Feature-Based Thresholding as a Defense Against Adversarial Attacks on Road Signs
Henry Bensted, Diane L. Peters, Mehrdad Zadeh · IFAC-PapersOnLine · 2025
In recent years, there has been a push towards autonomous vehicles. While this technology has the potential to save millions of lives, it could also take lives when operating in non-ideal conditions. Adversarial attacks against road signs are a common issue that can cause autonomous vehicles to not detect road signs when the passenger can clearly see them. Natural conditions such as weathering and occlusion can also reduce the confidence the classifier has in a segmented region. There are three types of defense methods proposed by researchers: modifying the data, modifying the model, and adding to the model. The approach taken in this paper is to modify the data. Different authors have proposed various defense methods against adversarial attacks on road signs. However, all approaches studied used deep learning, which can be very computationally expensive, especially for the low power hardware used in autonomous vehicles. This paper studies a novel feature-based thresholding (FBT) algorithm as a method to remove unwanted features such as graffiti on STOP signs while maintaining the necessary features in the image and being less computationally expensive than implementing an additional neural network. When combined with both linear prediction based edge detection and a contrast-based adaptive thresholding system, the program can remove all unwanted features from an image, with the unintended side effect of removing some features that should stay in the image.