The Spectrum Strikes Back: Infrared POV Attacks on Traffic Sign Classification Michael Kühr∗ , Mevlüt Yildirim∗ , Maximilian Luedecke, Mohammad Hamad, Sebastian Steinhorst
arXiv:2606.30153v1 [cs.CR] 29 Jun 2026
TUM School of Computation, Information and Technology, Technical University of Munich, Germany {firstname.lastname}@tum.de
Abstract—Traffic sign classification is a crucial task for autonomous vehicles, and numerous attacks against it have been identified. A majority of physical adversarial attacks involve attaching patches to traffic signs or projecting perturbations on them. While they demonstrate high effectiveness, they are perceptible to humans. At the same time, light-based attacks outside the human visible spectrum are known but have limitations in their dynamic adaptability. We propose a persistence-of-visionbased attack that operates in the near-infrared light spectrum. With the possibility of showing dynamic, remotely triggered content, this allows a stealthy physical adversarial attack against traffic sign classification. By identifying the optimal position through digital simulation, we conduct extensive real-world evaluations using two different traffic signs, 12 machine learning models from different families, multiple distances up to 20 meters, and varying illumination conditions. Our evaluation shows high attack success rates across our test scenarios. We propose nearinfrared cutoff filters and a software-based detection mechanism as defenses, and tackle limitations of the near-infrared persistence of vision display by prototyping a human-visible RGB version of it.
I. I NTRODUCTION
Attack Design
STOP
Digital Simulation
STOP
IR POV Display
Real-World Deployment STOP
Fig. 1: Infrared-based persistence of vision displays are a physical adversarial attack that can target traffic sign classification while being stealthy to humans. We identify the optimal placement through a digital simulation to ensure high attack success. As a result, traffic sign classifiers will misclassify the sign.
While autonomous vehicles are becoming reality [1], [2], the attack surface of such cars increases with the integration of perception sensors [3], [4], [5], such as LiDARs or cameras. Among these sensors, cameras are often used as a single source of information for tasks like traffic sign detection, lane detection, or traffic light recognition [4], [6]. As a result, camera-based perception has become a critical target for attacks. scenarios [16] and are being researched by the automotive Specifically, physical adversarial attacks have been investigated industry for use in adverse environmental conditions [17]. by different research communities [7], [8], [9], [10]. This makes near-infrared attacks both practical and safetyThese attacks against camera-based perception have been critical. However, existing infrared-based physical attacks face explored using a wide range of techniques, including printed important limitations: They rely on static perturbations or stickers on traffic signs [11], projector-based attacks [12], or continuous light emission [15] and often require high-power light-based attacks in the human-visible [13] and invisible laser beams [14]. As a result, these attacks lack flexibility, do spectrum [14], [15]. Such attacks target the Machine Learning not support selective triggering, and offer limited adaptability (ML) models that are used in autonomous vehicles to perform once deployed, which restricts their practicality in real-world tasks such as traffic sign detection. Among them, attacks settings. operating outside the human-visible spectrum are particularly Motivated by the limitations of existing physical adversarial concerning, as they show high stealthiness and are difficult or attacks in Table I, we introduce a new physical adversarial impossible to detect by humans [15]. attack based on a dynamically reconfigurable and triggerable Previous studies identified that autonomous vehicles can infrared light source. As shown in Figure 1, we realize this perceive light sources in this infrared spectrum [14], [15]. attack using a persistence of vision (POV) display that operates Additionally, infrared-sensitive cameras are already used in in the near-infrared spectrum and can display dynamic, remotely driver assistance systems to increase perception in nighttime triggered adversarial patterns. Unlike prior infrared attacks, ∗ Both authors contributed equally to this work. our POV display does not rely on high-power lasers [14]
TABLE I: Comparison of existing physical attacks with our POV display attack. Attack Dynamic RP2 [11] ✗ SLAP [12] ✓ AdvLB [13] ✗ ILR attack [14] ✗ ICSL Attack [15] ✗ Ours (POV display) ✓
Triggered ✗ ✓ ✓ ✓ ✓ ✓
Stealth ✗ ✗ ✗ ✓ ✓ ✓
Remote ✓ ✓ ✓ ✓ ✓ ✓
•
Transferable ✗ ✓ ✗ ✓ ✗ ✓
evaluate our attack and demonstrate its effectiveness. Defense against our attack, including evaluation: We propose defense and detection methods to protect traffic sign classification models against our POV display attack. II. BACKGROUND
This section introduces background information on infrared light and the POV effect on which our attack is based.
but instead operates using commercially available infrared light-emitting diodes (LEDs) [18]. By leveraging fast rotation, we exploit the POV mechanism, and our POV display shows spatially structured infrared patterns without relying on static physical patches. This design enables three key capabilities that distinguish our attack from prior work: (i) the attack can display dynamically reconfigurable content, allowing adaptation to different target assets and models without redeployment; (ii) it can be selectively activated by controlling the infrared LEDs while maintaining rotation, enabling the adversarial effect without permanently altering the appearance of the traffic sign, and (iii) it remains highly stealthy, as the emitted infrared light is invisible to human observers and the rotating POV display appears transparent when inactive. These properties differentiate our approach from static physical attacks such as stickers [11] and from human-visible projections [12]. To deploy this attack reliably, we provide a digital simulation to identify the optimal placement of freely configurable content in the POV display on a traffic sign. By applying different transformations [19] within our digital simulation, we ensure that our attack shows high robustness under different physical conditions, such as varying distances and illumination conditions. This simulation-driven placement optimization is critical for real-world effectiveness. Guided by the simulation results, we conduct extensive real-world evaluations across different traffic signs, POV display sizes, illumination conditions, and 12 ML models spanning multiple architectures and training datasets, demonstrating high attack success rates. To mitigate this threat, we evaluate both a hardware-based defense using near-infrared cutoff filters and a software-based detection mechanism that exploits sensor-specific spectral artifacts. Finally, we discuss the broader implications of POVbased attacks and show that similar threats can also arise when deploying POV displays in the human-visible spectrum. In summary, our contributions are: • Reconfigurable and triggerable infrared attack: We present a physical adversarial infrared POV display attack that enables high stealthiness and dynamically reconfigurable, remotely triggerable perturbations against camerabased perception. • Digital simulation of our POV display attack: We digitally simulate of our attack to identify the optimal positioning of the POV display. • Extensive real-world evaluation: By performing physical tests with varying distances, displayed content, POV display sizes, and ML models, we comprehensively
A. Infrared Characteristics of Cameras Typical Complementary Metal-Oxide-Semiconductor (CMOS) image sensors that are used in camera-based perception pipelines in autonomous vehicles are sensitive to near-infrared light with a wavelength of 780nm to 1000nm [20], [21], [22]. This wavelength is already outside the human-visible spectrum, which goes up to approximately 760nm [20], making it not perceivable by humans. At the same time, different attacks against camera-based perception are known that exploit the sensitivity of image sensors to infrared light, not only in autonomous vehicles [14], [15], but also in face detection [23], [24]. Based on the sensor-specific spectral sensitivity, near-infrared light is perceived either as red, purple, or magenta [14], [15]. B. Persistence of Vision The so-called POV effect tricks the human visual perception system [25], [26] and is colloquially referred to as "holograms" when used in POV displays. These POV displays typically consist of a rotating fan, equipped with precisely controlled LEDs. At high rotation speeds, they trick the human visual information-processing system into a circle-shaped display. Such POV displays in the human-visible light spectrum are typically found for advertising purposes or at show events. A similar effect is also observable with cameras: If the exposure time texp is larger than or equal to the rotational speed frot of the POV display, the complete displayed content will be captured. With smaller exposure times, only fractions of the displayed content are available. This leads to the exposure time constraint of Equation 1. texp ≥
1 frot
(1)
If this time constraint is fulfilled and the POV display shows static content, artifacts coming from the rolling-shutter effect [22] of CMOS image sensors can be mostly neglected, since the complete displayed content will be captured. Figure 2 shows the effect of the time constraint from Equation 1 with different scenarios. III. T HREAT M ODEL In this section, we explain our attack goal and requirements, as well as the necessary knowledge and capabilities of the attacker.
