IP Library › Granted Patent US 12,737,438
Granted Patent B2
US 12,737,438 · App. 18/180,476 · Granted Sep 15, 2026

Robust trajectory predictions against adversarial attacks in autonomous machines and applications

Inventors: Chaowei Xiao (Tempe, AZ); Yulong Cao (Union City, NJ); Danfei Xu (Atlanta, GA); Animashree Anandkumar (Pasadena, CA); Marco Pavone (Stanford, CA); Xinshuo Weng (North York, CA)
Assignee: NVIDIA Corporation
G06F21/14B60W60/0011G06N3/094
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,438
App. No.
18/180,476
Granted
Sep 15, 2026
Kind
B2
Abstract

In various examples, robust trajectory predictions against adversarial attacks in autonomous machines and applications are described herein. Systems and methods are disclosed that perform adversarial training for trajectory predictions determined using a neural network(s). In order to improve the training, the systems and methods may devise a deterministic attack that creates a deterministic gradient path within a probabilistic model to generate adversarial samples for training. Additionally, the systems and methods may introduce a hybrid objective that interleaves the adversarial training and learning from clean data to anchor the output from the neural network(s) on stable, clean data distribution. Furthermore, the systems and methods may use a domain-specific data augmentation technique that generates diverse, realistic, and dynamically-feasible samples for additional training of the neural network(s).

Claims (85)

1 . A method comprising:

receiving input data representing one or more points associated with a past trajectory of an object through an environment;

receiving ground truth data associated with the input data, the ground truth data representing a future trajectory of the object through the environment;

generating, using a deterministic attack that creates a deterministic gradient path within a probabilistic generative model, training data representing an adversarial trajectory of the object, the deterministic gradient path guiding an obfuscation of at least a point of the one or more points associated with the past trajectory; and

training, based at least on the input data, the training data, and the ground truth data, one or more neural networks comprising the probabilistic generative model for determining future trajectories.

2 . The method of claim 1 , wherein the deterministic attack includes generating an adversarial perturbation using a deterministic latent code.

3 . The method of claim 1 , wherein:

the obfuscation comprises updating a location of the point by a distance; and

the method further comprises determining to train the one or more neural networks using the training data based at least on the distance being within a threshold distance.

4 . The method of claim 1 , further comprising:

generating, based at least on the input data, second training data representing an augmented past trajectory associated with the object; and

generating, based at least on the ground truth data, second ground truth data representing an augmented future trajectory associated with the object,

wherein the training the one or more neural networks is further based at least on the second training data and the second ground truth data.

5 . The method of claim 4 , wherein at least one of:

the generating the second training data is further based at least on one or more of constraining one or more first states of the one or more points using one or more first thresholds, causing the augmented past trajectory to remain in a same lane as the past trajectory, or causing the augmented past trajectory to follow one or more first traffic rules; or

the generating the second ground truth data is further based at least on one or more of constraining one or more second states of one or more second points associated with the future trajectory using one or more second thresholds, causing the augmented future trajectory to remain in a same lane as the future trajectory, or causing the augmented future trajectory to follow one or more second traffic rules.

6 . The method of claim 1 , wherein the deterministic attack includes generating an adversarial perturbation using a deterministic sample of a latent distribution to define the adversarial trajectory based at least on the deterministic sample providing the deterministic gradient path for updating the obfuscation of the one or more points.

7 . The method of claim 1 , wherein the training the one or more neural networks comprises:

optimizing a hybrid objective function to interleave learning from the adversarial trajectory and learning from the input data, the hybrid objective function anchoring a conditional distribution of the probabilistic generative model to a stable clean data distribution thereby reducing a shift in adversarial distributions during the training relative to using the adversarial trajectory alone.

8 . A system comprising:

one or more processing units to:

receive input data representing at least a past trajectory of an object through an environment;

receive ground truth data associated with the input data, the ground truth data representing a future trajectory of the object through the environment;

generate, using a deterministic attack that creates a deterministic gradient path within a probabilistic generative model, training data representing an adversarial past trajectory associated with the object, the deterministic gradient path guiding an obfuscation of at least one point associated with the past trajectory; and

train, based at least on the training data and the ground truth data, one or more neural networks comprising the probabilistic generative model for determining trajectories.

