Pith. sign in

NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles

4 Pith papers cite this work. Polarity classification is still indexing.

4 Pith papers citing it
abstract

It has been shown that most machine learning algorithms are susceptible to adversarial perturbations. Slightly perturbing an image in a carefully chosen direction in the image space may cause a trained neural network model to misclassify it. Recently, it was shown that physical adversarial examples exist: printing perturbed images then taking pictures of them would still result in misclassification. This raises security and safety concerns. However, these experiments ignore a crucial property of physical objects: the camera can view objects from different distances and at different angles. In this paper, we show experiments that suggest that current constructions of physical adversarial examples do not disrupt object detection from a moving platform. Instead, a trained neural network classifies most of the pictures taken from different distances and angles of a perturbed image correctly. We believe this is because the adversarial property of the perturbation is sensitive to the scale at which the perturbed picture is viewed, so (for example) an autonomous car will misclassify a stop sign only from a small range of distances. Our work raises an important question: can one construct examples that are adversarial for many or most viewing conditions? If so, the construction should offer very significant insights into the internal representation of patterns by deep networks. If not, there is a good prospect that adversarial examples can be reduced to a curiosity with little practical impact.

years

2026 1 2019 3

verdicts

UNVERDICTED 4

representative citing papers

RELO: Reinforcement Learning to Localize for Visual Object Tracking

cs.CV · 2026-05-08 · unverdicted · novelty 6.0 · 2 refs

RELO formulates visual object tracking localization as a Markov decision process solved by reinforcement learning with combined IoU and AUC rewards, augmented by layer-aligned temporal token propagation, and reports 57.5% AUC on LaSOText without template updates.

Fooling a Real Car with Adversarial Traffic Signs

cs.CR · 2019-06-30 · unverdicted · novelty 6.0

A reproducible pipeline produces physical adversarial traffic signs that successfully attack production-grade traffic sign recognition systems in a real car under black-box conditions.

citing papers explorer

Showing 4 of 4 citing papers.

  • RELO: Reinforcement Learning to Localize for Visual Object Tracking cs.CV · 2026-05-08 · unverdicted · none · ref 200 · 2 links · internal anchor

    RELO formulates visual object tracking localization as a Markov decision process solved by reinforcement learning with combined IoU and AUC rewards, augmented by layer-aligned temporal token propagation, and reports 57.5% AUC on LaSOText without template updates.

  • Robust Synthesis of Adversarial Visual Examples Using a Deep Image Prior cs.CV · 2019-07-03 · unverdicted · none · ref 13 · internal anchor

    A DIP-based optimization produces adversarial perturbations and patches that are more robust to affine transformations than standard high-frequency noise while staying imperceptible.

  • ML-based Fault Injection for Autonomous Vehicles: A Case for Bayesian Fault Injection cs.LG · 2019-07-01 · unverdicted · none · ref 61 · internal anchor

    DriveFI, a Bayesian ML-based fault injection engine, identifies 561 safety-critical faults in AV systems in under 4 hours on NVIDIA and Baidu stacks, while random injection over weeks found none.

  • Fooling a Real Car with Adversarial Traffic Signs cs.CR · 2019-06-30 · unverdicted · none · ref 41 · internal anchor

    A reproducible pipeline produces physical adversarial traffic signs that successfully attack production-grade traffic sign recognition systems in a real car under black-box conditions.