paper-with-me

Papers

The Outline of Deception: Physical Adversarial Attacks on Traffic Signs Using Edge Patches

2025-11-30 · Haojie Ji, Te Hu, Haowen Li, Long Jin, Chongshi Xin, Yuchi Yao, Jiarui Xiao arxiv

Intelligent driving systems are vulnerable to physical adversarial attacks on traffic signs. These attacks can cause misclassification, leading to erroneous driving decisions that compromise road safety. Moreover, within V2X networks, such misinterpretations can propagate, inducing cascading failures that disrupt overall traffic flow and system stability. However, a key limitation of current physical attacks is their lack of stealth. Most methods apply perturbations to central regions of the sign, resulting in visually salient patterns that are easily detectable by human observers, thereby limiting their real-world practicality. This study proposes TESP-Attack, a novel stealth-aware adversarial patch method for traffic sign classification. Based on the observation that human visual attention primarily focuses on the central regions of traffic signs, we employ instance segmentation to generate edge-aligned masks that conform to the shape characteristics of the signs. A U-Net generator is utilized to craft adversarial patches, which are then optimized through color and texture constraints along with frequency domain analysis to achieve seamless integration with the background environment, resulting in highly effective visual concealment. The proposed method demonstrates outstanding attack success rates across traffic sign classification models with varied architectures, achieving over 90% under limited query budgets. It also exhibits strong cross-model transferability and maintains robust real-world performance that remains stable under varying angles and distances.

📄 PDF Abstract BibTeX arXiv:2512.00765

Code (0)

등록된 구현이 없습니다.

Tasks

Instance Segmentation

Similar Papers 제목 키워드 기반

Physical Adversarial Attacks on Deep Neural Networks for Traffic Sign Recognition: A Feasibility Study

2023-02-27 · Fabian Woitschek, Georg Schneider

Deep Neural Networks (DNNs) are increasingly applied in the real world in safety critical applications like advanced driver assistance systems. An example for such use case is represented by traffic sign recognition syst…

Traffic Sign Recognition

Attribution of Gradient Based Adversarial Attacks for Reverse Engineering of Deceptions

2021-03-19 · Michael Goebel, Jason Bunk, Srinjoy Chattopadhyay, Lakshmanan Nataraj 외

Machine Learning (ML) algorithms are susceptible to adversarial attacks and deception both during training and deployment. Automatic reverse engineering of the toolchains behind these adversarial machine learning attacks…

AttributeBIG-bench Machine Learning

Physical Adversarial Attacks For Camera-based Smart Systems: Current Trends, Categorization, Applications, Research Challenges, and Future Outlook

2023-08-11 · Amira Guesmi, Muhammad Abdullah Hanif, Bassem Ouni, Muhammed Shafique

In this paper, we present a comprehensive survey of the current trends focusing specifically on physical adversarial attacks. We aim to provide a thorough understanding of the concept of physical adversarial attacks, ana…

Adversarial AttackDepth EstimationFace RecognitionSemantic Segmentation+1

Effective faking of verbal deception detection with target-aligned adversarial attacks

2025-01-10 · Bennett Kleinberg, Riccardo Loconte, Bruno Verschuere

Background: Deception detection through analysing language is a promising avenue using both human judgments and automated machine learning judgments. For both forms of credibility assessment, automated adversarial attack…

Adversarial AttackDeception DetectionLanguage ModelingLanguage Modelling+1

Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems Perspective

2024-09-15 · Ningfei Wang, Shaoyuan Xie, Takami Sato, Yunpeng Luo 외

Traffic Sign Recognition (TSR) is crucial for safe and correct driving automation. Recent works revealed a general vulnerability of TSR models to physical-world adversarial attacks, which can be low-cost, highly deployab…

Adversarial AttackMemorizationTraffic Sign Recognition