arXiv:2511.12956cs.CVcs.CR2025-11

用AI生成骗过自动驾驶交通标志识别的隐形攻击图样。

T2I-Based Physical-World Appearance Attack against Traffic Sign Recognition Systems in Autonomous Driving

  • 基于T2I模型生成可物理打印的对抗性图案,提升隐蔽性和迁移能力。
  • 在真实场景下平均攻击成功率83.3%,对不同距离角度光照均有效。
  • 适合研究自动驾驶安全、对抗样本防御的学者与工程师。

交通标志识别(TSR)系统在自动驾驶中至关重要,可实时检测如停车和限速标志。尽管已广泛应用于量产车辆,近期研究揭示其易受物理世界对抗性外观攻击。此类攻击通过精心设计的视觉图案,使TSR模型误判为合法标志,而对人类观察者则保持隐蔽。现有方法存在明显局限:基于像素扰动的方法缺乏隐蔽性且泛化能力差;基于文本到图像(T2I)扩散模型的方法对域外标志类型效果不佳。本文提出DiffSign,一种新型T2I基外观攻击框架,可生成物理鲁棒、高效、可迁移、实用且隐蔽的攻击。通过引入CLIP损失与掩码提示增强攻击可控性,并设计两种新风格定制方法以提升域外标志攻击泛化性与隐蔽性。在多种真实条件(不同距离、角度、光照、标志类别)下评估,本方法平均物理攻击成功率达83.3%,充分展现高迁移性与有效性。

原文摘要 · Abstract (English)

Traffic Sign Recognition (TSR) systems play a critical role in Autonomous Driving (AD) systems, enabling real-time detection of road signs, such as STOP and speed limit signs. While these systems are increasingly integrated into commercial vehicles, recent research has exposed their vulnerability to physical-world adversarial appearance attacks. In such attacks, carefully crafted visual patterns are misinterpreted by TSR models as legitimate traffic signs, while remaining inconspicuous or benign to human observers. However, existing adversarial appearance attacks suffer from notable limitations. Pixel-level perturbation-based methods often lack stealthiness and tend to overfit to specific surrogate models, resulting in poor transferability to real-world TSR systems. On the other hand, text-to-image (T2I) diffusion model-based approaches demonstrate limited effectiveness and poor generalization to out-of-distribution sign types. In this paper, we present DiffSign, a novel T2I-based appearance attack framework designed to generate physically robust, highly effective, transferable, practical, and stealthy appearance attacks against TSR systems. To overcome the limitations of prior approaches, we propose a carefully designed attack pipeline that integrates CLIP-based loss and masked prompts to improve attack focus and controllability. We also propose two novel style customization methods to guide visual appearance and improve out-of-domain traffic sign attack generalization and attack stealthiness. We conduct extensive evaluations of DiffSign under varied real-world conditions, including different distances, angles, light conditions, and sign categories. Our method achieves an average physical-world attack success rate of 83.3%, leveraging DiffSign's high effectiveness in attack transferability.

对抗攻击自动驾驶视觉安全T2I生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。