Still Camouflage, Moving Illusion: View-Induced Trajectory Manipulation in Autonomous Driving
This paper introduces a novel physical adversarial attack paradigm for autonomous driving where a static, passive camouflage on a parked vehicle exploits natural view-dependent appearance changes during relative motion to induce consistent feature drift, causing the victim system to infer incorrect trajectories and trigger unnecessary hard braking without requiring complex multi-view optimization or active intervention.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are driving a self-driving car. Your car's "eyes" are cameras, and its "brain" is a computer that constantly watches the road, guesses where other cars are going, and decides whether to speed up, slow down, or change lanes.
This paper introduces a new way to trick that computer brain. The researchers call it "Still Camouflage, Moving Illusion."
Here is the simple breakdown of how it works, using everyday analogies:
The Old Way vs. The New Way
- The Old Way (The "Chameleon" Problem): Previous attacks tried to put a special, high-tech sticker on a car that looked different from every angle. It was like trying to paint a chameleon that changes color perfectly no matter how you look at it. This was very hard to do because the computer had to be fooled from every possible viewpoint at once.
- The New Way (The "Magic Trick"): This paper says, "Why fight the changing angle? Let's use it!"
Imagine you are walking past a parked car. As you walk, the angle at which you see that car changes. The researchers put a static (non-moving) pattern on a parked car. Because the pattern is designed just right, as your self-driving car drives past, the pattern looks like it is shifting and moving, even though the car is perfectly still.
How the Illusion Works
Think of it like a flip-book animation.
- The Setup: A bad actor parks a car on the side of the road with a specific, weirdly painted camouflage on it.
- The Motion: Your self-driving car drives past this parked car.
- The Trick: As your car moves, the camera sees the parked car from slightly different angles every fraction of a second. The special paint job is designed so that these changing angles make the computer think the parked car is drifting sideways into your lane.
- The Result: The computer doesn't just see a "glitch" for one second. It sees a smooth, logical story: "Oh no, that parked car is slowly sliding into my path!"
The Consequence: The "Fake Cut-In"
Because the computer believes the parked car is moving into its lane (a "cut-in"), it panics.
- The Reaction: The self-driving car slams on the brakes (hard braking) or refuses to overtake the parked car, thinking it's unsafe.
- The Reality: The parked car never moved an inch. It was just a static piece of art that played a trick on the camera's perspective.
Why This is a Big Deal
The researchers tested this on a massive dataset of real driving videos (nuScenes). They found that:
- It works really well: In up to 87.5% of their test cases, the self-driving car was tricked into braking hard.
- It's easy to deploy: The attacker doesn't need a robot, a projector, or a computer to change the image. They just need to stick a piece of printed camouflage on a car and park it.
- It's hard to stop: Because the "movement" is created by the natural physics of driving past the car, it looks very real to the computer. It's not a sudden error; it's a smooth, believable lie.
The Bottom Line
This paper shows that self-driving cars are vulnerable to a new kind of trick: using the natural change in perspective as a weapon. By painting a static object correctly, an attacker can create a "ghost" motion that convinces a self-driving car to make dangerous or unnecessary decisions, all without the attacker ever touching the victim's car or the road.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.