2
1 (a) texp < frot
1 (b) texp ≈ frot
an infrared cutoff filter. Such generic system knowledge can be obtained from public sources or reference cameras and is similar to assumptions of other physical adversarial attacks [27], [28], [14], [29]. As specified in our requirements, the attacker does not need to be physically present during the attack execution but only for the attack preparation, namely for mounting the POV display at the targeted traffic sign. This allows the attack to not raise any suspicion by avoiding the permanent physical presence of the attacker. Lastly, we assume an attacker who has basic knowledge of electrical engineering and access to low-cost commodity hardware (e.g., infrared LEDs, a microcontroller, and a power supply). While POV displays in the human-visible light spectrum are commercially available, infrared ones have to be crafted individually, but can be done with limited knowledge and resources.
1 (c) texp > frot
Fig. 2: A two-blade POV display in front of a stop sign, visualizing the exposure time constraint when showing a full 1 circle. If texp < frot , the pattern cannot be captured completely, 1 1 if texp = frot , the pattern is captured fully, and if texp > frot , artifacts such as brighter areas due to overlaps can occur.
A. Attack Goal and Requirements
The goal of our attack are misclassifications of ML-based image classifiers, specifically traffic sign classification models, although we will also test with generically trained image IV. ATTACK D ESIGN classification models. Following the terminology of Zhu et al. [27], we will consider an Altering Attack. To achieve this In this section, we will introduce the requirements for our goal, our attack needs to fulfill the following requirements: initial prototype of a near-infrared POV display and present • Stealth: A key requirement of our attack is the stealthiness in detail the steps of our attack based on three stages that are against human vision. Therefore, we use LEDs in the near- depicted in Figure 3. Our physical attack is based on a digital infrared spectrum. In contrast to existing attacks in this simulation (⃝) II that requires some initially captured real-world spectrum [14], [24], we do not operate with laser diodes ground-truth images (⃝) I and results in an optimal placement that can harm the human eye, but with low-power LEDs position for the deployment in the real world (⃝). III that are invisible to human perception. • Dynamic: To be effective against different target assets A. Infrared POV Display Requirements and different ML models, our POV display must be able We will present our two-blade near-infrared POV display to to show dynamic adaptable content. capture ground-truth images that serve as a basis for our digital • Triggered: In contrast to printed physical adversarial simulation. While POV displays in the human-visible light patches [11], our attack can be triggered to be effective spectrum are used for entertainment or advertising purposes against only specific vehicles. By only switching off the and are readily available, to the best of our knowledge, nearLEDs of our POV display, but not the rotation, the traffic infrared POV displays are not commercially available. Since sign is still visible, with only negligible occlusion. the near-infrared spectrum is an essential factor in creating a • Remote: Our attack does not require physical access to stealth attack, we craft a prototypical POV display hardware. the target vehicle, but the POV display is attached to an Further details on the configuration and software settings will asset, e.g., a traffic sign, and can be controled remotely be explained later in Section V. or without manual intervention. The most important aspect in the design of a near-infrared • Optimized Position: While the displayed content and POV display is the selection of infrared LEDs. The sensitivity position of the POV display can be freely chosen, we of an image sensor to a specific wavelength is defined by optimize our attack for the optimal position that shows the quantum efficiency [22], [30]. While the exact quantum the highest effect in our digital simulation. efficiency curve depends on the used image sensor in the Our attack targets illumination conditions, under which camera, CMOS-based color image sensors typically show a Equation 1 is fulfilled. This will result in a limited application local maximum between approx. 800nm to 900nm [31], [32], use case of dawn or nighttime attacks for typical cameras [33]. This requirement limits the search for suitable LEDs to and a reasonable rotation speed of the POV display. this wavelength spectrum. In our prototypical implementation, Additionally, this limitation allows the use of low-power we, therefore, use near-infrared LEDs with a wavelength of infrared LEDs that are commercially available, instead of 860nm [18]. These LEDs can be mounted on a printed circuit expensive and potentially dangerous laser diodes. board (PCB), attached to a small electric motor. Different B. Attacker Knowledge and Capabilities patterns can then be visualized by using pulse-width modulation (PWM) to create rotation-symmetric circular sectors. We assume an attacker without prior knowledge of the ML model internal weights ("black-box attack") but with general awareness of the system. Specifically, the attacker needs to know whether the targeted vehicle uses cameras without
I Digital Simulation Ground Truth B. ⃝
Our digital simulation of the POV attack requires two inputs:
3
OI Digital Simulation Ground Truth 30
squared crop
STOP
Benign Traffic Sign
𝐼
STOP
STOP STOP STOP
Transform 𝐼 ★ T1
Grid 𝐺
One Image
⊕
★ } { 𝐼 ★ ⊕ 𝐼pov Transform
remove backgr. Rotating POV display
II Digital Simulation O
𝑛max Images
(𝑛) ) (𝐼pov
Transform T2
★ 𝐼pov
STOP STOP STOP
T3
...
ML Model 1
Σ
ML Model 2
Σ
ML Model 3
Σ
Batches 𝐵 of transformed
adversarial images
Shapes 𝑆, Rotations Φ
Shape-specific heatmaps 𝐻 with optimal positions
III Real-World Deployment O STOP
STOP
POV display active
POV display inactive
Fig. 3: Overview of our POV display-based attack. The complete process consists of three steps: The data captured in the I digital simulation ground truth serves as input to identify the optimal placement of the POV display in a ⃝ II digital ⃝ III deploying the identified position in the real-world, and activating the infrared POV display, ML-based simulation. By ⃝ image classification models can be tricked while being invisible to humans. Algorithm 1 Digital simulation from benign traffic-sign image (1:n ) I and a nmax -frame POV display sequence Ipov max .
1) A single benign image of a traffic sign I which shows the traffic sign that shall be attacked. 2) A sequence of nmax images of a rotating infrared POV display with a given diameter, displaying a full circle (n) max (Ipov )nn=1 , acting as a basis for the digitally simulated POV display. For our prototypical implementation, we will select nmax = 10.
max 1: Input: 𝐼, (𝐼pov ) 𝑛=1 , grid 𝐺 = {0:𝑚} × {0:𝑚}, shapes 𝑆, rotations Φ, ML model
(𝑛) 𝑛
𝐹 (·) 2: Output: Heatmap: 𝐻 (𝑥, 𝑦) for all (𝑥, 𝑦) ∈ 𝐺 3: Init: 𝐻 [(𝑥, 𝑦) ∈ 𝐺] ← 0 (1:𝑛 ) (𝑛) 𝑛max 4: for all 𝐼pov max ∈ (𝐼pov ) 𝑛=1 do 5: for (𝑥, 𝑦) ∈ 𝐺 do 6: 𝐵←∅ 7: for (𝑠, 𝜑) ∈ 𝑆 × Φ do 8: 𝐼 ★ ← T1 (𝐼; 𝑠, 𝜑, 𝑥, 𝑦); ★ ← T (𝐼 (𝑛) ; 𝑠, 𝜑, 𝑥, 𝑦); 9: 𝐼pov 2 pov ★ }) 10: 𝐵 ← 𝐵 ∪ T3 ({ 𝐼 ★ ⊕ 𝐼pov 11: end for 12: 𝐿ˆ ← 𝐹 (𝐵) 13: for all ℓˆ ∈ 𝐿ˆ ≠ street sign do 14: 𝐻 [𝑥, 𝑦] ← 𝐻 [𝑥, 𝑦] + 1 15: end for 16: end for 17: end for
Both inputs are optimally captured on a neutral background, such as a black wall. Afterwards, we crop the image of the traffic sign to result in a square aspect ratio required by the targeted image classification model. From the nmax images of the rotating infrared POV display, we remove the background by setting it transparent, showing only the full circle. While our digital simulation can also work with only a single image of a POV display, multiple consecutive images compensate for flickering artifacts and changing light intensities due to potentially overlapping regions in the POV display, as shown in Figure 2c. This makes the digital simulation more robust.
// Random transform T1 // Random transform T2 // Random transform T3 // top labels ℓˆ of 𝐹 (·)
that can easily be deployed in the real world. Different numbers of sectors can be visualized with a two-blade POV display. II Digital Simulation C. ⃝ Additionally, we create a configurable number of rotated The goal of the digital simulation is the identification of the circular sectors Φ to compensate for the dynamic changes of optimal position of the POV display on the targeted traffic sign the rotating POV display. While the ground-truth images from I are required for each new attack, the grid, shape definition, to ensure high attack success for the ML model under test. We ⃝ I ⃝ use the prepared ground truth captured in to create model- and rotated circular sectors are configurable parameters that specific heatmaps that visualize the most successful attack can be fixed once by the attacker. positions. A detailed description is available in Algorithm 1. For both the benign traffic sign and the different shapes of In a first step, we apply a grid G = {0:m} × {0:m} on the the POV display, we apply transformations T1 , T2 individually traffic sign where each grid point marks a possible placement (lines 8 and 9), similar to existing approaches of adversarial option of the POV display. Additionally, we create different attacks [19]. After overlaying the different shapes on the shapes S, representing rotation-symmetric circular sectors that grid positions of the benign traffic sign, we apply additional ⋆ the POV display can display with low-level control hardware transformations T3 to the combined resulting images I ⋆ ⊕ Ipov
4
TABLE II: List of available transformations, including their value range and the stage they are applied. Brightness transformations are based on the YCbCr color model. Transformation Brightness Scale Perspective
Stage
Parameter
Possible Range
Traffic sign POV display POV display Combined image
∆Y in DN ∆Y in DN Factor Factor Tilthorizontal in ◦ Tiltvertical in ◦ Perspective Factor Extension Factor Fade Strength Crop Factor
−50 . . . 50 20 . . . 50 0.3 . . . 1.5 0.5 . . . 1.2 5 . . . 30 5 . . . 30 0.05 . . . 0.10 1.2 . . . 1.5 0.2 . . . 0.4 0.01 . . . 0.05
Combined image
Glare
POV display
Center Crop
Combined image
confidence, the confidence of the class "street sign", and the respective configuration of our digital simulation, including the applied transformation parameters and shape configuration. We aggregate the number of misclassified frames for each grid position based on sequential frames, applied rotations of the circular sectors, and applied transformations, resulting in a two-dimensional heatmap H that can be overlayed on the original image to identify the optimal placement position of the POV display (line 14). III Real-World Deployment D. ⃝
The final stage of the attack is the deployment of the infrared POV display in the real world by placing it at the position of the resulting heatmap H from the digital simulation. By using PWM, circular sectors as shown in Figures 4b and 4c can be achieved even with low-cost commodity LEDs. With the transformations applied in the digital simulation, the resulting optimal position already compensates possible deviations of environmental conditions during deployment.
(a) Full POV dis- (b) Two circular sec- (c) Six circular secplay without transfor- tors without transfor- tors without transformations mations mations
V. E VALUATION We evaluate both the digitally simulated images and the realworld deployment of the POV display. In our initial overview, we will define our deployment setup and the attack success metrics. A. Overview
Hardware Setup: In contrast to existing infrared attacks [14], [15], we do not work with highly directed infrared lasers but commercially available near-infrared LEDs with a wavelength of 860nm [18], thus making it stealth and less harmful for the Fig. 4: Example images from the digital simulation. All images human eye. All LEDs are soldered in parallel on a PCB to show the overlay of the captured POV display images and the limit the required voltage for operation. The total diameter of benign traffic sign with different transformations. our POV display is 30cm, but larger and smaller hardware is possible. For selected evaluations, we also test POV displays with diameters of 10cm and 20cm. We use a direct current (line 10). Table II shows the various available transformation motor [34], operated at 12V, to rotate the PCBs with the LEDs. parameters, including their possible values, and where they While different motors can be used, it is important to note that are applied. The exact values are randomly sampled from the timing constraints of Equation 1 must be fulfilled, even the specified range. By applying these randomly selected with the PCBs and LEDs attached. For the power transmission transformations with randomly sampled values, the resulting of the stationary power supply to the rotating LEDs, we use placement options in the digital simulation are more robust slip rings. Figure 5a shows the developed prototype of our to environmental factors such as different illumination or near-infrared POV display with a diameter of 30cm that we changing perspectives that occur in the real world. Additionally, also use in our evaluation. POV display-specific parameters, such as the scaling, can Additionally, we show a 15cm version of the near-infrared help to identify the necessary size of POV displays for real- POV display that allows for portable deployment. It can be world deployment. A visual depiction of some representative directly attached to traffic signs without the need for an transformations is available in Figure 4. external mounting. We use a 3D-printed body that contains the The resulting batches B of transformed, digitally simulated, motor [35] and blades with the near-infrared LEDs [18]. This adversarial images serve as an input to one or multiple targeted body is connected through neodymium magnets on both sides ML image classifiers F (·) (line 12). Since we do not apply of the traffic sign, since the sign itself is not magnetic. The backpropagation and do not work with the model’s internal wires for the power supply can be reduced to a minimum by weights or architecture, our attack is a black-box attack. only leading to the back of the traffic sign, where a battery For each digitally simulated adversarial image, we run the can be hidden. With this setup, the attacker can deploy and ML model inference and store only the top label ℓ̂, the top remove the POV display very fast to ensure high stealthiness. (d) Full POV display (e) Full POV display (f) Full POV display with crop transforma- with brightness trans- with two perspective tion formation transformations
5
TABLE III: List of models and their respective training datasets used for evaluation of the physical deployment of our attack. Training Dataset
(a) POV display (b) POV display with (c) Mobile POV diswith 30cm diameter 15cm diameter for mo- play with 15cm diammounted on a tripod bile deployment eter on a traffic sign
GTSRB [37]
Fig. 5: Prototypical hardware setups of a near-infrared POV display. The LEDs are soldered with their respective resistors on a PCB, which is attached to the motor. The portable POV display allows for stealth deployment, if the LEDs are switched off and the fan is rotating.
ImageNet [41] COCO [42]
Figures 5b and 5c show the portable version of our POV display and highlight its stealthiness if the LEDs are off. As a camera, we select an embedded camera module featuring a Sony IMX708 image sensor with no infrared filter [36]. This camera module has a wide field of view and comparable features, including high dynamic range imaging, to those of real automotive image sensors.
Model ConvNeXt small [40] ConvNeXt base [40] ResNet-50 [39] ResNet-152 [39] ResNext-101 [43] VGG16 [44] ViT-32 [45] ConvNeXt base [40] ResNet-152 [39] ResNet-50 [39] YOLO11 [46] Faster R-CNN [47]
pretrained models deployed by PyTorch1 . Additionally, we analyze the transferability of our attack across 12 image classification and detection models, as shown in Table III. We analyze the transferability of the stop sign using both GTSRBand pretrained versions of the ML models (ImageNet [41], or COCO [42]). However, we analyze the transferability of the speed limit sign only against the GTSRB-trained versions, Targeted Traffic Signs: Since our attack operates at the since only these models can recognize this specific sign. For all sensor level by displaying controlled infrared patterns received models, we will show benign performance with a switched-off by the camera, it is sign-agnostic and does not rely on the POV display because the results are similar to those without semantic properties of individual traffic signs. For evaluation, any POV display. we focus on the following traffic signs: Attack Success: As defined in our threat model, the goal 1) A stop sign, as this sign can be classified/detected by all of our attack is to cause misclassifications in ML-based image evaluated ML models. classification models. At the same time, our POV display can 2) A German 30km/h speed limit sign, as German Traf- exhibit temporal artifacts, such as non-perfectly synchronized fic Sign Recognition Benchmark (GTSRB)-trained ML PWM signals and motor speeds. For this reason, we evaluate models can classify this sign specifically. Additionally, it the physical deployment of our attack over video durations represents a differently sized and shaped traffic sign. that are sufficient to observe periodic temporal artifacts. In Both signs are utilized in widely used benchmarks and prior our experiment, we used 30-second video snippets. We extract physical adversarial attack studies [37], [11] and represent each image from the video and run it through the respective safety-critical traffic signs with distinct visual characteristics, image classification model, defining the attack success rate enabling controlled and reproducible evaluation. (ASR) as the ratio of misclassified frames within each snippet, Perception-Level Evaluation: We aim to evaluate the impact consistent with existing approaches of sticker-based adversarial of our POV display attack at the perception level and, therefore, attacks [11]. We emphasize that this definition of the ASR do not perform an end-to-end validation on a specific commer- already accounts for real-world distortions that may arise during cial vehicle. End-to-end autonomy stacks differ substantially actual deployment. across platforms in their planning and control logic, making B. Digital Test vehicle-level behavior highly implementation-dependent [38]. We perform digital tests for both the stop sign and the By focusing on perception models, we isolate the effect of German 30km/h speed limit sign using a 30cm POV display. the attack on a core component shared across autonomous Since a 30 cm POV display covers a large fraction of the driving systems while still mimicking an approaching vehicle 30km/h speed limit sign, we further evaluate POV displays through physical evaluations at distances up to 20m. Prior with diameters of 10cm and 20cm to study the feasibility of work has shown that perception-level attacks can propagate to smaller, even stealthier, and easier-to-deploy devices. For both system-level safety risks [38]. I and ⃝ II from the attack design of traffic signs, we run steps ⃝ We will evaluate all steps of the attack design from Figure 3 with two representative shapes, namely a full circle Section IV independently for two different ML-based image ( ) and two circular sectors ( ), which can be displayed classification models: (i) ResNet-50 [39], and (ii) Conv- with the PWM controlled LEDs. As defined in our overview, NeXt small [40]. Both models were trained on the GTSRB 1 https://github.com/pytorch/vision/tree/main/references/classification dataset [37], using the same training parameters as the
6
(a) Heatmaps for the stop sign. From left to right: (i) ResNet-50, full circle; (ii) ResNet-50, two sectors; (iii) ConvNeXt small, full circle, and (iv) ConvNeXt small, two sectors.
(a) Examples for the stop sign. From left to right: (i) ResNet-50, full circle; (ii) ResNet-50, two sectors; (iii) ConvNeXt small, full circle, and (iv) ConvNeXt small, two sectors.
(b) Heatmaps for the 30km/h speed limit sign. From left to right: (i) ResNet-50, full circle; (ii) ResNet-50, two sectors; (iii) ConvNeXt small, full circle, and (iv) ConvNeXt small, two sectors.
(b) Examples for the 30km/h speed limit sign. From left to right: (i) ResNet-50, full circle; (ii) ResNet-50, two sectors; (iii) ConvNeXt small, full circle, and (iv) ConvNeXt small, two sectors.
(c) Heatmaps for the smaller POV display for ResNet-50. From left to right: (i) 10cm, full circle; (ii) 10cm, two sectors; (iii) 20cm, full circle, and (iv) 20cm, two sectors.
(c) Examples for smaller POV display. From left to right: (i) 10cm, full circle; (ii) 10cm, two sectors; (iii) 20cm, full circle, and (iv) 20cm, two sectors.
Fig. 6: Heatmaps for the stop sign (upper row), and the 30km/h speed limit sign (middle row) for two different shapes, and two ML models each. The lower row shows the heat maps for two different POV display sizes with ResNet-50 GTSRB.
Fig. 7: Examples of our digitally simulated POV display. The positions are derived from the heatmaps of Figure 6.
30km/h Speed Limit Sign: Similarly, we run the digital simulation for a German 30km/h speed limit sign with the same shapes and the same ML models with Figure 6b depicting the resulting heatmaps and Figure 7b showing the digitally simulated POV display on the highest-ranked positions. In comparison to the stop sign, the heatmaps of the different shapes show a higher similarity, while the different ML models show a clear difference in their position. Similar to our previous test with the stop sign, Table IV contains the top misclassifications. Especially misclassifications of a different speed limit can lead to potentially safety-critical behaviour in real-world scenarios. 30km/h Speed Limit Sign with smaller POV display: As previously defined, we also run the digital simulation with 10cm and 20cm POV displays. We run the digital simulation for the same shapes as in the previous tests, resulting in the heatmaps shown in Figure 6c. For all smaller POV display sizes that are shown in Figure 7c, this results in the highest number of misclassifications as a "Speed Limit 50." This digital simulation of smaller POV displays shows that even more stealthy versions of our attack are possible and cause misclassifications.
TABLE IV: Top three labels of misclassified, digitally simulated images for the 30cm POV display for a stop sign and 30km/h speed limit sign. For ConvNeXt small at the stop sign, a maximum of two labels is observed. Sign
Model ResNet-50 GTSRB ConvNeXt small GTSRB ResNet-50 GTSRB ConvNeXt small GTSRB
Full Circle Road Work No Passing No Vehicles No Vehicles No Vehicles Speed Limit 50 Speed Limit 80 No Vehicles No Passing End Speed Limit 70
Two Sectors Road Work No Passing Pedestrians No Passing End Trucks Prohibited Speed Limit 50 No Passing Priority Road No Passing End No Vehicles No Passing
we run the digital simulation for both ResNet-50 GTSRB and ConvNeXt small GTSRB models. Stop Sign: We run the digital simulation of our POV display attack and obtain four heatmaps from the two shapes and the two ML models, with one heatmap for each shape–model combination, as shown in Figure 6a. Although all heatmaps are qualitatively similar, ConvNeXt small GTSRB shows a more focused area than ResNet-50 GTSRB. A depiction of the two selected shapes for the highest-ranked positions in both ML models is shown in Figure 7a. Table IV shows the top three labels of misclassified images from the digital simulation.
C. Physical Test To evaluate the attack requirements defined in our threat model, we organize our results into categories targeting distinct attack capabilities. In particular, by comparing classification confidence with the POV display switched on and off while
7
TABLE V: Overview of the ASR and top misclassification label for the physical tests of the 30cm POV display in front of different traffic signs. Sign
Model ResNet-50
(a) Example images in front of a (b) Example images in front of a stop sign 30km/h speed limit sign
GTSRB ConvNeXt s.
Fig. 8: Example images of the 30cm POV display for the physical tests. The positions are derived from Figure 6.
