Adaptive Shadow Attack on Traffic Sign Recognition Models

Zhen Zhou, Miao Li, Daiyun Wang, Xin Jun Xu · 2025

Physical adversarial attacks against deep neural networks (DNNs) have recently garnered increasing attention. Recently, natural optical attacks have been studied. The methods usually produce adversarial perturbations by casting shadows to reduce brightness in specific regions of the target surface. However, the shadows are generally strict for natural environments. In this study, we propose an adaptive shadow attack (AS A) method to attack traffic signs. ASA encodes the parameters of the vertex coordinates of the triangular shadow as particles, and designs a particle swarm optimization algorithm with adaptive learning strategy (PSOALS) to optimize the parameters. Then, the particles are decoded to generate shadows, and the shadows are projected onto the component images of the input traffic signs to generate an adversarial sample. The comparison experiments are conducted on the G TSRB test sets. The experimental results on traffic sign recognition show that our algorithm effectively generates adversarial examples, achieving attack success rates of 97.6% on the GTSRB test set. In addition, ASA is robust against viewpoint changes. Overall, ASA is effective in producing attacks against traffic signs under natural and reflected light illuminations.

Read the paper · More papers on PaperTik