arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

智能交通系统中语言模型的内联控制架构

An Inline Control Architecture for Language Models in Intelligent Transportation Systems

Narendra Kumar Dewangan, Mounira Msahli

arXiv 2608.04065首次发表:更新:

发表机构

Télécom Paris, Institut Polytechnique de Paris(巴黎高等电信学院,巴黎理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对V2X系统中LLM的提示级攻击问题,提出Guarded-V2X内联语义护栏架构,经四阶段实验验证其可降低入侵成功率且不超延迟预算。

AI 中文摘要

车联网(V2X)系统正越来越多地将大语言模型(LLM)用于语义任务,如路边单元和边缘节点的消息摘要、操作员辅助及决策支持。尽管这些组件不属于安全关键控制回路,但它们引入了提示级攻击面,而传统V2X安全机制聚焦于认证和消息完整性,并未解决该问题。本文提出Guarded-V2X,一种内联语义护栏架构,用于在实时约束下保护支持LLM的V2X服务。该系统集成了基于规则的入口过滤、轻量安全分类器、受策略约束的结构化生成、仅可信检索及决策后裁决,以在下游执行前强制实施机器可检查的安全边界。Guarded-V2X通过包含入侵漏洞分析、校准与延迟基准测试、护栏验证及对抗压力下鲁棒性的四阶段实验流程进行评估。实验基于源自RSU通告、操作员消息及带注释V2X消息摘要的V2X对齐模拟数据集开展。结果显示,无防护及仅提示的基线在多轮对抗试验中仍存在残留漏洞,而Guarded-V2X在两轮设置中持续降低入侵接受成功率并消除观测到的不安全完成,且未超过V2X语义通告路径的延迟预算。

英文摘要

Vehicle-to-everything (V2X) systems increasingly incorporate large language models (LLMs) for semantic tasks such as message summarization, operator assistance, and decision support at roadside units and edge nodes. Although these components are not part of safety-critical control loops, they introduce prompt-level attack surfaces that are not addressed by traditional V2X security mechanisms focused on authentication and message integrity. This paper presents Guarded-V2X, an inline semantic guardrail architecture for securing LLM-enabled V2X services under real-time constraints. The proposed system integrates rule-based ingress filtering, a lightweight safety classifier, policy-constrained structured generation, trusted-only retrieval, and post-decision adjudication to enforce machine-checkable safety boundaries prior to downstream execution. Guarded-V2X is evaluated using a four-stage experimental pipeline encompassing intrusion vulnerability analysis, calibration and latency benchmarking, guardrail validation, and robustness under adversarial stress. Experiments are conducted on a V2X-aligned simulated dataset derived from RSU advisories, operator messages, and annotated V2X message summaries. Results show that unguarded and prompt-only baselines retain residual vulnerability under multi-turn adversarial trials, while Guarded-V2X consistently reduces intrusion acceptance success rates and eliminates observed unsafe completions in two-turn settings, without exceeding latency budgets for V2X semantic advisory paths.

Comments18 pages, under minor revision (IEEE transactions)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