9 . The system of claim 8 , wherein the deterministic attack is performed through an encoder and a decoder of the probabilistic generative model using a deterministic latent code to bypass stochasticity within the encoder.

10 . The system of claim 8 , wherein:

the obfuscation comprises updating a location of a point associated with the past trajectory by a distance; and

the one or more processing units are further to train the one or more neural networks using the training data based at least on the distance being within a threshold distance.

11 . The system of claim 8 , wherein the one or more processing units are further to:

generate, based at least on the input data, second training data representing an augmented past trajectory associated with the object; and

generate, based at least on the ground truth data, second ground truth data representing an augmented future trajectory associated with the object,

wherein the one or more neural networks are further trained based at least on the second training data and the second ground truth data.

12 . The system of claim 11 , wherein at least one of:

the generation of the second training data is further based at least on one or more of constraining one or more first states of the past trajectory using one or more first thresholds, causing the augmented past trajectory to remain in a same lane as the past trajectory, or causing the augmented past trajectory to follow one or more first traffic rules; or

the generation of the second ground truth data is further based at least on one or more of constraining one or more second states of the future trajectory using one or more second thresholds, causing the augmented future trajectory to remain in a same lane as the future trajectory, or causing the augmented future trajectory to follow one or more second traffic rules.

13 . The system of claim 8 , wherein the one or more neural networks are further trained based at least on the input data.

14 . The system of claim 8 , wherein the one or more neural networks are trained by at least:

determining, using the one or more neural networks and based at least on the training data, a second future trajectory associated with the object;

determining a difference between the second future trajectory and the future trajectory; and

updating, based at least on the difference, one or more parameters associated with the one or more neural networks.

15 . The system of claim 8 , wherein the system is comprised in at least one of:

a control system for an autonomous or semi-autonomous machine;

a perception system for an autonomous or semi-autonomous machine;

a system for performing simulation operations;

a system for performing digital twin operations;

a system for performing light transport simulation;

a system for performing collaborative content creation for 3D assets;

a system for performing deep learning operations;

a system implemented using an edge device;

a system implemented using a robot;

a system for performing conversational AI operations;

a system for generating synthetic data;

a system incorporating one or more virtual machines (VMs);

a system implemented at least partially in a data center; or

a system implemented at least partially using cloud computing resources.

16 . At least one processor comprising:

one or more processing units to:

receive input data representing at least a past trajectory of an object through an environment;

receive ground truth data associated with the input data, the ground truth data representing a future trajectory of the object through the environment;

generate, using a deterministic attack that creates a deterministic gradient path within a probabilistic generative model, training data representing an adversarial past trajectory, the deterministic gradient path guiding an obfuscation of at least a portion of the past trajectory; and

train, based at least on the training data and the ground truth data, one or more neural networks comprising the probabilistic generative model for determining trajectories.

17 . The at least one processor of claim 16 , wherein the obfuscation comprises updating at least one of a location associated with a point of the past trajectory, a velocity associated with the point, an acceleration associated with the point, or an orientation associated with the point.

18 . The at least one processor of claim 16 , wherein:

the obfuscating the at least the portion of the past trajectory comprises updating a location of a point associated with the past trajectory by a distance; and

the one or more processing units are further to train the one or more neural networks using the training data based at least on the distance being within a threshold distance.

19 . The at least one processor of claim 16 , wherein the one or more processing units are further to:

generate, based at least on the input data, second training data representing an augmented past trajectory associated with the object; and

generate, based at least on the ground truth data, second ground truth data representing an augmented future trajectory associated with the object,

wherein the one or more neural networks are further trained based at least on the second training data and the second ground truth data.