GTSRB ResNet-50 GTSRB
remaining physically deployed, we validate the triggerability requirement and demonstrate that the attack can be externally activated or deactivated without redeployment, enabling selective activation against specific targets. Stop Sign: In our first test, we place the POV display in front of a real stop sign at the aggregated position derived from the heatmaps of Figure 6a. With this test, we aim for a physical reproducibility of the results from Figure 7a and Table IV. We capture images with a Sony IMX708 from distances of 5m to 20m to investigate the effect of different distances. Example images, captured at a distance of 5m, are available in Figure 8a. As our analysis of the ASR in Table V shows, the attack is successful for both ResNet-50 GTSRB and ConvNeXt small GTSRB, with a minimum ASR of 40.69% for ConvNeXt small, and 99.70% for ResNet-50. While ResNet-50 shows a high ASR across all distances and shapes, ConvNeXt small shows greater success at longer distances. The ASRs confirm the placement provided by our digital simulation, but the top misclassification labels differ, as they are not targeted by the simulation. A major reason is the differently perceived red color of the benign stop sign image in the digital simulation compared to the actual color from physical measurements, which are affected by reflections and variations in white balancing. To ensure that the misclassifications are not the result of either the physical mounting of our POV display or of the differently perceived colors, we perform measurements for all distances with switched-off LEDs of the POV display but the same mounting and illumination conditions as in Figure 8. ResNet-50 GTSRB classifies all images correctly as a stop sign with an average confidence of 97.90%, and ConvNeXt small GTSRB classifies them all correctly with an average confidence of 71.49%. This test also shows that POV display is not harmful unless the LEDs are triggered by the attacker. 30km/h Speed Limit Sign: Similar to the stop sign, we evaluate the POV display in front of the 30km/h speed limit sign for distances of 5m to 20m and use the heatmaps of Figure 6b for the placement. Since the heatmaps for ResNet-50 GTSRB and ConvNeXt small GTSRB show different central points, we capture all images for two placement options. Figure 8b shows the physical reproducibility of one exemplary position to reproduce the digital simulations of Figure 7b, captured at a distance of 5m. The ASR is high for most test cases with the 30km/h speed limit sign, as shown in Table V, but especially ConvNeXt small
ConvNeXt s. GTSRB
Shape
5m 100% No Vehicles 99.70% Speed Limit 30 40.69% No Vehicles 91.28% Keep Right 3.34% Speed Limit 70 16.69% Speed Limit 70 4.05% No Passing 2.12% Keep Right
ASR at a distance of 10m 15m 100% 100% No Vehicles No Vehicles 100% 100% No Vehicles No Vehicles 100% 100% No Vehicles No Vehicles 77.84% 97.00% Keep Right No Vehicles 76.69% 100% No Vehicles No Passing 79.13% 96.29% No Vehicles No Vehicles 83.52% 100% Keep Right No Vehicles 99.50% 41.12% No Vehicles Keep Right
20m 100% No Vehicles 100% No Vehicles 100% No Vehicles 98.88% No Vehicles 56.01% No Vehicles 88.01% End all Limits 100% No Vehicles 84.36% No Vehicles
(a) 10cm POV display (b) 15cm portable (c) 20cm POV display POV display
Fig. 9: Example images of smaller POV displays for the physical tests, each with two different shapes. The positions are derived from Figure 6c. The differently perceived brightness levels result from the exposure control algorithm of the camera to compensate for the increased brightness of the larger POV display.
shows low ASRs for the 5m distance, while it is more successful at distances of 10m to 20m. The misclassification labels from digital simulation in Table IV show similarities, especially for the "No Vehicles" misclassification. At the same time, there are similar optical artifacts in the real-world deployment as for the stop sign. For the speed limit sign, both models classify all images for all distances as a 30km/h speed limit sign if the rotating POV display has the LEDs switched off. While ResNet-50 GTSRB has an average confidence of 99.95%, ConvNeXt small GTSRB shows 67.24%. 30km/h Speed Limit Sign with smaller POV display: For the smaller 10cm, 15cm, and 20cm POV display, we evaluated the same distances from 5m to 20m as for the other physical tests, based on the heatmaps of Figure 6c. Figure 9 shows example images of the smaller POV displays, displaying both a full circle and two sectors. As shown in Table VI, the 20cm POV display achieves high ASRs across all tested distances, whereas the smaller 10cm POV display becomes similarly effective only for distances of at least 10m. Nevertheless, misclassification persists up to 10m, meaning that correct recognition may occur only very late, leaving limited reaction time for perception systems. The portable 15cm POV display is effective in most cases, except for ResNet-50 GTSRB and two circular sectors. The lower ASR at a distance of 5m is similar to the observation of our
8
TABLE VI: Overview of the ASR and top misclassification label for the physical tests of the small POV displays in front of the 30km/h speed limit sign. Size
Model ResNet-50
10cm
GTSRB ConvNeXt s. GTSRB ResNet-50
15cm
GTSRB ConvNeXt s. GTSRB ResNet-50
20cm
GTSRB ConvNeXt s. GTSRB
Shape
5m 0% – 1.34% Trucks Prohibited 0.12% Speed Limit 60 4.49% Drive Ahead 0% – 0% – 1.63% Ahead Only 13.20% Go Straight/Left 98.00% No Vehicles 19.66% No Vehicles 100% Ahead Only 98.31% Keep Right
ASR at a distance of 10m 15m 100% 100% No Vehicles No Vehicles 100% 39.10% No Vehicles No Vehicles 100% 100% No Vehicles No Vehicles 97.83% 100% No Vehicles Priority Road 100% 100% No Vehicles No Vehicles 88.37% 1.00% No Vehicles No Vehicles 97.54% 100% No Vehicles No Vehicles 37.26% 88.20% Keep Right Ahead Only 100% 100% No Vehicles No Vehicles 98.43% 98.20% No Vehicles No Vehicles 100% 99.78% No Vehicles No Vehicles 100% 98.65% No Vehicles No Vehicles
TABLE VII: Overview of the ASR for the physical night tests of the 30cm POV display in front of different traffic signs. Sign
20m 100% No Vehicles 86.85% No Vehicles 100% No Vehicles 100% No Vehicles 100% No Passing End 4.17% No Passing End 100% No Vehicles 99.65% Speed Limit 50 100% No Vehicles 76.91% No Vehicles 100% No Vehicles 100% No Vehicles
Model ResNet-50 GTSRB ConvNeXt s. GTSRB ResNet-50 GTSRB ConvNeXt s. GTSRB
(a) Switched off
Shape
5m 100% 100% 73.42% 100% 100% 100% 87.94% 26.72%
ASR at a distance of 10m 15m 20m 100% 100% 100% 100% 100% 100% 100% 100% 100% 52.63% 0.21% 7.34% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100%
(b) Full circle
(c) Two sectors
Fig. 10: Example images of our POV display in front of a stop sign for evaluating the impact of illumination. The effect of the near-infrared LEDs is more noticeable, as the camera adjusts its exposure settings to the darker environment.
10cm POV display. When comparing the top misclassification labels with those from the larger 30cm POV display in Table V, they show high similarity for most test cases. This evaluation shows that even a smaller, stealthier POV display attack can be effectively deployed in the real world. Similar to our other physical tests, both ResNet-50 GTSRB and ConvNeXt small GTSRB classify all street signs with LEDs switched of but rotating POV display correctly, except for a small number of misclassifications for ConvNeXt small at 5m and 10m. While ResNet-50 GTSRB has an average confidence of 99,94% for the switched-off 10cm POV display and 99.97% for the 20cm version, ConvNeXt small GTSRB shows 74.93% and 75.67%, respectively. Impact of Illumination: As the POV display needs to fulfill the previously described timing constraints of Equation 1, tests at bright daylight are not possible, as the short exposure times of cameras would require an extremely fast rotating engine. We will, therefore, conduct night tests, where the timing constraint can be fulfilled. For this evaluation, we create a test stand consisting of two automotive LED car headlights [48] that we align as they are used in an average compact car. Additionally, we calibrate the headlights using UN Regulation No. 112 [49]. This calibration is important to create realistic conditions, especially considering the retroreflective property of street signs [50], [51], [52]. Similar to other tests, we repeat our evaluation at distances of 5m to 20m. As shown in Table VII, our POV display shows even higher ASRs for close distances at all models, compared to the results of Table V. The only exceptions are the two sectors at distances of 15m and 20m and ConvNeXt small GTSRB. In these scenarios, the two sectors cannot be captured accurately at night, as the timing requirement of Equation 1 is not fulfilled. This leads to imprecise shapes. For closer distances, the attack shows even higher ASRs, as the near-infrared LEDs are more noticeable. Figure 10 shows that the glare effect is stronger
compared to the indoor day tests of Figure 8. For both the stop sign and the 30km/h speed limit sign, we used the 30cm version of our POV display. If the POV display is not triggered, all images of both signs are correctly classified. Impact of Placement: To demonstrate that effective POV display deployment is highly placement-dependent, we evaluate an intentionally non-optimal placement of the POV display in front of a stop sign. Specifically, we place a 30 cm POV display at a position that lies outside the high-impact regions identified by our digital simulation heatmaps. This experiment shows that placing the POV display at arbitrary locations does not reliably cause misclassification, highlighting the necessity of our digital simulation for identifying effective placement locations. As in previous experiments, we evaluate both the full circle and the two circular sectors at distances ranging from 5m to 20m using ResNet-50 and ConvNeXt-Small trained on GTSRB. The POV display is positioned to partially cover the letter “S” of the stop sign, as shown in Figure 11. Table VIII shows that the ASR is substantially lower compared to the correctly placed POV display in Table V. In particular, for shorter and intermediate distances, the off-position deployment fails to cause misclassification for ConvNeXt-Small GTSRB and has only a negligible effect on ResNet-50 GTSRB. While a higher ASR can be observed at larger distances, the attack effectiveness remains inconsistent and significantly lower than that achieved with heatmap-guided placement. Overall, these results demonstrate that arbitrary POV display placement does not reliably induce misclassification and highlight the importance of our digital simulation in identifying effective deployment locations. Similar to our previous physical tests, we also perform tests
9
TABLE IX: The ASR of the transferabillity tests of the 30cm POV display in front of different traffic signs. Sign
(a) Full circle
ConvNext b. GTSRB ResNet-152 GTSRB ResNext-101 GTSRB VGG-16 GTSRB ViT-32 GTSRB ConvNeXt b. ImageNet ResNet-50 ImageNet ResNet-152 ImageNet YOLO11 COCO Faster R-CNN COCO ConvNext b. GTSRB ResNet-152 GTSRB ResNext-101 GTSRB VGG-16 GTSRB ViT-32 GTSRB
(b) Two sectors
Fig. 11: Example images of the POV display arbitrarily placed outside the heatmaps of Figure 6a. TABLE VIII: Overview of the ASR for the POV display placed outside the heatmaps positions, in front of a stop sign. The ASR is significantly lower compared to the recommended placement at the heatmap positions in Table V. Model ResNet-50 GTSRB ConvNeXt s. GTSRB
Shape
5m 1.45% 0.45% 0% 0%
Model
ASR at a distance of 10m 15m 20m 5.26% 85.80% 100% 2.93% 14.19% 65.93% 0% 1.19% 62.97% 0.12% 0.69% 24.39%
at this position with a switched-off POV display to evaluate the impact of the mounting and the physical deployment of the POV display. All captured images are classified correctly by both ML models for all distances, with an average confidence of 99.93% for ResNet-50 GTSRB and 75.95% for ConvNeXt small GTSRB. These values are similar to the correctly placed and switched-off POV display, highlighting that the misclassifications in Table VIII are solely from the POV display with activated LED and not from other influences.
