paper-with-me

홈 › Papers

Fooling a Real Car with Adversarial Traffic Signs

2019-06-30 · Nir Morgulis, Alexander Kreines, Shachar Mendelowitz, Yuval Weisglass

The attacks on the neural-network-based classifiers using adversarial images have gained a lot of attention recently. An adversary can purposely generate an image that is indistinguishable from a innocent image for a human being but is incorrectly classified by the neural networks. The adversarial images do not need to be tuned to a particular architecture of the classifier - an image that fools one network can fool another one with a certain success rate.The published works mostly concentrate on the use of modified image files for attacks against the classifiers trained on the model databases. Although there exists a general understanding that such attacks can be carried in the real world as well, the works considering the real-world attacks are scarce. Moreover, to the best of our knowledge, there have been no reports on the attacks against real production-grade image classification systems.In our work we present a robust pipeline for reproducible production of adversarial traffic signs that can fool a wide range of classifiers, both open-source and production-grade in the real world. The efficiency of the attacks was checked both with the neural-network-based classifiers and legacy computer vision systems. Most of the attacks have been performed in the black-box mode, e.g. the adversarial signs produced for a particular classifier were used to attack a variety of other classifiers. The efficiency was confirmed in drive-by experiments with a production-grade traffic sign recognition systems of a real car.

📄 PDF Abstract BibTeX arXiv:1907.00374

Code (0)

등록된 구현이 없습니다.

Tasks

image-classificationImage ClassificationTraffic Sign Recognition

Similar Papers 제목 키워드 기반

Adversarial Scratches: Deployable Attacks to CNN Classifiers

2022-04-20 · Loris Giulivi, Malhar Jere, Loris Rossi, Farinaz Koushanfar 외

A growing body of work has shown that deep neural networks are susceptible to adversarial examples. These take the form of small perturbations applied to the model's input which lead to incorrect predictions. Unfortunate…

Adversarial Attacks on Traffic Sign Recognition: A Survey

2023-07-17 · Svetlana Pavlitska, Nico Lambing, J. Marius Zöllner

Traffic sign recognition is an essential component of perception in autonomous vehicles, which is currently performed almost exclusively with deep neural networks (DNNs). However, DNNs are known to be vulnerable to adver…

Adversarial AttackAutonomous VehiclesSurveyTraffic Sign Detection+1

Fooling the Eyes of Autonomous Vehicles: Robust Physical Adversarial Examples Against Traffic Sign Recognition Systems

2022-01-17 · Wei Jia, Zhaojun Lu, Haichun Zhang, Zhenglin Liu 외

Adversarial Examples (AEs) can deceive Deep Neural Networks (DNNs) and have received a lot of attention recently. However, majority of the research on AEs is in the digital domain and the adversarial patches are static, …

Autonomous VehiclesObjectTraffic Sign Recognition

The Outline of Deception: Physical Adversarial Attacks on Traffic Signs Using Edge Patches

2025-11-30 · Haojie Ji, Te Hu, Haowen Li, Long Jin 외 arxiv

Intelligent driving systems are vulnerable to physical adversarial attacks on traffic signs. These attacks can cause misclassification, leading to erroneous driving decisions that compromise road safety. Moreover, within…

Instance Segmentation

Road images augmentation with synthetic traffic signs using neural networks

2021-01-13 · Anton Konushin, Boris Faizov, Vlad Shakhuro

Traffic sign recognition is a well-researched problem in computer vision. However, the state of the art methods works only for frequent sign classes, which are well represented in training datasets. We consider the task …

Generative Adversarial NetworkTraffic Sign DetectionTraffic Sign Recognition