In vision-based object classification systems imaging sensors perceive the\nenvironment and machine learning is then used to detect and classify objects\nfor decision-making purposes; e.g., to maneuver an automated vehicle around an\nobstacle or to raise an alarm to indicate the presence of an intruder in\nsurveillance settings. In this work we demonstrate how the perception domain\ncan be remotely and unobtrusively exploited to enable an attacker to create\nspurious objects or alter an existing object. An automated system relying on a\ndetection/classification framework subject to our attack could be made to\nundertake actions with catastrophic results due to attacker-induced\nmisperception.\n We focus on camera-based systems and show that it is possible to remotely\nproject adversarial patterns into camera systems by exploiting two common\neffects in optical imaging systems, viz., lens flare/ghost effects and\nauto-exposure control. To improve the robustness of the attack to channel\neffects, we generate optimal patterns by integrating adversarial machine\nlearning techniques with a trained end-to-end channel model. We experimentally\ndemonstrate our attacks using a low-cost projector, on three different image\ndatasets, in indoor and outdoor environments, and with three different cameras.\nExperimental results show that, depending on the projector-camera distance,\nattack success rates can reach as high as 100% and under targeted conditions.\n