Shape
5m 0% 0% 0% 0% 0% 54.19% 0% 0% 0% 0% 0% 0% 5.98% 16.80% 8.25% 0% 0% 0% 0% 0% 0% 0% 100% 26.08% 100% 66.05% 98.54% 91.38% 100% 39.63%
ASR at a distance of 10m 15m 20m 0% 0.03% 13.32% 0% 0% 22.48% 100% 100% 100% 63.97% 100% 100% 100% 100% 100% 93.24% 100% 100% 0.79% 100% 100% 0% 70.00% 100% 95.05% 100% 100% 3.34% 99.96% 100% 0% 100% 100% 0% 99.92% 100% 100% 100% 100% 100% 100% 100% 71.92% 100% 100% 45.15% 100% 100% 43.82% 100% 100% 91.32% 100% 100% 0% 0% 0% 0% 0% 100% 100% 99.66% 99.95% 87.27% 98.64% 99.94% 100% 100% 97.24% 100% 100% 100% 100% 100% 97.93% 100% 100% 99.76% 100% 100% 100% 100% 99.83% 99.76% 100% 99.83% 90.46% 99.72% 100% 99.41%
We also test the transferability of the smaller 10cm, 15cm, and 20cm POV display in front of the 30km/h speed limit sign. Similarly, we test distances from 5m to 20m on all GTSRB models specified in Table III. Like the speed limit sign results of the 30cm POV display in Table IX, the smaller POV displays in Table X show high transferability for the majority of tested cases. The ML models perform with no or a negligible amount of misclassifications if the smaller POV displays are switched off, except for ViT-32 GTSRB at 5m and 20m. The transferability results show that near-infrared POV displays can pose a severe threat for many ML models, independent of their training dataset or model architecture.
Attack Transferability: To evaluate the transferability of our POV display attack across different perception models, we test the same physically captured attack images on multiple ML models. We reuse the identical physical test scenarios from our initial physical tests: a 30cm POV display placed in front of a stop sign and a 30km/h speed limit sign, with distances ranging from 5m to 20m, and evaluate the models listed in Table III. We analyze the transferability of the speed limit sign only for GTSRB-trained models, as only these models are trained to classify this traffic sign. To isolate transferability from deployment effects, we fix the placement using the positions from the heatmaps in Figure 6, ensuring that differences in attack success are from the model behavior rather than the attack procedure or the digital simulation. Table IX shows the results of our transferability analysis of the 30cm POV display. Although close distances of 5m show no attack success for most models with a stop sign, the attack remains effective against the majority of models and distances of ≥10m. For the 30km/h speed limit sign, the attack remains effective against most models even at close range. The ML model performance of all tested use-cases of Table IX shows no, or a negligible number of misclassifications if the POV display is rotating but switched off, except for ResNet-50 ImageNet at 15m and 20m.
D. Dynamic Test In this evaluation, we aim to investigate the impact of driving dynamics on the ASR. We place our camera, the Sony IMX708 with no infrared filter [36], in a real vehicle and place the 30km/h speed limit sign with the 15cm portable POV display in an indoor parking lot. For our tests, we start at a distance of 30m from the traffic sign and approach it at a maximum speed of 10km/h to stay legally compliant. The POV display deployment and the camera perspective of our dynamic tests are shown in Figure 12. Similar to our static physical tests, we capture videos and evaluate the ASR as the ratio of misclassified frames per test while passing by the traffic sign. To ensure repeatability of our results, we conduct five tests with this setup.
10
TABLE X: The ASR of the transferability tests of the 10, 15, and 20cm POV display in front of the 30km/h speed limit sign. Size
10cm
15cm
20cm
Model ConvNext b. GTSRB ResNet-152 GTSRB ResNext-101 GTSRB VGG-16 GTSRB ViT-32 GTSRB ConvNext b. GTSRB ResNet-152 GTSRB ResNext-101 GTSRB VGG-16 GTSRB ViT-32 GTSRB ConvNext b. GTSRB ResNet-152 GTSRB ResNext-101 GTSRB VGG-16 GTSRB ViT-32 GTSRB
(a) POV display deployment
Shape
5m 42.46% 9.55% 97.66% 91.80% 100% 100% 100% 99.78% 98.48% 73.15% 0% 0.15% 0% 0% 100% 5.79% 100% 91.11% 0% 0% 100% 100% 0% 14.16% 100% 99.66% 100% 92.13% 100% 88.76%
ASR at a distance of 10m 15m 20m 1.59% 100% 100% 7.09% 96.07% 100% 100% 100% 100% 81.94% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 98.97% 99.89% 96.52% 100% 100% 100% 63.54% 99.66% 100% 0% 100% 100% 1.26% 97.56% 2.96% 0% 100% 100% 0.16% 13.43% 56.35% 100% 100% 100% 46.07% 54.63% 60.87% 100% 100% 100% 88.21% 94.19% 98.43% 0% 100% 100% 0.63% 10.16% 38.96% 100% 100% 100% 99.33% 98.43% 97.38% 100% 100% 100% 99.44% 100% 75.20% 100% 100% 100% 100% 92.92% 65.64% 100% 100% 100% 100% 98.76% 98.98% 100% 100% 100% 99.66% 99.89% 97.61%
TABLE XI: Overview of ASRs of the dynamic real-world tests. Even in dynamic environments, the POV display remains effective against most ML models. As with other evaluations using the speed limit sign, all models are used in their GTSRB variants. Model ConvNext s. ConvNext b. ResNet-50 ResNet-152 ResNext-101 VGG-16 ViT-32
1 86.21% 37.93% 29.31% 72.41% 78.44% 60.34% 78.45%
ASR at a test no. 2 3 4 79.65% 82.72% 79.03% 33.63% 60.49% 41.94% 53.51% 64.20% 48.39% 92.92% 80.25% 88.71% 98.23% 83.95% 83.87% 74.37% 75.31% 67.74% 85.84% 72.84% 87.10%
5 82.05% 23.08% 28.21% 74.56% 74.36% 58.97% 94.87%
VI. D EFENSE In this section, we discuss a hardware-based defense mechanism using an optical filter and propose a software-based detection method.
