Research Exposes Security Flaws in Autonomous Vehicle Traffic Sign Recognition
Researchers from the University of California, Irvine have demonstrated that multicolored stickers applied to stop and speed limit signs can deceive self-driving vehicle AI systems, leading to unpredictable and potentially dangerous driving behaviors. The study, presented at the Network and Distributed System Security Symposium, highlights how such low-cost attacks can either make road signs invisible to autonomous vehicles or create phantom signs, resulting in unsafe traffic violations. The researchers tested these vulnerabilities on commercially available autonomous driving systems from top-selling brands.
The study found that AI-based traffic sign recognition (TSR) systems can be confused by simple printed patterns created using open-source tools. This method can trigger unintended braking, acceleration, or disregard for real road signs. The research also identified a common spatial memorization feature in TSR systems, which makes erasing real signs difficult but makes the appearance of fake signs surprisingly easy. These findings challenge previous academic assumptions and emphasize the need for further industry and academic collaboration to improve security in autonomous vehicles.
The research, supported by the National Science Foundation and the U.S. Department of Transportation, was conducted by a team led by UC Irvine scientists and published as a first-of-its-kind large-scale evaluation of security risks in commercial self-driving technology.