20 . The at least one processor of claim 16 , wherein the at least one processor is comprised in at least one of:

a control system for an autonomous or semi-autonomous machine;

a perception system for an autonomous or semi-autonomous machine;

a system for performing simulation operations;

a system for performing digital twin operations;

a system for performing light transport simulation;

a system for performing collaborative content creation for 3D assets;

a system for performing deep learning operations;

a system implemented using an edge device;

a system implemented using a robot;

a system for performing conversational AI operations;

a system for generating synthetic data;

a system incorporating one or more virtual machines (VMs);

a system implemented at least partially in a data center; or

a system implemented at least partially using cloud computing resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: XIAO, CHAOWEI; CAO, YULONG; XU, DANFEI; ANANDKUMAR, ANIMASHREE; PAVONE, MARCO; WENG, XINSHUO
To: NVIDIA CORPORATION
Reel/Frame 063007/0725 →
Continuity (2)
Provisional Application 63389684 · Jul 15, 2022
Related Publication 20240028673A1 · Jan 25, 2024
References Cited (46)
US 10521718B1 · Szegedy · 2019 [cited by examiner]
US 11514293B2 · Villegas et al. · 2022 [cited by applicant]
US 11520345B2 · Onofrio et al. · 2022 [cited by applicant]
US 11609572B2 · Chen et al. · 2023 [cited by applicant]
US 12266144B2 · Mustikovela · 2025 [cited by examiner]
US 20190049970A1 · Djuric · 2019 [cited by examiner]
US 20190095731A1 · Vernaza · 2019 [cited by examiner]
US 20190303759A1 · Farabet · 2019 [cited by examiner]
US 20190384303A1 · Muller et al. · 2019 [cited by applicant]
US 20200180647A1 · Anthony · 2020 [cited by examiner]
US 20200339109A1 · Hong et al. · 2020 [cited by applicant]
US 20210081715A1 · Rosman · 2021 [cited by examiner]
US 20210124353A1 · Dally et al. · 2021 [cited by applicant]
US 20210253128A1 · Nister et al. · 2021 [cited by applicant]
Caesar, H., et al.: “NuScenes: A Multimodal Dataset for Autonomous Driving”; https://arxiv.org/abs/1903.11027; May 5, 2020, 16 pgs. [cited by applicant]
Alahi, et al.; “Social LSTM: Human Trajectory Prediction in Crowded Spaces”, In Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 961-971, 2016. [cited by applicant]
Ivanovic, et al.; “The Trajectron: Probabilistic Multi-Agent Trajectory Modeling with Dynamic Spatiotemporal Graphs”; In Proceedings of the IEEE/CVF International Conference on Computer Vision, pp. 2375-2384, 2019. [cited by applicant]
Salzmann, et al.; “Trajectron++:Dynamically-feasible Trajectory Forecasting with Heterogeneous Data”; In European Conference on Computer Vision, pp. 683-700, Springer, 2020. [cited by applicant]
Yuan, et al.; “Agentformer: Agent-Aware Transformers for Socio-Temporal Multi-Agent Forecasting”; In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), 2021, 11 pgs. [cited by applicant]
Rhinehart, et al.; “R2p2: A Reparameterized Pushforward Policy for Diverse, Precise Generative Path Forecasting”; In Proceedings of the European Conference on Computer Vision (ECCV), pp. 772-788, 2018. [cited by applicant]
Rhinehart, et al.; “Precog: Prediction Conditioned on Goals in Visual Multi-Agent Settings”; In Proceedings of the IEEE/CVF International Conference on Computer Vision, pp. 2821-2830, 2019. [cited by applicant]
Kosaraju, et al.; “Social-Bigat: Multimodal Trajectory Forecasting Using Bicycle-GAN and Graph Attention Networks”; Advances in Neural Information Processing Systems, 32, 2019. [cited by applicant]
Zhang, et al.; “On Adversarial Robustness of Trajectory Prediction for Autonomous Vehicles”; arXiv preprint arXiv:2201.05057, 2022, 13 pgs. [cited by applicant]
