Research presented at NDSS 2025 examines the realism of LiDAR spoofing attacks against autonomous driving vehicles. A related paper investigates physical-world adversarial attacks on commercial Traffic Sign Recognition (TSR) systems, finding that while some academic attacks can achieve 100% success against specific commercial TSR functionality, results are not generalizable. A key factor identified is a spatial memorization design in commercial TSR systems. The researchers introduce new attack success metrics to model this design's impact and uncover 7 novel observations, some challenging prior academic claims.
Sort: