arXiv:2512.00765cs.CV2025-12

用边缘贴片制造隐蔽攻击,让交通标志骗过智能驾驶系统。

The Outline of Deception: Physical Adversarial Attacks on Traffic Signs Using Edge Patches

  • 基于视觉注意力机制,在标志边缘生成贴合形状的遮挡掩码。
  • 在有限查询下攻击成功率超90%,且跨模型迁移能力强。
  • 贴片与背景融合自然,角度距离变化下仍有效,适合真实场景。

智能驾驶系统易受交通标志的物理对抗攻击,此类攻击可引发误识别,导致错误驾驶决策,威胁道路安全。此外,在车联网(V2X)网络中,此类误判可能传播并引发级联故障,破坏整体交通流与系统稳定性。然而,当前物理攻击普遍缺乏隐蔽性:多数方法在标志中心区域施加扰动,产生明显视觉特征,易被人类察觉,限制了实际应用。本文提出 TESP-Attack,一种面向交通标志分类的新型隐蔽对抗贴片方法。基于人眼注意力多集中于标志中心的观察,采用实例分割生成与标志形状契合的边缘对齐掩码;利用 U-Net 生成器构造对抗贴片,并通过颜色、纹理约束及频域分析优化,实现与背景环境的高度融合,达成强视觉隐蔽效果。该方法在多种架构的交通标志分类模型上均表现出卓越攻击成功率,有限查询预算下超过90%;具备强跨模型迁移能力,且在不同视角与距离下保持稳定的真实世界性能。

原文摘要 · Abstract (English)

Intelligent driving systems are vulnerable to physical adversarial attacks on traffic signs. These attacks can cause misclassification, leading to erroneous driving decisions that compromise road safety. Moreover, within V2X networks, such misinterpretations can propagate, inducing cascading failures that disrupt overall traffic flow and system stability. However, a key limitation of current physical attacks is their lack of stealth. Most methods apply perturbations to central regions of the sign, resulting in visually salient patterns that are easily detectable by human observers, thereby limiting their real-world practicality. This study proposes TESP-Attack, a novel stealth-aware adversarial patch method for traffic sign classification. Based on the observation that human visual attention primarily focuses on the central regions of traffic signs, we employ instance segmentation to generate edge-aligned masks that conform to the shape characteristics of the signs. A U-Net generator is utilized to craft adversarial patches, which are then optimized through color and texture constraints along with frequency domain analysis to achieve seamless integration with the background environment, resulting in highly effective visual concealment. The proposed method demonstrates outstanding attack success rates across traffic sign classification models with varied architectures, achieving over 90% under limited query budgets. It also exhibits strong cross-model transferability and maintains robust real-world performance that remains stable under varying angles and distances.

对抗攻击交通标志隐蔽性U-Net

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。