Rogue Signs: Deceiving Traffic Sign Recognition with Malicious Ads and Logos

We propose a new real-world attack against the computer vision based systems\nof autonomous vehicles (AVs). Our novel Sign Embedding attack exploits the\nconcept of adversarial examples to modify innocuous signs and advertisements in\nthe environment such that they are classified as the adversary's desired\ntraffic sign with high confidence. Our attack greatly expands the scope of the\nthreat posed to AVs since adversaries are no longer restricted to just\nmodifying existing traffic signs as in previous work. Our attack pipeline\ngenerates adversarial samples which are robust to the environmental conditions\nand noisy image transformations present in the physical world. We ensure this\nby including a variety of possible image transformations in the optimization\nproblem used to generate adversarial samples. We verify the robustness of the\nadversarial samples by printing them out and carrying out drive-by tests\nsimulating the conditions under which image capture would occur in a real-world\nscenario. We experimented with physical attack samples for different distances,\nlighting conditions and camera angles. In addition, extensive evaluations were\ncarried out in the virtual setting for a variety of image transformations. The\nadversarial samples generated using our method have adversarial success rates\nin excess of 95% in the physical as well as virtual settings.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC