A state-approved digital license plate looks like a routine piece of vehicle hardware. New work from the University of Southern California argues it is also a ready-made tool for attacking the cameras that read plates.
The researchers built CIAplates, which weaponizes the fast-updating electrophoretic displays found on commercial digital plates. The screen shows a normal registration, yet carries carefully placed adversarial patterns covering less than 6.2 percent of the plate surface. Tested against OpenALPR, Plate Recognizer, and Qwen3-VL, the patterns defeated all three systems in lab and real-world trials.
Because the plate is mounted on a legitimate vehicle, the attack does not require forging documents or stickers. Operators of fleets, rentals, or personal cars with a compromised plate could slip past tolling, parking, and police scanning systems, and the display can swap patterns to fit each situation.
With under a tenth of the plate area given over to the perturbations, the plate still reads as authentic to a human observer. The authors also laid out countermeasures, among them detecting artifacts at the display layer and verifying plate readings against independent signals.
Digital plates are multiplying as states approve them, and they are internet-connected by design, an exposure researchers have repeatedly flagged. The study shows the same device can be turned against the enforcement infrastructure that was built to trust it.
The paper ran at the VehicleSec ’26 conference in Baltimore.