The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
Shuai Yuan, Xingshuo Han, Hongwei Li, Guowen Xu, Wenbo Jiang, Tao Ni, Qingchuan Zhao, Yuguang Fang
Abstract
Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Adversarial Patch EXterminator: Zero-Shot and Patch-Agnostic Defense Framework Against Adversarial Patch AttacksJiayimei Wang, Tao Ni, Guowen Xu, Qingchuan Zhao et al.USENIX Security 2026
- CamPI: Physical Adversarial Examples through Camera Power Signal InjectionYanze Ren, Mingyuan Lv, Qinhong Jiang, Yan Jiang et al.CVPR 2026
Builds on12
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial PerturbationsGiulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier et al.USENIX Security 2021 · 123 citations
- Does Physical Adversarial Example Really Matter to Autonomous Driving? Towards System-Level Effect of Adversarial Object Evasion AttackNingfei Wang, Yunpeng Luo, Takami Sato, Kaidi Xu et al.ICCV 2023 · 65 citations
- Fooling the Eyes of Autonomous Vehicles: Robust Physical Adversarial Examples Against Traffic Sign Recognition SystemsWei Jia, Zhaojun Lu, Haichun Zhang, Zhenglin Liu et al.NDSS 2022
- Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter EffectAthena Sayles, Ashish Hooda, Mohit Gupta, Rahul Chatterjee et al.CVPR 2021
Related papers
- Targeted Physical Evasion Attacks in the Near-Infrared DomainPascal Zimmer, Simon Lachnit, Alexander Jan Zielinski, Ghassan KarameNDSS 2026
- Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign PerceptionTakami Sato, Sri Hrushikesh Varma Bhupathiraju, Michael Clifford, Takeshi Sugawara et al.NDSS 2024
- TPatch: A Triggered Physical Adversarial PatchWenjun Zhu, Xiaoyu Ji, Yushi Cheng, Shibo Zhang et al.USENIX Security 2023
- Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural PhenomenonYiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang et al.CVPR 2022 · 148 citations
- Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems PerspectiveNingfei Wang, Shaoyuan Xie, Takami Sato, Yunpeng Luo et al.NDSS 2025
