Singapore Institute of Technology
Browse

Invisible Adversarial Stripes on Traffic Sign: Threat and Defense for Autonomous Vehicles

Download (2.57 MB)
journal contribution
posted on 2025-11-14, 05:40 authored by DONGFANG GUODONGFANG GUO, Yuting Wu, Pengfei Zhou, Xin LouXin Lou, Rui Tan
<p dir="ltr">Camera-based computer vision is essential to autonomous vehicle’s perception. This paper presents an attack that uses light-emitting diodes and exploits the camera’s rolling shutter efect to create adversarial stripes in the captured images to mislead traic sign recognition. The attack is stealthy because the stripes on the traic sign are invisible to human. For the attack to be threatening, the recognition results need to be stable over consecutive image frames. To achieve this, we design and implement GhostStripe, an attack system that controls the timing of the modulated light emission to adapt to camera operations and victim vehicle movements. Evaluated on real testbeds, GhostStripe can stably spoof the traic sign recognition results for up to 94% of frames to a wrong class when the victim vehicle passes the road section. In reality, such attack effect may fool victim vehicles into life-threatening incidents. To counteract this threat, we propose GhostBuster, a software-based defense module to detect and mitigate the efects of GhostStripe. GhostBuster incorporates a perturbation detector and a sign restorer, efectively restoring the natural appearance of compromised traic signs and signiicantly reducing t</p>

History

Related Materials

  1. 1.
    DOI - Is identical to https://doi.org/10.1145/3773031

Journal/Conference/Book title

ACM Transactions on Sensor Networks

Publication date

2025-10-27

Version

  • Published

Usage metrics

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC