Skip to content

Enhancing adversarial robustness of lightweight neural networks for on-vehicle traffic sign recognition systems

Aug 2026 · Proceedings of the Institution of mechanical engineers. Part D, journal of automobile engineering · 0 citations · 16 references

TL;DR

TRADES-JR, a TRADES loss function guided by Jacobian regularization, is proposed, which enables LNNs to maintain robust and high-accuracy traffic sign recognition even in adversarial environments, thereby enhancing the reliability of the autonomous driving system.

Abstract

In recent years, with the rapid development of autonomous driving technology, lightweight neural networks (LNNs) have been increasingly applied in-vehicle and edge computing devices. A growing number of studies have focused on deploying LNNs in resource-constrained environments to achieve real-time traffic sign recognition, obstacle detection, and other tasks. However, while LNNs maintain high inference efficiency, their robustness has become an increasingly important concern. Research has shown that adversarial attacks targeting traffic signs can significantly disrupt the predictions of LNNs, leading to misclassifications. To enhance the adversarial robustness of LNNs, we propose TRADES-JR, a TRADES loss function guided by Jacobian regularization. This approach simultaneously considers the prediction distribution differences between clean and adversarial samples while penalizing the Frobenius norm of the network output’s Jacobian with respect to the input. By constraining the sensitivity to input perturbations, our method enhances the adversarial robustness of LNNs. We evaluate the proposed algorithm on the GTSRB and TSRD datasets. The results demonstrate that our method significantly improves the adversarial robustness of LNNs under both white-box and black-box attacks. Therefore, this method enables LNNs to maintain robust and high-accuracy traffic sign recognition even in adversarial environments, thereby enhancing the reliability of the autonomous driving system.

View source

Similar papers

Open access Aug 2026

Enhanced Robustness in Neural Network Models against Adversarial Attacks and their Performance Analysis

Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance.

Surekha M., A. K. Sagar, Vineeta Khemchandani · 0 citations
Open access Aug 2026

A Generative Adversarial Network-Based Method for Intelligent Detection of Military Targets with Few Training Samples for Embedded Edge Devices

A generative adversarial network (GAN) based few-shot military target detection is presented, and results demonstrate that the method effectively balances few-shot detection accuracy, robustness in complex environments, and real-time inference requirements on embedded edge devices.

X. Li, X.-L. Tang, H.-Y. Shi · 0 citations
Conference Jul 2026

Adversarial Robustness in Lane Detection For Autonomous Vehicles Using Generative Adversarial Networks

This research investigates the adversarial robustness of lane detection for Autonomous Vehicles (AVs) under challenging driving conditions using Generative Adversarial Networks (GANs). In this work, the term adversarial refers to the adversarial training mechanism of GANs and to robustness under naturally adverse drivi...

Brian Lee Chong Ming, Thinesh Ganesan · 0 citations
Aug 2026

Multi-layer Adversarial Robustness Analysis of Neural Networks: Visual and Metric-based Approaches

A method to analyze ANNs designed for image classification from an adversarial robustness perspective and implemented an ablation and fine-tuning strategy that successfully boosted the robustness of the ANNs against a variant of the Auto-PGD attack under different threat models.

Inês Valentim, Nuno Antunes, Nuno Lourenço · 0 citations
Preprint Aug 2026

AdROD: HyperNetwork-based Adversarially Robust Object Detection for Autonomous Driving

AdROD outperforms five baseline defenses and exhibits superior generalizability compared with the evaluated adversarial-training baselines, while maintaining real-time performance for safely stopping the vehicle at a stop sign instrumented with adversarial patches.

Yuting Wu, Dongfang Guo, Xiangzhong Luo et al. · 0 citations
Review Aug 2026

A Comprehensive Review on Adversarial Attacks and Detection Techniques in Deep Learning Models for Image Analysis

The research methodology involved a systematic literature review using the Scopus database, adhering to Preferred Reporting Items for Systematic Reviews and Meta-Analyses guidelines, and focusing on recent advancements in attack and defence techniques.

Reeti Jaswal, Vikas Khullar, Surya Narayan Panda · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.