Madry, et al.; “Towards Deep Learning Models Resistant to Adversarial Attacks”; arXiv preprint arXiv:1706.06083, 2017, 28 pgs. [cited by applicant]
Zhang, et al.; “Theoretically Principled Trade-Off Between Robustness and Accuracy”; In International Conference on Machine Learning, pp. 7472-7482, PMLR, 2019. [cited by applicant]
Athalye, et al.; “Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples”; In International Conference on Machine Learning, pp. 274-283, PMLR, 2018. [cited by applicant]
Kos, et al.; “Adversarial Examples for Generative Models”; In 2018 IEEE Security and Privacy Workshops (spw), pp. 36-42, IEEE, 2018. [cited by applicant]
Barrett, et al.; “Certifiably Robust Variational Autoencoders”; In Proceedings of the 25th International Conference on Artificial Intelligence and Statistics, V.151 of Proceedings of Machine Learning Research, 21 pgs, P… [cited by applicant]
Willetts, et al.; “Improving VAEs' Robustness to Adversarial Attack”; arXiv preprint arXiv:1906.00230, 2019, 27 pgs. [cited by applicant]
Xie, et al.; “Intriguing Properties of Adversarial Training at Scale”; arXiv preprint arXiv:1906.03787, Dec. 21, 2019, 14 pgs. [cited by applicant]
Jeddi, et al.; “A Simple Fine-Tuning is All You Need: Towards Robust Deep Learning Via Adversarial Fine-Tuning”; arXiv preprint arXiv:2012.13628, Dec. 25, 2020, 10 pgs. [cited by applicant]
Liu, et al.; “Extending Adversarial Attacks and Defenses to Deep 3D Point Cloud Classifiers”; arXiv:1901.03006, Jun. 28, 2019, 9 pgs. [cited by applicant]
Papernot, et al.; “Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks”; arXiv:1511.04508, Mar. 14, 2016, 16 pgs. [cited by applicant]
Papernot, et al.; “Extending Defensive Distillation”; arXiv:1705.05264; May 15, 2017, 11 pgs. [cited by applicant]
Shafahi, et al.; “Adversarial Training for Free!”; arXiv preprint arXiv:1904.12843, 2019, 12 pgs. [cited by applicant]
Wong, et al.; “Fast is Better than Free: Revisiting Adversarial Training”; arXiv preprint arXiv:2001.03994, Jan. 12, 2020, 17 pgs. [cited by applicant]
Xie, et al.; “Adversarial Examples Improve Image Recognition”; In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pp. 819-828, 2020. [cited by applicant]
Xie, et al.; “Smooth Adversarial Training”; arXiv preprinted arXiv:2006.14536, Jul. 11, 2021, 11 pgs. [cited by applicant]
Xu, et al.; “Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks”; arXiv preprint arXiv:1704.01155; Dec. 5, 2017, 15 pgs. [cited by applicant]
Yang, et al.; “Me-Net: Towards Effective Adversarial Robustness with Matrix Estimation”; arXiv preprint arXiv:1905.11971, May 28, 2019, 22 pgs. [cited by applicant]
Weng, et al.; “Towards Fast Computation of Certified Robustness for Relu Networks”; In International Conference on Machine Learning, pp. 5276-5285, PMLR, 2018. [cited by applicant]
Rice, et al.; “Overfitting in Adversarilly Robust Deep Learning”; In International Conference on Machine Learning, pp. 8093-8104, PMLR, 2020. [cited by applicant]
Rebuffi, et al.; “Fixing Data Augmentation to Improve Adversarial Robustness”; arXiv:2103.01946; Oct. 18, 2021, 21 pgs. [cited by applicant]
Polack, et al.; “The Kinematic Bicycle Model: A Consistent Model for Planning Feasible Trajectories for Autonomous vehicles?”; In 2017 IEEE Intelligent Vehicles Symposium (IV), pp. 812-818, 2017. [cited by applicant]
Eykholt, et al.; “Robust Physical-World Attacks on Deep Learning Visual Classification”; In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1625-1634, 2018. [cited by applicant]
Choquette, et al.; “NVIDIA a100 Tensor Core GPU: Performance and Innovation”; IEEE Micro, 41(2):29-35, 2021, 7 pgs. [cited by applicant]