The Image Scaling Attack: Unveiling the Risks in Traffic Sign Classification

Aliza Reif, Tarek Stolz, Stjepan Picek, Oscar Hernán Ramírez-Agudelo, Michael Karl · 2025

Image scaling attacks exploit vulnerabilities in the resizing process of deep learning-based vision systems, leading to severe misclassifications of the trained model. Such attacks pose a critical threat to automated traffic signal recognition systems, particularly in autonomous vehicles and intelligent traffic management. Indeed, autonomous vehicles must be able to adhere to traffic rules. As such, they need a reliable and robust traffic sign classification system. By using the German Traffic Sign Recognition Benchmark dataset and by building upon previous versions of image scaling attacks, this work implements clean-label and dirty-label experiments. As a result, this paper finds stronger attack methods than previously reported with over 90% accuracy, which are, at the same time, more difficult to detect. More precisely, we propose a novel clean-label image scaling attack that requires only small local changes to a part of the image. Furthermore, we demonstrate the versatility of the image scaling attack and show how the image scaling attack method is universally compatible with other backdoor and evasion attacks, as the approach can be applied independently of the actual attack. Finally, the real-world risks of the image scaling attack on traffic sign classification models are shown by replacing the computer-generated training trigger with a physical object at test time.

Read the paper · More papers on PaperTik