:
the obfuscation comprises updating a location of the point by a distance; and
the method further comprises determining to train the one or more neural networks using the training data based at least on the distance being within a threshold distance.
4 . The method of claim 1 , further comprising:
generating, based at least on the input data, second training data representing an augmented past trajectory associated with the object; and
generating, based at least on the ground truth data, second ground truth data representing an augmented future trajectory associated with the object,
wherein the training the one or more neural networks is further based at least on the second training data and the second ground truth data.
5 . The method of claim 4 , wherein at least one of:
the generating the second training data is further based at least on one or more of constraining one or more first states of the one or more points using one or more first thresholds, causing the augmented past trajectory to remain in a same lane as the past trajectory, or causing the augmented past trajectory to follow one or more first traffic rules; or
the generating the second ground truth data is further based at least on one or more of constraining one or more second states of one or more second points associated with the future trajectory using one or more second thresholds, causing the augmented future trajectory to remain in a same lane as the future trajectory, or causing the augmented future trajectory to follow one or more second traffic rules.
6 . The method of claim 1 , wherein the deterministic attack includes generating an adversarial perturbation using a deterministic sample of a latent distribution to define the adversarial trajectory based at least on the deterministic sample providing the deterministic gradient path for updating the obfuscation of the one or more points.
7 . The method of claim 1 , wherein the training the one or more neural networks comprises:
optimizing a hybrid objective function to interleave learning from the adversarial trajectory and learning from the input data, the hybrid objective function anchoring a conditional distribution of the probabilistic generative model to a stable clean data distribution thereby reducing a shift in adversarial distributions during the training relative to using the adversarial trajectory alone.
8 . A system comprising:
one or more processing units to:
receive input data representing at least a past trajectory of an object through an environment;
receive ground truth data associated with the input data, the ground truth data representing a future trajectory of the object through the environment;
generate, using a deterministic attack that creates a deterministic gradient path within a probabilistic generative model, training data representing an adversarial past trajectory associated with the object, the deterministic gradient path guiding an obfuscation of at least one point associated with the past trajectory; and
train, based at least on the training data and the ground truth data, one or more neural networks comprising the probabilistic generative model for determining trajectories.
9 . The system of claim 8 , wherein the deterministic attack is performed through an encoder and a decoder of the probabilistic generative model using a deterministic latent code to bypass stochasticity within the encoder.
10 . The system of claim 8 , wherein:
the obfuscation comprises updating a location of a point associated with the past trajectory by a distance; and
the one or more processing units are further to train the one or more neural networks using the training data based at least on the distance being within a threshold distance.
11 . The system of claim 8 , wherein the one or more processing units are further to:
generate, based at least on the input data, second training data representing an augmented past trajectory associated with the object; and
generate, based at least on the ground truth data, second ground truth data representing an augmented future trajectory associated with the object,
wherein the one or more neural networks are further trained based at least on the second training data and the second ground truth data.
12 . The system of claim 11 , wherein at least one of:
the generation of the second training data is further based at least on one or more of constraining one or more first states of the past trajectory using one or more first thresholds, causing the augmented past trajectory to remain in a same lane as the past trajectory, or causing the augmented past trajectory to follow one or more first traffic rules; or
the generation of the second ground truth data is further based at least on one or more of constraining one or more second states of the future trajectory using one or more second thresholds, causing the augmented future trajectory to remain in a same lane as the future trajectory, or causing the augmented future trajectory to follow one or more second traffic rules.
13 . The system of claim 8 , wherein the one or more neural networks are further trained based at least on the input data.
14 . The system of claim 8 , wherein the one or more neural networks are trained by at least:
determining, using the one or more neural networks and based at least on the training data, a second future trajectory associated with the object;
determining a difference between the second future trajectory and the future trajectory; and
updating, based at least on the difference, one or more parameters associated with the one or more neural networks.
15 . The system of claim 8 , wherein the system is comprised in at least one of:
a control system for an autonomous or semi-autonomous machine;
a perception system for an autonomous or semi-autonomous machine;
a system for performing simulation operations;
a system for performing digital twin operations;
a system for performing light transport simulation;
a system for performing collaborative content creation for 3D assets;
a system for performing deep learning operations;
a system implemented using an edge device;
a system implemented using a robot;
a system for performing conversational AI operations;
a system for generating synthetic data;
a system incorporating one or more virtual machines (VMs);
a system implemented at least partially in a data center; or
a system implemented at least partially using cloud computing resources.
16 . At least one processor comprising:
one or more processing units to:
receive input data representing at least a past trajectory of an object through an environment;
receive ground truth data associated with the input data, the ground truth data representing a future trajectory of the object through the environment;
generate, using a deterministic attack that creates a deterministic gradient path within a probabilistic generative model, training data representing an adversarial past trajectory, the deterministic gradient path guiding an obfuscation of at least a portion of the past trajectory; and
train, based at least on the training data and the ground truth data, one or more neural networks comprising the probabilistic generative model for determining trajectories.
17 . The at least one processor of claim 16 , wherein the obfuscation comprises updating at least one of a location associated with a point of the past trajectory, a velocity associated with the point, an acceleration associated with the point, or an orientation associated with the point.
18 . The at least one processor of claim 16 , wherein:
the obfuscating the at least the portion of the past trajectory comprises updating a location of a point associated with the past trajectory by a distance; and
the one or more processing units are further to train the one or more neural networks using the training data based at least on the distance being within a threshold distance.
19 . The at least one processor of claim 16 , wherein the one or more processing units are further to:
generate, based at least on the input data, second training data representing an augmented past trajectory associated with the object; and
generate, based at least on the ground truth data, second ground truth data representing an augmented future trajectory associated with the object,
wherein the one or more neural networks are further trained based at least on the second training data and the second ground truth data.
20 . The at least one processor of claim 16 , wherein the at least one processor is comprised in at least one of:
a control system for an autonomous or semi-autonomous machine;
a perception system for an autonomous or semi-autonomous machine;
a system for performing simulation operations;
a system for performing digital twin operations;
a system for performing light transport simulation;
a system for performing collaborative content creation for 3D assets;
a system for performing deep learning operations;
a system implemented using an edge device;
a system implemented using a robot;
a system for performing conversational AI operations;
a system for generating synthetic data;
a system incorporating one or more virtual machines (VMs);
a system implemented at least partially in a data center; or
a system implemented at least partially using cloud computing resources.