Skip to content
Conference

Traffic sign recognition robustness against real-world naturalistic and weather perturbations

Jul 2026 · International Conference on Machine Vision and Applications · Vol 14270, pp. 1427003 - 1427003-13 · 0 citations · 45 references
Engineering

TL;DR

It is established that architectural choice critically impacts adversarial robustness and that diffusion-based purification provides practical test-time defense for deployed autonomous driving systems.

Abstract

Traffic sign recognition systems are critical for autonomous vehicle safety yet remain vulnerable to adversarial perturbations that exploit environmental conditions. Existing naturalistic attacks employ simplified approximations without modeling underlying physics, while defenses lack comprehensive evaluation across diverse architectures and attack types. This work formulates six physically-grounded adversarial attacks spanning naturalistic perturbations (shadow, light patch, obstruction) and weather conditions (fog, snow, frost), optimized via Prior-guided Bayesian Optimization for black-box scenarios. We evaluate nine architectures across three geographically diverse datasets, revealing that transformer-based models exhibit 20.0 percentage points (pp) lower average attack success rate than CNNs (41.5% vs 61.5%) with comparable clean accuracy across datasets. We introduce Robustness Score (RS) to quantify resilience across all attacks, with baseline ConvNeXt-Tiny achieving 60.9% RS compared to best CNN at 50.7%. DiffPure diffusion-based purification substantially improves robustness through test-time noise injection and reverse denoising, increasing RS by 29.8-37.3 pp. Post-defense, transformer architectures achieve 6-16% residual attack success rate compared to 15-39% for CNNs, with consistent effectiveness across datasets (variance ⪅ 2.1 pp). These findings establish that architectural choice critically impacts adversarial robustness and that diffusion-based purification provides practical test-time defense for deployed autonomous driving systems.

View source

Similar papers

Preprint Aug 2026

Distilling Vision-Language Models for Robust Traffic Sign Perception in Autonomous Vehicles

Evaluated on GTSRB and LISA across four backbones and three physical attack types, LAMDA is the only method among ten evaluated that consistently improves robustness across all attack-backbone-dataset combinations, while preserving or improving clean accuracy in nearly all cases.

Pedram MohajerAnsari, Amir Salarpour, Mert D. Pesé · 0 citations
Aug 2026

Enhancing adversarial robustness of lightweight neural networks for on-vehicle traffic sign recognition systems

TRADES-JR, a TRADES loss function guided by Jacobian regularization, is proposed, which enables LNNs to maintain robust and high-accuracy traffic sign recognition even in adversarial environments, thereby enhancing the reliability of the autonomous driving system.

YunKai Zhao, Shang Gao, Jieliang Zhao · 0 citations
Open access Aug 2026

ADS Guard: A Generalizable Defense Framework for Adversarially Robust Occupancy Detection in Smart Buildings

Occupancy detection is fundamental to the operational intelligence of smart buildings, driving critical functions in energy management, HVAC automation, and physical security. While modern Deep Learning (DL) models have achieved high accuracy in parsing complex environmental sensor data, they remain highly vulnerable t...

Pratiksha Chaudhari, Yang Xiao, Wei Sun · 0 citations
Jul 2026

Revisiting the Adversarial Robustness of Graph-Based Traffic Forecasting

This work reframe robustness as a detection problem, introducing a learned physics-informed detector whose output is fed to a hardened forecaster as an input feature and trained against adaptive attacks with the forecaster fixed and improves even on adversarial training hardened against the physics-aware attack itself.

Qingzhao Zhang · 0 citations
Open access Aug 2026

Sparse Adversarial Patch Attack and Robustness Evaluation Algorithm for Vision-Language Models

Visual language models (VLMs) have demonstrated outstanding performance in high-value domains such as autonomous driving, unmanned system navigation, and intelligent question-answering; however, the security of their cross-modal alignment mechanisms has not yet been fully verified. Existing visual adversarial patch att...

T.-Y. Chen, X.-Y. Hu, J.-F. Wang et al. · 0 citations
Conference Jul 2026

Adversarial Robustness in Lane Detection For Autonomous Vehicles Using Generative Adversarial Networks

This research investigates the adversarial robustness of lane detection for Autonomous Vehicles (AVs) under challenging driving conditions using Generative Adversarial Networks (GANs). In this work, the term adversarial refers to the adversarial training mechanism of GANs and to robustness under naturally adverse drivi...

Brian Lee Chong Ming, Thinesh Ganesan · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.