paper-with-me

Papers

Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems Perspective

2024-09-15 · Ningfei Wang, Shaoyuan Xie, Takami Sato, Yunpeng Luo, Kaidi Xu, Qi Alfred Chen

Traffic Sign Recognition (TSR) is crucial for safe and correct driving automation. Recent works revealed a general vulnerability of TSR models to physical-world adversarial attacks, which can be low-cost, highly deployable, and capable of causing severe attack effects such as hiding a critical traffic sign or spoofing a fake one. However, so far existing works generally only considered evaluating the attack effects on academic TSR models, leaving the impacts of such attacks on real-world commercial TSR systems largely unclear. In this paper, we conduct the first large-scale measurement of physical-world adversarial attacks against commercial TSR systems. Our testing results reveal that it is possible for existing attack works from academia to have highly reliable (100\%) attack success against certain commercial TSR system functionality, but such attack capabilities are not generalizable, leading to much lower-than-expected attack success rates overall. We find that one potential major factor is a spatial memorization design that commonly exists in today's commercial TSR systems. We design new attack success metrics that can mathematically model the impacts of such design on the TSR system-level attack success, and use them to revisit existing attacks. Through these efforts, we uncover 7 novel observations, some of which directly challenge the observations or claims in prior works due to the introduction of the new metrics.

📄 PDF Abstract BibTeX arXiv:2409.09860

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackMemorizationTraffic Sign Recognition

Similar Papers 제목 키워드 기반

Revisiting Physically Realizable Adversarial Object Attack against LiDAR-based Detection: Clarifying Problem Formulation and Experimental Protocols

2025-07-24 · Luo Cheng, Hanwei Zhang, Lijun Zhang, Holger Hermanns arxiv

Adversarial robustness in LiDAR-based 3D object detection is a critical research area due to its widespread application in real-world scenarios. While many digital attacks manipulate point clouds or meshes, they often la…

Adversarial Robustness3D Object DetectionPoint Clouds

ITPatch: An Invisible and Triggered Physical Adversarial Patch against Traffic Sign Recognition

2024-09-19 · Shuai Yuan, Hongwei Li, Xingshuo Han, Guowen Xu 외

Physical adversarial patches have emerged as a key adversarial attack to cause misclassification of traffic sign recognition (TSR) systems in the real world. However, existing adversarial patches have poor stealthiness a…

Adversarial AttackTraffic Sign Recognition

Rogue Signs: Deceiving Traffic Sign Recognition with Malicious Ads and Logos

2018-01-09 · Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Prateek Mittal 외

We propose a new real-world attack against the computer vision based systems of autonomous vehicles (AVs). Our novel Sign Embedding attack exploits the concept of adversarial examples to modify innocuous signs and advert…

Autonomous VehiclesTraffic Sign Recognition

The Outline of Deception: Physical Adversarial Attacks on Traffic Signs Using Edge Patches

2025-11-30 · Haojie Ji, Te Hu, Haowen Li, Long Jin 외 arxiv

Intelligent driving systems are vulnerable to physical adversarial attacks on traffic signs. These attacks can cause misclassification, leading to erroneous driving decisions that compromise road safety. Moreover, within…

Instance Segmentation

T2I-Based Physical-World Appearance Attack against Traffic Sign Recognition Systems in Autonomous Driving

2025-11-17 · Chen Ma, Ningfei Wang, Junhao Zheng, Qing Guo 외 arxiv

Traffic Sign Recognition (TSR) systems play a critical role in Autonomous Driving (AD) systems, enabling real-time detection of road signs, such as STOP and speed limit signs. While these systems are increasingly integra…

Traffic Sign RecognitionAutonomous Driving