Diffusion-based driving planners capture diverse behaviors but can generate unsafe trajectories under distribution shift. We propose BridgeGuard, a safety-constrained diffusion planning method that progressively strengthens a constraint term during denoising to drive intermediate trajectories toward a scene-dependent safety domain. Corrections operate in a low-dimensional curve space, promoting geometric coherence. A learned module, DistanceFieldNet, predicts a time-dependent distance field from bird's-eye-view features. Value and spatial-gradient supervision at queries sampled beyond expert trajectories teaches this field about both safe and unsafe regions. The learned field supplies the constraint term through safety injection while the pretrained perception backbone and planner remain frozen. We further establish sufficient conditions for terminal safety in an idealized continuous-time bridge. On Bench2Drive, BridgeGuard improves driving score/success rate from 87.99/74.99% to 90.88/76.36% for BridgeDrive and from 80.79/58.18% to 90.46/74.09% for DiffusionDrivegeo, demonstrating cross-model generalization.
Figures & tables
Figure 1: BridgeGuard safety correction. A learned distance field guides curve refinement during denoising, promoting geometric coherence. Terminal safety is guaranteed only for the idealized continuous-time bridge under the stated assumptions.
Figure 2: DistanceFieldNet training queries. Expert-only sampling (left) covers a narrow, typically safe region. Anchor-based sampling (right) broadens coverage to safe (green) and violating (red) queries beyond the expert path.
Figure 3: BridgeGuard inference. Green components denote BridgeGuard additions. At each denoising step, DistanceFieldNet supplies gradients for curve correction; resampled waypoints are returned to the frozen planner’s solver.
Table 1: Comparison of different methods on Bench2Drive.
Table 5
Figure 4: Unprotected left turn on Bench2Drive. BridgeDrive (blue) collides with an oncoming vehicle; BridgeGuard (orange) avoids the collision by bypassing the vehicle. See also Appendix H .
Figure 5: Multi-lane change on Bench2Drive. BridgeDrive (blue) enters an occupied lane; BridgeGuard (orange) yields to the white vehicle and merges safely. See also Appendix H .
Appendix figures & tables4 assets
Supplementary material from the paper’s appendix.
Appendix
Component
Configuration
Inputs
Shared BEV features, waypoint coordinates, and corresponding time horizons
BEV feature shape
(B,64,64,64)
Convolutional stem
FBEV∈RB×64×H×W→F0∈RB×32×H×W
Spatial query encoding
Sinusoidal positional encoding and MLP; dimensions = 256
Temporal query encoding
Sinusoidal positional encoding and MLP; dimensions = 256
Query normalization
Position scaled by BEV metric extent ( ymax=xmax=32 )
Autonomous driving in complex traffic requires planners that generalize beyond hand-crafted rules, motivating data-driven approaches that learn behavior from expert demonstrations. Diffusion-based trajectory planners have recently shown strong closed-loop performance by iteratively denoising a full-horizon plan, but they remain difficult to certify and can fail catastrophically in rare or out-of-distribution scenarios. To address this challenge, we present PC-Diffuser, a safety augmentation framework that embeds a certifiable, path-consistent barrier-function structure directly into the denoising loop of diffusion planning. The key idea is to make safety an intrinsic part of trajectory generation rather than a post-hoc fix: we enforce forward invariance along the rollout while preserving the diffusion model's intended path geometry. Specifically, PC-Diffuser (i) evaluates collision risk using a capsule-distance barrier function that better reflects vehicle geometry and reduces unnecessary conservativeness, (ii) converts denoised waypoints into dynamically feasible motion under a kinematic bicycle model, and (iii) applies a path-consistent safety filter that eliminates residual constraint violations without geometric distortion, so the corrected plan remains close to the learned distribution. By injecting these safety-consistent corrections at every denoising step and feeding the refined trajectory back into the diffusion process, PC-Diffuser enables iterative, context-aware safeguarding instead of post-hoc repair...
Eugene Ku, Yiwei Lyu
Department of Computer Science and Engineering, Texas A&M University, College Station, TX, USA
End-to-End (E2E) autonomous driving models have shown growing capability in recent years, with performance improving on increasingly challenging benchmarks. However, modern generative E2E planners still suffer from a substantial number of catastrophic failures in safety-critical scenarios. We find that many such failures arise from violations of physical constraints and safety requirements, leading to unsafe behavior. Motivated by this finding, in this paper, we focus on improving safety outcomes in generative end-to-end driving with a targeted reduction of catastrophic planning failures, instead of enhancing average planning quality. Towards this end, we propose DriveSafer, a failure-aware safety framework for end-to-end planners. DriveSafer explicitly steers generative planners towards safe behaviors leveraging both training-time safety constraints and inference-time safety guidance. Compared to the state-of-the-art DiffusionDrive model, on the NAVSIM benchmark, DriveSafer reduces the number of catastrophic failures (PDMS=0) by 48%, with over 65% reduction in drivable-area compliance failures.
Many diffusion-based planners enforce safety through inference-time guidance, but such interleaved trajectory deformations often degrade kinematic feasibility due to manifold rupture. We propose Graph-Guided Safe Diffuser (G2SD), a hierarchical framework that leverages a high-level topological graph planner to guide a low-level diffusion model. G2SD enforces safety at a structural level by abstracting the data manifold into a learned latent graph, on which high-level planning is performed. Continuous trajectories are generated by diffusion planners, which are conditioned on the graph node representations selected by the high-level planner. Theoretical analyses demonstrate conditions under which manifold rupture occurs in diffusion planners, and show that G2SD improves safety by reducing the constraint violation probability as the number of segments increases. Experiments demonstrate that G2SD substantially outperforms baselines, increasing goal-reaching rate without any collision from 40-50% to 98% in Maze2D navigation and also achieving superior task scores in locomotion.
Nakgyu Yang, KwangBin Lee, SooJean Han
School of Electrical Engineering, Korea Advanced Institute of Science and Technology (KAIST) Daejeon, Republic of Korea