{"id":"c19ff4e1-b9a3-4343-a670-ade673330a8a","arxiv_id":"1907.00374","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"A reproducible pipeline produces physical adversarial traffic signs that successfully attack production-grade traffic sign recognition systems in a real car under black-box conditions.","lead":"The paper describes a pipeline to generate physical adversarial traffic signs that fool both open-source and production-grade classifiers during real drive-by tests on a commercial vehicle. Smart readers should care because it shows that digital adversarial attacks can transfer to physical objects and affect real safety-critical systems.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.3","headline":"Physical transfer of digitally generated perturbations through printing, placement, lighting, distance, and moving-camera capture remains the least-secured step.","rationale":"The reader's weakest assumption directly identifies the physical-transfer step as the critical unverified link; the full text does not alter that assessment because the abstract's assertion still hinges on unquantified real-world outcomes. No other internal inconsistency (e.g., black-box methodology or legacy CV comparison) is more load-bearing for the central claim.","tokens_in":1705,"tokens_out":309,"duration_ms":23477,"concrete_test":"From the results section, extract the exact success rate (successful frames / total frames) across all drive-by passes, the tested distance and speed ranges, and any reported degradation under changed lighting or angles. If the aggregate rate is below ~60 % or confined to a narrow subset of conditions, the physical-robustness claim is not supported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The headline claim requires that perturbations optimized in digital space remain effective after the full physical pipeline (printing on sign material, outdoor mounting, variable illumination, perspective distortion, motion, and the car's actual camera + preprocessing). Even when digital attacks succeed, this transfer frequently collapses; the abstract asserts drive-by confirmation on a production system but supplies no quantitative success rates, trial counts, distance/speed ranges, or failure cases. If the reported successes occurred only under narrow conditions or after post-hoc selection, the claim does not generalize.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper claims to introduce a reproducible pipeline for generating adversarial traffic signs that fool a range of neural-network classifiers (open-source and production-grade) in both digital and physical settings. It emphasizes black-box transferability and reports that the attacks were validated through drive-by experiments on a real car's production-grade traffic sign recognition system.","tokens_in":1804,"tokens_out":287,"duration_ms":30269,"significance":"If the physical transfer results hold with adequate controls and statistics, the work would be significant for showing that digitally optimized perturbations can survive printing, outdoor placement, variable lighting, perspective, and motion to affect a deployed automotive vision system—an extension beyond purely digital or lab-based attacks.","major_comments":[{"comment":"Abstract: the statement that 'the efficiency of the attacks was confirmed in drive-by experiments with a production-grade traffic sign recognition systems of a real car' supplies no quantitative success rates, trial counts, distance/speed ranges, lighting conditions, or failure cases. This information is load-bearing for the central claim of real-world effectiveness.","section":"Abstract"}],"minor_comments":[{"comment":"The abstract refers to 'legacy computer vision systems' without clarifying which systems or how they were evaluated relative to the neural-network attacks.","section":"Abstract"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the constructive comment on the abstract. We agree that quantitative details are important for supporting the central claim and will revise the abstract accordingly.","responses":[{"response":"We agree that the abstract should summarize the quantitative aspects of the drive-by experiments. In the revised version we will update the abstract to include reported success rates, trial counts, distance and speed ranges, lighting conditions, and mention of observed failure cases. These details appear in the experimental sections of the manuscript; we will ensure they are also reflected concisely in the abstract.","revision_made":"yes","referee_comment":"[Abstract] Abstract: the statement that 'the efficiency of the attacks was confirmed in drive-by experiments with a production-grade traffic sign recognition systems of a real car' supplies no quantitative success rates, trial counts, distance/speed ranges, lighting conditions, or failure cases. This information is load-bearing for the central claim of real-world effectiveness."}],"tokens_in":1254,"tokens_out":217,"duration_ms":17394,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The new part is the extension to printed signs tested on an actual production vehicle in motion, with black-box transfer across multiple classifiers including legacy CV ones. That moves past the usual digital-only or lab-bound experiments and directly targets a deployed system, which is the concrete step the abstract highlights as previously unreported. The pipeline for generating reproducible signs is presented as robust enough to work in the real world, and they checked both neural and non-neural recognizers. That focus on cross-system transfer and physical realization is the useful piece if the data hold up. The soft spot is exactly the one the stress-test flags: the abstract asserts drive-by confirmation on the car's system but gives no quantitative success rates, number of trials, distance or speed ranges, lighting conditions, or failure cases. Physical transfer after printing, mounting, and moving-camera capture is the step that most often breaks, and without those numbers it is impossible to judge whether the successes were consistent or narrow. The reader's weakest-assumption note is on target here. This is the kind of work that matters for AV safety discussions, so a reader working on physical robustness or automotive perception would get value from the methods section if it contains the missing counts and controls. It deserves a serious referee to check whether the experimental evidence actually supports the headline claim rather than desk-rejecting on the abstract alone.","headline":"The paper claims successful black-box physical attacks on a real car's production traffic sign system but the abstract supplies no success rates or trial details to support the drive-by results.","tokens_in":2253,"tokens_out":347,"would_cite":false,"duration_ms":17129,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":{"model":"grok-4.3","evidence":[],"headline":"Physical adversarial transfer pipeline (EOT + domain-specific grayscale + TV-in-loop) has no overlap with RS cost or distinction forcing","alignment":"orthogonal","rationale":"Paper's core machinery is an extended DARTS/EOT pipeline (random per-iteration transformations, grayscale loss term L_gs, PASR metric, drive-by validation on production TSR) for generating printable perturbations that survive physical imaging. RS framework derives J-cost, φ, 8-tick periodicity, D=3, and constants from a single distinction (reality_from_one_distinction, AbsoluteFloorClosure, AlexanderDuality, Cost.FunctionalEquation). No shared primitives, no ratio-symmetric cost, no ladder or periodicity claims; domain is ML security, outside RS scope.","tokens_in":50798,"confidence":"high","tokens_out":172,"duration_ms":10232,"cache_read_input_tokens":38528,"cache_creation_input_tokens":0},"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"Digitally generated adversarial traffic signs fool production-grade systems in a real moving car.","keywords":["adversarial examples","traffic signs","real-world attacks","black-box attacks","production systems","physical perturbations","autonomous vehicles"],"falsifier":"Repeated drive-by tests with printed signs on the road that produce no misclassifications in the real car's production-grade system under standard conditions would falsify the claim.","tokens_in":2617,"feed_emoji":"🚗","tokens_out":489,"duration_ms":37920,"temperature":0.7,"pith_summary":"The paper demonstrates a pipeline to generate traffic signs that appear normal but cause misclassification by neural networks and legacy vision systems. These signs are created to work across different classifiers in black-box settings and are tested by printing them and placing them on roads for drive-by capture by a real car's camera. The authors confirm success in actual vehicle experiments with production-grade recognition systems. A reader would care because this bridges digital adversarial attacks to physical-world threats on deployed automotive hardware. If the results hold, it shows that perturbations can survive printing, lighting changes, and motion without needing model-specific knowledge.","feed_headline":"Printed adversarial signs fool real car's traffic system","feed_subtitle":"Drive-by tests confirm digitally made signs cause misclassifications in a production vehicle under motion.","key_machinery":"A pipeline that produces adversarial perturbations on traffic sign images designed to transfer across classifiers and remain effective after physical printing and real-world imaging.","core_discovery":"The paper presents a robust pipeline for reproducible production of adversarial traffic signs that can fool a wide range of classifiers, both open-source and production-grade in the real world. Most attacks were performed in black-box mode, and efficiency was confirmed in drive-by experiments with a production-grade traffic sign recognition system of a real car.","pith_inferences":["This opens questions about whether similar pipelines could target other real-world vision systems beyond traffic signs.","Defenses might need to incorporate physical-world robustness testing rather than digital-only evaluation.","The success rate in drive-by conditions suggests physical adversarial examples may require new mitigation strategies in safety-critical applications."],"forward_implications":["The same signs can attack both neural networks and legacy computer vision systems.","Black-box transfer allows signs generated for one classifier to affect many others.","Physical realization and vehicle motion do not eliminate the attack effectiveness."],"fun_headline_variants":["Adversarial signs trick real car's traffic system","Printed attacks fool production car sign recognition","Drive-by tests reveal sign fooling in real car","Black-box signs mislead vehicle traffic classifiers"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"That perturbations optimized in digital images will continue to cause misclassifications once printed on physical signs viewed by a moving vehicle's camera under real lighting and distance variations.","fun_headline_variants_meta":{"raw":{"variants":["Adversarial signs trick real car's traffic system","Printed attacks fool production car sign recognition","Drive-by tests reveal sign fooling in real car","Black-box signs mislead vehicle traffic classifiers"]},"model":"grok-4.3","cost_usd":0.00364,"raw_usage":{"total_tokens":1896,"prompt_tokens":665,"num_sources_used":0,"completion_tokens":54,"cost_in_usd_ticks":36399500,"prompt_tokens_details":{"text_tokens":665,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1177,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":665,"tokens_out":54,"duration_ms":11796,"temperature":1.0,"reasoning_tokens":1177,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-05-25T12:33:26.309885+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"Repeated drive-by tests with printed signs on the road that produce no misclassifications in the real car's production-grade system under standard conditions would falsify the claim.","supporting_citations":[],"review_version":1}