The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
When the adversary has not triggered the attack, a blank traffic sign is not detected by the model. The driver's naked eyes do not detect the anomaly.
When the adversary has triggered the attack, the model detects a blank traffic sign as a STOP sign. The driver's naked eyes do not detect the anomaly.
When the adversary has not triggered the attack, the model detects the STOP sign normally. The driver's naked eyes do not detect the anomaly.
When the adversary has triggered the attack, the model does not detect the STOP sign. Instead, the driver's naked eyes can see the word "STOP" normally.
When the adversary has not triggered the attack, the model detects the speed limit (40km/h) sign normally.
The driver's naked eyes do not detect the anomaly.
When the adversary has triggered the attack, the model misclassifies the speed limit (40km/h) sign as a no-parking sign.
Instead, the driver's naked eyes can see the number 40 normally.