arXiv:2604.02457cs.CVcs.CR2026-04

用不到100美元造出合法可上路的车牌对抗环,让识别系统准确率降60%。

Street-Legal Physical-World Adversarial Rim for License Plates

  • 设计可量产的物理对抗车牌环,无需接触识别系统
  • 在理想条件下使识别准确率下降60%,可18%精准伪装车牌
  • 符合德州法律,适合关注隐私与系统安全的研究者

自动车牌识别(ALPR)系统广泛用于车辆追踪。尽管已有研究揭示其漏洞,但对其合法性与真实世界可行性关注较少。本文探讨低资源攻击者能否对现代开源ALPR系统fast-alpr实施有效对抗攻击。提出街合法物理对抗环(SPAR),一种可实际部署的白盒攻击,无需访问识别基础设施,且不遮挡或修改原车牌。基于德州立法与判例,论证SPAR在该州合法。最优条件下,SPAR使识别准确率降低60%,目标伪装成功率达18%。制造成本低于100美元,且完全由商业智能编程助手实现。结果揭示现代ALPR在真实环境中的实际脆弱性,并为攻防研究提供新方向。

原文摘要 · Abstract (English)

Automatic license plate reader (ALPR) systems are widely deployed to identify and track vehicles. While prior work has demonstrated vulnerabilities in ALPR systems, far less attention has been paid to their legality and physical-world practicality. We investigate whether low-resourced threat actors can engineer a successful adversarial attack against a modern open-source ALPR system. We introduce the Street-legal Physical Adversarial Rim (SPAR), a physically realizable white-box attack against the popular ALPR system fast-alpr. SPAR requires no access to ALPR infrastructure during attack deployment and does not alter or obscure the attacker's license plate. Based on prior legislation and case law, we argue that SPAR is street-legal in the state of Texas. Under optimal conditions, SPAR reduces ALPR accuracy by 60% and achieves an 18% targeted impersonation rate. SPAR can be produced for under $100, and it was implemented entirely by commercial agentic coding assistants. These results highlight practical vulnerabilities in modern ALPR systems under realistic physical-world conditions and suggest new directions for both attack and defense.

对抗攻击车牌识别物理安全隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。