Pith. sign in

REVIEW 3 cited by

Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign Perception

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2401.03582 v1 pith:C2KIWBTI submitted 2024-01-07 cs.CR cs.CV

classification cs.CRcs.CV
keywords attacktrafficattacksreflectionssignhumanslaserperception
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

All vehicles must follow the rules that govern traffic behavior, regardless of whether the vehicles are human-driven or Connected Autonomous Vehicles (CAVs). Road signs indicate locally active rules, such as speed limits and requirements to yield or stop. Recent research has demonstrated attacks, such as adding stickers or projected colored patches to signs, that cause CAV misinterpretation, resulting in potential safety issues. Humans can see and potentially defend against these attacks. But humans can not detect what they can not observe. We have developed an effective physical-world attack that leverages the sensitivity of filterless image sensors and the properties of Infrared Laser Reflections (ILRs), which are invisible to humans. The attack is designed to affect CAV cameras and perception, undermining traffic sign recognition by inducing misclassification. In this work, we formulate the threat model and requirements for an ILR-based traffic sign perception attack to succeed. We evaluate the effectiveness of the ILR attack with real-world experiments against two major traffic sign recognition architectures on four IR-sensitive cameras. Our black-box optimization methodology allows the attack to achieve up to a 100% attack success rate in indoor, static scenarios and a >80.5% attack success rate in our outdoor, moving vehicle scenarios. We find the latest state-of-the-art certifiable defense is ineffective against ILR attacks as it mis-certifies >33.5% of cases. To address this, we propose a detection strategy based on the physical properties of IR laser reflections which can detect 96% of ILR attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Asymmetry Vulnerability and Physical Attacks on Online Map Construction for Autonomous Driving

    cs.CR 2025-09 conditional novelty 7.0 of 10

    Online HD map construction models are biased toward symmetric roads; roadside flashlight or adversarial-patch interference can trigger wrong straight-road predictions in asymmetric scenes, degrading map accuracy and p...

  2. A Privacy Enhancing Technique to Evade Detection by Street Video Cameras Without Using Adversarial Accessories

    cs.CV 2025-01 conditional novelty 6.0 of 10

    Pedestrians can lower a detector's confidence by walking through spatial 'blind spots' found from confidence heatmaps, and a location-based threshold can partially counter this.

  3. Towards an End-to-End (E2E) Adversarial Learning and Application in the Physical World

    cs.CV 2025-01 conditional novelty 6.0 of 10

    Adversarial patches can be trained and applied entirely in the physical world through a projector-camera feedback loop, avoiding the transferability loss of printed stickers.

Pith tools