GhostStripe attack haunts self-driving cars by making them ignore road signs
theregister.com
theregister.com
My take: Maybe the machine vision of recent self-driving software has become harder to fool than human vision? Human vision is remarkably easy to fool. See https://www.ritsumei.ac.jp/~akitaoka/index-e.html and https://en.wikipedia.org/wiki/Optical_illusion for example.
Luckily for all of us, there are no smart people laboring all day long in a lab trying to find new ways to fool human drivers into doing dumb, dangerous things on the road. Human drivers already do that on their own -- no tricks or illusions are necessary.
We don't make things where you need to pick up on small differences in alignment or color, and the illusions that cause motion have to be very big to be a distraction.
Illusions aren't even necessary with human drivers, many of whom are shockingly bad -- look around next time you're on the road.
The type of issue in the article needs signs that seem to be working to humans, but are secretly failing. Not just "oh they put up too much in a single spot" or "there are two signs that contradict each other".
I'm honestly not worried about cars being occasionally unable to read a sign. In fact, I know my car already knows where the signs are and what they say before it sees them. I'll always be more scared of human drivers: computers can't get distracted peeling a banana.
It’s not just about are they harder to fool than humans but to find the conditions under which they are fooled which are often can be very different.
This is needed to both identify edge cases where these patterns can appear in the wild and to make the systems resistant to outside interference.
LED wall displays are becoming more and more common, I’ve already seen ones that cause annoying reflections on road signs as they turn the retro-reflectors into a disco ball.
I’ve skimmed through the paper and I can’t understand how likely this to occur unintentionally in the wild but their strobing pattern doesn’t seem to be that aggressive so a combination of the animation itself on the sign and LED strobing due to PWM control can quite possibly cause similar interference.
The camera is easy enough to make inconspicuous. The LEDs and processor can be in a regular light enclosure. You just need to find a good excuse for the sign to be illuminated.
When I was 1yo my dad was driving on the highway, got distracted, and ended up on a highway portion that was under construction. He was driving full speed, when he saw a barrier, late enough that he swung the steering wheel to avoid the barrier, and ended up driving on 2 wheels before the car felt back and stopped. No baby at the time, my grand-ma was holding me in the back (good old years when cars were lighter and less secure).
Random things can happen on the road, including wrong signage. As long as the car can assess the current state and graceful transition to a safe spot, it should be fine to throw at them random signage.
Who knows what context besides the actual sign itself is used to determine where to stop, for example. Maybe the line on the road, maybe map data, maybe the pole or the appearance of the intersection itself. Maybe the vision system is resilient to this attack in some other way. Maybe the system detects this state and has a fail-safe behavior.
Anyway, interesting to research, but unclear how it affects production systems.
How do non-camera based systems (lidar etc) get road sign information? I would expect with cameras...?
Lidar as I was told to use it would be in conjunction with a database of way points like signs, so the trouble would be knowing if the sign was updated.
I don't know how it determines the existence of a sign. It might be visual, lidar, or a combination.
I think I drew a faulty and unstated inference. Feel free to disregard.
Is this attack actually in anybody's threat model?
There are people out there who don't want autonomous vehicles on the streets. Whatever their reasoning is isn't particularly relevant, because if someone wants to accomplish a given end, this has potential as an attack vector.
A cone is not an example of a dangerous attack.
It's not like cones cause the cars to jam the accelerator.
- my car is haunted by visions
- my computer needs a pep talk to generate some work
- my other computer gets upset when I'm wearing sunglasses because it doesn't recognize me
- My car is stuck because it cannot see the road lines through the snow.
- The power is out and my car cannot handle a broken traffic light.
- My car doesn't like tunnels because there is no cell coverage inside.
- The lollipop guy dropped his sign and my car treated it like the start of a drag race.
- All traffic ordered stopped after Fast and Furious 19 was accidentally used as training footage by the AI.