DARTS: Deceiving Autonomous Cars with Toxic Signs

  • 2018-02-18 19:39:28
  • Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, Prateek Mittal
  • 65

Abstract

Sign recognition is an integral part of autonomous cars. Anymisclassification of traffic signs can potentially lead to a multitude ofdisastrous consequences, ranging from a life-threatening accident to alarge-scale interruption of transportation services relying on autonomous cars.In this paper, we propose and examine realistic security attacks against signrecognition systems for Deceiving Autonomous caRs with Toxic Signs (we call theproposed attacks DARTS). Leveraging the concept of adversarial examples, we modify innocuoussigns/advertisements in the environment in such a way that they seem normal tohuman observers but are interpreted as the adversary's desired traffic sign byautonomous cars. Further, we pursue a fundamentally different perspective toattacking autonomous cars, motivated by the observation that the driver andvehicle-mounted camera see the environment from different angles (the cameracommonly sees the road with a higher angle, e.g., from top of the car). Wepropose a novel attack against vehicular sign recognition systems: we createsigns that change as they are viewed from different angles, and thus, can beinterpreted differently by the driver and sign recognition. We extensively evaluate the proposed attacks under various conditions:different distances, lighting conditions, and camera angles. We first examineour attacks virtually, i.e., we check if the digital images of toxic signs candeceive the sign recognition system. Further, we investigate the effectivenessof attacks in real-world settings: we print toxic signs, install them in theenvironment, capture videos using a vehicle-mounted camera, and process themusing our sign recognition pipeline.

 

Quick Read (beta)

loading the full paper ...