(b) Camera perspective of the POV display
Fig. 12: Test setup of the dynamic tests. The portable POV display is attached to the traffic sign via magnets and perceived by the camera as a bright circle.
As shown in Table XI, the POV display is also effective in dynamic environments, with high ASRs for most evaluated ML models. For the tested models, ConvNext base GTSRB shows the lowest ASR across all tests, which is consistent with the transferability analysis of the 15cm POV display in Table X. Similarly, ResNet-50 GTSRB shows lower ASRs in all tests. This is the same as the lower ASRs for the 15cm POV display in Table VI. The other models show an ASR of ≥58% in all our tests.
11
Hardware-based Defense: As our proposed POV display operates in the near-infrared spectrum, the most effective defense is an infrared cutoff filter. Such optical filters will block light of the near-infrared spectrum and are available with different cutoff wavelengths [53], [54]. We evaluate the impact of a near-infrared cutoff filter using the same image sensor, a Sony IMX708 [36], with and without the filter. This ensures that only the impact of the filter is evaluated, not other sensor parameters or data processing. As shown in Figure 13, the impact of a near-infrared cutoff filter is significant: While the image sensor without the filter shows the displayed content as in our previous evaluation, the same image sensor with a filter does not perceive the POV display anymore. Although Figure 13b appears visually darker, it is not a direct effect of the cutoff filter but rather the absence of additional infrared reflections that are visible in Figure 13a, when no filter is applied. While the images of the camera without an infrared filter show an ASR of 100% for both ResNet-50 GTSRB and ConvNeXt small GTSRB, all images from the camera with a filter are classified correctly with an average confidence of ≈93%. We repeat the tests with a POV display that shows a full circle and obtain the same result. This ML model-agnostic defense can also be effective against other infrared-based attacks [14], [15]. While highly effective, such hardware modifications can be infeasible in already deployed autonomous vehicles. In addition, using this cutoff filter may conflict with design goals, such as low-light perception [14]. Adding an infrared filter can reduce image quality or sensing reliability in these cases. As a result, this defense may not be suitable for all camera setups or operating conditions. Software-based Detection: We discuss a sensor-specific, software-based detection approach that can be used to detect near-infrared POV display attacks. Due to differences in spectral sensitivity across image sensors, near-infrared light can be perceived as visible colors such as red, purple, or
Algorithm 2 Proposed detection of a near-infrared POV display in a captured image I. 1: Input: 𝐼 ∈ R 𝐻 ×𝑊 ×3 , 𝛿 ≥ 0, 𝛾 ≥ 0, 𝑚 ≥ 0, optional 𝜀 ∈ [0, 1], offset 𝑜 = (𝑜 𝑥 , 𝑜 𝑦 ),
connectivity 𝜅 = 8
(a) Without nearinfrared cutoff filter
2: Output: R ∈ {true, false} 𝑛 3: 𝑀 [𝑦, 𝑥] ← (𝐼 [𝑦, 𝑥, 0] ≥ 255 − 𝛿) ∧ (𝐼 [𝑦, 𝑥, 1] ≥ 255 − 𝛿) ∧ (𝐼 [𝑦, 𝑥, 2] ≥ 255 − 𝛿) 4: Label connected components 𝐿 of 𝑀 via BFS with 𝜅-connectivity; let labels be 1..𝑛 5: 𝜏 ← max 𝑚, ⌊𝜀𝐻𝑊⌋
(b) With nearinfrared cutoff filter
Fig. 13: Comparison of a POV display showing two sectors, captured with the same cameras, only adding a near-infrared cutoff filter. Although the identical image sensor is used, the infrared POV display is not visible anymore. 2,500 2,000 Amount of pixels
2,500
Red Green Blue
2,000 1,500
1,500
1,000 500
1,000
0 250
255
500 0
0
50
100 150 Pixel value in DN
200
250
6: R ← [ ] 7: for ℓ = 1 to 𝑛 do 8: Sℓ ← {(𝑦, 𝑥) | 𝐿 [𝑦, 𝑥] = ℓ}; 9: if |Sℓ | < 𝜏 then continue 10: (𝑥 min , 𝑥max ) ← (min 𝑥, max 𝑥) over Sℓ 11: (𝑦 min , 𝑦 max ) ← (min 𝑦, max 𝑦) over Sℓ
𝑜 , 𝑥 𝑜 ) ← (𝑥 (𝑥 min min + 𝑜 𝑥 , 𝑥 max + 𝑜 𝑥 ) max 𝑜 , 𝑦 𝑜 ) ← (𝑦 (𝑦 min min + 𝑜 𝑦 , 𝑦 max + 𝑜 𝑦 ) max 𝑜 − 𝑥𝑜 ; ℎ ← 𝑦𝑜 𝑜 𝑤 ← 𝑥max max − 𝑦 min min cw ← 𝛾𝑤; ch ← 𝛾ℎ ′ 𝑜 − 𝛾 cw); 𝑥 ′ 𝑜 𝑥 min ← int(𝑥min max ← int(𝑥 max + 𝛾 cw) ′ 𝑜 − 𝛾 ch); 𝑦 ′ 𝑜 𝑦 min ← int(𝑦 min max ← int(𝑦 max + 𝛾 ch) ′ ′ , 𝑥′ ′ 18: 𝑋 ← 𝐼 [𝑦 min : 𝑦 max min : 𝑥 max , :] 19: 𝑣 min ← min(𝑋) 20: 𝑣 max ← max(𝑋); 𝐵 ← 𝑣 max − 𝑣 min + 1 21: for 𝑐 ∈ {0, 1, 2} do 22: counts𝑐 ← hist 𝑋 [:, :, 𝑐], {𝑣 min , 𝑣 min + 1, . . . , 𝑣 max } Í 𝐵−1 23: 𝑟 𝑐 ← 𝑘=𝐵−5 counts𝑐 [𝑘] 24: end for 25: R ← R ∥ (𝑟 0 > 𝑟 1 ) ∧ (𝑟 2 > 𝑟 1 ) 26: end for 27: Return: R
12: 13: 14: 15: 16: 17:
TABLE XII: TN and TP rates for our proposed near-infrared POV display detection algorithm for over 180k images.
Fig. 14: Histogram of Figure 13a. For values >250, the number of red and blue pixels is higher than the green pixels.
magenta [14]. For the image sensor used in our evaluation, the Sony IMX708, the perceived color is magenta, as shown in the evaluation images. When creating a histogram of the attacked image in Figure 13a, there is not only a highly saturated region with all color channels being at their maximum value, as shown in Figure 14. Due to spectral sensitivity, the close proximity of the saturated region results in a higher number of red and blue pixel values exceeding 250 than in the green channel. This anomaly is specific to the sensor hardware used and needs to be derived from the spectral response characteristics of the sensor. Based on that observation, we provide a proof-of-concept detection approach in Algorithm 2. Our approach first identifies the saturated regions in an image and creates (line 3) binary masks of these regions using a breadth-first search (BFS) [55]. For each saturated region, it analyzes the spatial proximity (lines 9-12) for the identified anomaly, specifically a higher occurrence of high red and blue pixel values compared to green ones (lines 19-21). We evaluate this detection approach on more than 180k images from the test cases described in Section V and report the true positive (TP) and true negative (TN) rates. The TP rate is the amount of correctly identified POV displays, while the TN rate is important for the benign cases. As shown in Table XII, our approach achieves high TN rates, with only two false positives among ≈27k benign images. While the TP rate decreases for smaller POV display, it remains above 55%. Overall, this software-based detection serves as a
12
Test case TN rate Stop Sign 99.97% 30km/h Sign 100% 30km/h Sign, 10cm POV display 100% 30km/h Sign, 20cm POV display 100% Portable POV display 100% Stop Sign Night 100% 30km/h Sign Night 100% * Different Placement * Only adversarial images available in this use case.
