TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GhostStripe attack haunts self-driving cars by making them ignore road signs

32 pointsby curmudgeon22about 1 year ago

12 comments

cs702about 1 year ago
These guys had to work really, really hard to find a way to fool the machine vision of recent self-driving software!<p>My take: Maybe the machine vision of recent self-driving software has become harder to fool than human vision? Human vision is <i>remarkably easy to fool</i>. See <a href="https:&#x2F;&#x2F;www.ritsumei.ac.jp&#x2F;~akitaoka&#x2F;index-e.html" rel="nofollow">https:&#x2F;&#x2F;www.ritsumei.ac.jp&#x2F;~akitaoka&#x2F;index-e.html</a> and <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Optical_illusion" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Optical_illusion</a> for example.<p>Luckily for all of us, there are no smart people laboring all day long in a lab trying to find new ways to fool human drivers into doing dumb, dangerous things on the road. Human drivers already do that on their own -- no tricks or illusions are necessary.
评论 #40323850 未加载
评论 #40322367 未加载
NegativeLatencyabout 1 year ago
Interesting, but wouldn&#x27;t it be less work to cover&#x2F;remove&#x2F;deface the sign if you&#x27;re trying to do something like this? Planting a sneaky black box with an LED would seem super suspicious.
评论 #40321823 未加载
评论 #40322660 未加载
llsfabout 1 year ago
As long as cars are gracefully handling weird visions (like Stop sign in middle of 80mph highway) it should be fine.<p>When I was 1yo my dad was driving on the highway, got distracted, and ended up on a highway portion that was under construction. He was driving full speed, when he saw a barrier, late enough that he swung the steering wheel to avoid the barrier, and ended up driving on 2 wheels before the car felt back and stopped. No baby at the time, my grand-ma was holding me in the back (good old years when cars were lighter and less secure).<p>Random things can happen on the road, including wrong signage. As long as the car can assess the current state and graceful transition to a safe spot, it should be fine to throw at them random signage.
wilgabout 1 year ago
Somewhat confusing because it seems like they didn&#x27;t test it against any actual self-driving car stack, just some kind of toy version?<p>Who knows what context besides the actual sign itself is used to determine where to stop, for example. Maybe the line on the road, maybe map data, maybe the pole or the appearance of the intersection itself. Maybe the vision system is resilient to this attack in some other way. Maybe the system detects this state and has a fail-safe behavior.<p>Anyway, interesting to research, but unclear how it affects production systems.
briandwabout 1 year ago
It’s good to know the limits AI systems. However this doesn’t mean that we shouldn’t develop self driving. Infrastructure is vulnerable, AI or no. You can attack the infrastructure, there is no counter other than a populous that mostly obeys the rules. People can go out and remove road signs, paint fake lines on the highway or coverup stop signs with plastics bags. Those would be crimes. Intentional interference with a self driving car would also be a crime. A certain amount of trust is required to make society work.
评论 #40322580 未加载
dublinbenabout 1 year ago
So they’ve finally reached parity with human drivers then.
edge17about 1 year ago
<i>Six boffins mostly hailing from Singapore-based universities have proven it&#x27;s possible to interfere with autonomous vehicles by exploiting their reliance on camera-based computer vision and cause them to not recognize road signs.</i><p>How do non-camera based systems (lidar etc) get road sign information? I would expect with cameras...?
评论 #40322521 未加载
alex-robbinsabout 1 year ago
The only difference between this and <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;1958&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;1958&#x2F;</a> is that this attack confuses cars from certain manufacturers but not human drivers, and I&#x27;m not sure that that distinction is important.<p>Is this attack actually in anybody&#x27;s threat model?
评论 #40322118 未加载
评论 #40322792 未加载
banish-m4about 1 year ago
Perhaps sign recognition should be lossy-tolerant multifactor for redundancy: size, shape, orientation, GNSS position against GIS map data, color, text font, etc.
mhbabout 1 year ago
So change the cameras to global shutter?
评论 #40322228 未加载
smegsicleabout 1 year ago
irl traffic signs are retroreflective, which might give the headlights an edge over the malicious leds
FredPretabout 1 year ago
The future is hilarious.<p>- my car is haunted by visions<p>- my computer needs a pep talk to generate some work<p>- my other computer gets upset when I&#x27;m wearing sunglasses because it doesn&#x27;t recognize me
评论 #40321917 未加载
评论 #40322686 未加载
评论 #40322650 未加载
评论 #40322743 未加载