LIMA: Towards building a non-invasive and stealthy real-world adversarial attack model for traffic sign recognition systems.

Fang, Junbin; Shen, Yixuan; Sun, Yujing; Jiang, Canjian; Jiang, You; Pan, Hezhong; Yiu, Siu-Ming; Jiang, Zoe L · Neural Netw · 2026

basic_science · Level V

Where this comes from

Abstract

Traffic sign recognition systems are crucial for autonomous driving safety. However, their susceptibility to adversarial attacks poses severe risks, potentially leading to catastrophic accidents. The purpose of adversarial attack research is to identify vulnerabilities in the systems, thereby improving understanding and response to these security threats. Unlike prior adversarial attacks, which are typically invasive, conspicuous, and impractical, our proposed attack operates non-invasively while remaining stealthy to human observers. Specifically, we exploit high-speed modulation of LED illumination and the rolling shutter mechanism of CMOS sensors to create imperceptible perturbations. By adjusting the LED flicker frequency, we effectively conduct denial-of-service attack and evasion attack. Extensive evaluations in both simulations and real-world scenarios confirm LIMA's effectiveness, with a 100% success rate across most distance-angle combinations and 69.67% success even against defense models.