A paper got accepted!

We are thrilled to announce that our conference paper entitled “Hidden in Plain Signs: Realistic Sticker Attacks on Production Traffic Sign Recognition Systems” has been accepted for publication in The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027). This work is a fruit of our international collaboration with Politecnico di Milano. The research theme was conceived during the sabbatical stay of Prof. Mori at Politecnico di Milano in 2024. Congratulations to Bruzzese-kun and kudos to the entire team!

Traffic Sign Recognition (TSR) is a safety-critical component widely deployed in modern cars, while stickers and other artistic modifications on traffic signs have become commonplace in urban environments and are rarely perceived as suspicious. This coexistence creates a realistic attack surface. Existing adversarial attacks against TSR are rarely validated on production vehicles, often require expensive or conspicuous equipment, and typically target a narrow range of sign categories. To address this gap, we propose a black-box adversarial pipeline that leverages realistic urban sticker designs to induce misclassification and disappearance in neural-network-based TSR systems. Our method identifies sensitive regions on a target sign, selects stickers from a pre-defined pool, and iteratively optimizes their placement using an ensemble of state-of-the-art surrogate detectors within a high-fidelity rendering engine that simulates diverse driving conditions. We evaluate our approach using two distinct training datasets targeting 11 sign categories, and validate the resulting attacks through extensive real-world experiments on five commercial vehicles equipped with TSR systems. Across these vehicles, the proposed approach induces incorrect detections in 62% of cases on average, significantly outperforming state-of-the-art baselines, which reach only 19%. A human perception survey with over 100 participants further suggests that our perturbations are perceived as plausible urban artifacts, ensuring operational stealth. These findings demonstrate that adversarial examples extend beyond controlled laboratory settings and pose a credible, concrete, low-cost threat to real-world driving safety.

Luigi Bruzzese, Francesco Panebianco, Tatsuya Mori, Michele Carminati, Stefano Zanero, and Stefano Longari, "Hidden in Plain Signs: Realistic Sticker Attacks on Production Traffic Sign Recognition Systems." In Proc. of The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027), Seoul, Republic of Korea, Mar 2027.

A paper got accepted!

We are thrilled to announce that our conference paper entitled “Privacy in Motion: Role Perspectives on Connected Vehicle Data Collection” has been accepted for publication in The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027). Congratulations to Moore-kun and kudos to the entire team!

Connected vehicles have become data-intensive platforms that collect vast amounts of personal information not only from drivers but also from passengers and even nearby pedestrians, yet privacy protections and public understanding have not kept pace. In this work, we bridge the gap between what manufacturers disclose and how people perceive these practices through two complementary studies. In Study 1, we analyze the U.S. privacy policies of 17 major vehicle manufacturers, revealing extensive data collection, fragmented disclosures, and limited user control over third-party sharing. In Study 2, we survey 437 participants from the U.S., Germany, and China to examine comfort, expectations, and willingness to share data across the roles of driver, passenger, and pedestrian. We find that biometric and commercial data are perceived as particularly sensitive, that comfort with data collection varies significantly by role, and that a majority of users are willing to opt out of data collection. The results highlight a substantial disconnect between industry practices and public understanding, calling for clearer, role-aware, and culturally sensitive transparency mechanisms.

Lachlan Moore, Yinan Zhao, Rei Yamagishi, Allan Wirth, and Tatsuya Mori, "Privacy in Motion: Role Perspectives on Connected Vehicle Data Collection." In Proc. of The 34th ISOC Network and Distributed System Security Symposium (NDSS 2027), Seoul, Republic of Korea, Mar 2027.

研究室夏合宿

軽井沢セミナーハウスでの研究室夏合宿 2026 の集合写真(アニメ風)
集合写真(アニメ風に加工)

9/11-13に軽井沢セミナーハウスにて研究室合宿を行いました!

合宿ではB4、M2の卒論・修論に向けた研究進捗発表に加え、ソフトボールなどのレクリエーションを通じてメンバ同士の親睦を深めました。

研究室夏合宿 2026 でのソフトボールの集合写真(アニメ風)
ソフトボール(アニメ風に加工)

A paper got accepted!

We are thrilled to announce that our conference paper entitled “Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems” has been accepted for publication in The 42nd Annual Computer Security Applications Conference (ACSAC 2026). This work is a fruit of our collaboration with Keio University and the University of California, Irvine. Congratulations to Tsuruoka-kun and kudos to the entire team!

In this work, we propose the Adversarial Retroreflective Patch (ARP), a novel attack vector against Traffic Sign Recognition (TSR) systems that combines the high deployability of physical patches with the stealth of light-based attacks. ARP leverages retroreflective materials that remain inconspicuous under ambient light and are activated only by the victim vehicle’s own headlights. Through physics-based retroreflection modeling and black-box attack optimization, ARP achieves over a 90% attack success rate in dynamic driving scenarios and 60% against commercial TSR systems, while a human user study confirms stealthiness comparable to benign signs. We also design DPR Shield, a defense built from two strategically placed polarized filters, which achieves ≥75% defense success rates for stop signs and speed limit signs.

Go Tsuruoka, Takami Sato, Qi Alfred Chen, Kazuki Nomoto, Ryunosuke Kobayashi, Yuna Tanaka, and Tatsuya Mori, "Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems." In Proc. of The 42nd Annual Computer Security Applications Conference (ACSAC 2026), Los Angeles, CA, USA, Dec 2026. (Acceptance rate=98/507=19.3%)