閉じる

NEWS

Paper accepted at ACSAC 2026: “Trapped by Their Own Light”

2026.09.11
Editorial illustration of a car headlight activating a retroreflective adversarial patch on a stop sign

Traffic Sign Recognition (TSR) is fundamental to the safety and efficiency of autonomous vehicles, yet it remains vulnerable to physical adversarial attacks such as stickers and laser projections. Existing attacks are either easy for humans to notice or require bulky projection equipment, leaving a gap between theoretical feasibility and real-world impact.

This work introduces the Adversarial Retroreflective Patch (ARP), a new attack vector that combines the deployability of physical patches with the stealth of light-based attacks. ARP uses retroreflective materials that stay inconspicuous under ambient light and are activated only by the victim vehicle’s own headlights. With physics-based retroreflection modeling and black-box optimization, ARP achieves over a 90% attack success rate in dynamic driving scenarios and 60% against commercial TSR systems, and a user study confirms stealthiness comparable to benign signs. The paper also proposes DPR Shield, a defense built from two strategically placed polarized filters, which reaches defense success rates of 75% or higher for stop signs and speed limit signs. The work will be presented at ACSAC 2026 (acceptance rate 19.3%) in Los Angeles in December 2026. It is a collaboration among Waseda University, Keio University, and the University of California, Irvine.

[Paper]
Go Tsuruoka, Takami Sato, Qi Alfred Chen, Kazuki Nomoto, Ryunosuke Kobayashi, Yuna Tanaka, Tatsuya Mori, “Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems,” Proceedings of the 42nd Annual Computer Security Applications Conference (ACSAC 2026), Los Angeles, CA, USA, December 2026.

ACSAC 2026 website