Adversarial patches are getting harder to spot, and the newest ones look exactly like the road signs they hide beside. Researchers from Waseda University and Deloitte Tohmatsu Cyber built patches that suppress traffic light detection while masquerading as legitimate traffic signs.
The attack targets a realistic scenario: signs often sit next to traffic lights, so a patch that resembles a sign can be deployed without raising suspicion. The team optimized each patch with detection suppression loss, camouflage loss that makes it look like a real sign, expectation over transformation, and total variation loss to keep it physically printable.
In digital experiments the best patch removed traffic lights from the detector’s output 85% of the time. Physical-world tests with a traffic light mock-up hit 100% attack success in several conditions, showing the approach works outside simulation.
For autonomous driving, a hidden traffic light is not a cosmetic failure. A vehicle that fails to register a red signal at an intersection can roll into crossing traffic, and the patch’s camouflage makes it difficult for a human supervisor or downstream system to notice the interference.
The work was presented as a poster at VehicleSec 2026 in Baltimore. It joins a wave of sensor-targeting research from this year’s conference, where optical attacks on cameras, LiDAR, and now traffic light recognition all point to the same conclusion: perception pipelines need defenses that assume the physical world can be manipulated.