
We are thrilled to announce that our conference paper entitled “Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems” has been accepted for publication in The 42nd Annual Computer Security Applications Conference (ACSAC 2026). This work is a fruit of our collaboration with Keio University and the University of California, Irvine. Congratulations to Tsuruoka-kun and kudos to the entire team!
In this work, we propose the Adversarial Retroreflective Patch (ARP), a novel attack vector against Traffic Sign Recognition (TSR) systems that combines the high deployability of physical patches with the stealth of light-based attacks. ARP leverages retroreflective materials that remain inconspicuous under ambient light and are activated only by the victim vehicle’s own headlights. Through physics-based retroreflection modeling and black-box attack optimization, ARP achieves over a 90% attack success rate in dynamic driving scenarios and 60% against commercial TSR systems, while a human user study confirms stealthiness comparable to benign signs. We also design DPR Shield, a defense built from two strategically placed polarized filters, which achieves ≥75% defense success rates for stop signs and speed limit signs.
Go Tsuruoka, Takami Sato, Qi Alfred Chen, Kazuki Nomoto, Ryunosuke Kobayashi, Yuna Tanaka, and Tatsuya Mori, "Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems." In Proc. of The 42nd Annual Computer Security Applications Conference (ACSAC 2026), Los Angeles, CA, USA, Dec 2026. (Acceptance rate=98/507=19.3%)