TP rate 79.25% 78.39% 66.26% 55.45% 98.30% 98.89% 89.08% 68.51%
proof-of-concept that relies on sensor-specific artifacts. VII. D ISCUSSION Our evaluation results show that near-infrared POV displays can pose a significant threat to traffic sign classification models, leading to misclassifications and transferring well to other ML models. We further discuss two practical limitations of nearinfrared POV display attacks: 1) The effectiveness of near-infrared POV displays depends on the ability of infrared light to reach the image sensor and is therefore limited to infrared-sensitive cameras. 2) The perceived color of near-infrared emissions depends on sensor spectral sensitivity and may appear red, purple, or magenta [14]. As a result, near-infrared POV displays offer limited control over color and primarily allow shapebased attack patterns. To explore whether these limitations are specific to nearinfrared operation rather than inherent to the POV display concept, we additionally investigate POV displays operating in the human-visible spectrum using RGB LEDs. Compared with
TABLE XIII: Overview of the ASRs for different colored circles of the RGB POV display in front of a stop sign. Color Blue Cyan Magenta Red Green Yellow
Brightness
5m 100% 100% 100% 100% 100% 100% 100% 100% 100% 0% 0% 0% 0% 0% 0% 0% 0% 0%
ASR at a distance of 10m 15m 20m 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 100% 42.22% 0% 100% 97.62% 0% 100% 99.48% 0.98% 100% 36.46% 0% 78.07% 49.02% 0% 0% 91.11% 7.69% 18.06% 26.67% 0% 60.00% 10.09% 0% 0% 6.25% 0% 3.33%
(a) Blue (
)
(b) Cyan (
)
(c) Magenta (
(d) Red (
)
(e) Green (
)
(f) Yellow (
)
)
Fig. 15: Example images from the RGB POV display with different-colored full circles. The images have been captured at a distance of 5m with the POV display at full brightness.
blue, cyan, or magenta circles, while red, green, and yellow show a lower ASR. Example images captured at 5m are shown in Figure 15. VIII. C ONCLUSION
our attack goals in Section III-A, RGB POV displays sacrifice parts of the stealthiness, as they operate in the human-visible spectrum and can be perceived by humans. Nevertheless, RGB POV displays remain less conspicuous than classical displays used in prior attacks [56], [57]. While both classical displays and POV displays can be remotely triggered to show dynamic attack content, POV displays appear visually transparent when rotating without displaying content, as human vision cannot follow the fast rotation speed. This makes POV displays stealthier than classical displays, which are typically black and framed when switched off. In contrast to near-infrared POV displays, RGB POV displays can not only visualize different shapes but also controllable colors that are perceived by cameras using the widely available Bayer color filter array [58]. This additional degree of freedom enables the visualization of dynamic content and colors while preserving the attack goals described in Section III-A. We conduct an initial evaluation of an RGB POV display prototype by capturing videos using a Sony ILCE-6400 [59] and the same definition of the ASR as in our previous evaluation. We test the following colors: Blue ( ), Cyan ( ), magenta ( ), red ( ), green ( ), and yellow ( ). Additionally, we we set the RGB LEDs to three different brightness levels: Bright ( ; 100% intensity), medium ( ; 60% intensity), and dark ( ; 20% intensity). Following our evaluation from Section V, we capture 30-second video snippets at distances from 5m to 20m and use the same ASR definition as in our previous experiments. For this evaluation, we execute all steps of the attack design shown in Figure 3 using a stop sign and targeting ResNet-50 GTSRB. As Table XIII shows, the RGB POV display is especially effective when displaying
13
Our near-infrared POV display represents a new physical adversarial attack, operating in a light spectrum outside the human-visible spectrum with high rotation speeds to ensure stealthiness. Unlike prior infrared-based attacks [14], [15], POV displays support dynamic and remotely triggerable attack content, enabling flexible and targeted deployment. Through extensive evaluation across different traffic signs, ML model architectures, distances, and environmental conditions, we demonstrated that POV displays can reliably cause misclassifications and exhibit strong transferability across ML models. Our results further show that correct placement, as determined through a digital simulation, is important for attack success. We also demonstrated that smaller, portable POV displays remain effective, increasing the practicality of real-world attacks. Additionally, we discussed the impact of hardware- and sensor-dependent factors on near-infrared POV displays and showed that POV display attacks exhibit a balance between stealthiness and deployability in camera-based perception systems. To explore the design space further, we introduced an RGB-based POV display variant that trades partial stealth for increased control over displayed content, highlighting that the POV display concept extends beyond a single wavelength spectrum. Overall, our findings demonstrate that our proposed attack represents a realistic and flexible threat to camera-based perception systems. R EFERENCES [1] Mercedes-Benz Group AG, “Mercedes-Benz world’s first automotive company to certify SAE Level 3 system for U.S. market | Mercedes-Benz Group > Innovations > Product innovation > Autonomous driving,” January 2023. [Online]. Available: https://group.mercedes-benz.com/innovation/product-innovation/ autonomous-driving/drive-pilot-nevada.html
[2] Waymo LLC, “Self-Driving Car Technology for a Reliable Ride Waymo Driver,” July 2024. [Online]. Available: https://waymo.com/ waymo-driver/ [3] C. Yan, H. Shin, C. Bolton, W. Xu, Y. Kim, and K. Fu, “SoK: A Minimalist Approach to Formalizing Analog Sensor Security,” in 2020 IEEE Symposium on Security and Privacy (SP). San Francisco, CA, USA: IEEE, May 2020, pp. 233–248. [4] C. Gao, G. Wang, W. Shi, Z. Wang, and Y. Chen, “Autonomous Driving Security: State of the Art and Challenges,” IEEE Internet of Things Journal, vol. 9, no. 10, pp. 7572–7595, May 2022. [5] Z. El-Rewini, K. Sadatsharan, N. Sugunaraj, D. F. Selvaraj, S. J. Plathottam, and P. Ranganathan, “Cybersecurity Attacks in Vehicular Sensors,” IEEE Sensors Journal, vol. 20, no. 22, pp. 13 752–13 767, November 2020. [6] J. Ibanez-Guzman and Y. Li, “LiDAR and cameras in autonomous driving,” Nature Reviews Electrical Engineering, May 2025. [7] A. Guesmi, M. A. Hanif, B. Ouni, and M. Shafique, “Physical Adversarial Attacks for Camera-Based Smart Systems: Current Trends, Categorization, Applications, Research Challenges, and Future Outlook,” IEEE Access, vol. 11, pp. 109 617–109 668, 2023. [8] H. Wei, H. Tang, X. Jia, Z. Wang, H. Yu, Z. Li, S. Satoh, L. Van Gool, and Z. Wang, “Physical Adversarial Attack Meets Computer Vision: A Decade Survey,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 46, no. 12, pp. 9797–9817, December 2024. [9] B. Badjie, J. Cecílio, and A. Casimiro, “Adversarial Attacks and Countermeasures on Image Classification-based Deep Learning Models in Autonomous Driving Systems: A Systematic Review,” ACM Computing Surveys, vol. 57, no. 1, pp. 1–52, January 2025. [10] M. Kühr, M. Hamad, P. MohajerAnsari, M. D. Pesé, and S. Steinhorst, “SoK: Security of the Image Processing Pipeline for Camera-based Sensing in Autonomous Vehicles,” January 2026, arXiv:2409.01234 [cs]. [Online]. Available: http://arxiv.org/abs/2409.01234 [11] K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust Physical-World Attacks on Deep Learning Visual Classification,” in 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition. Salt Lake City, UT, USA: IEEE, June 2018, pp. 1625–1634. [12] G. Lovisotto, H. Turner, I. Sluganovic, M. Strohmeier, and I. Martinovic, “SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations,” in 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, August 2021, pp. 1865–1882. [13] R. Duan, X. Mao, A. K. Qin, Y. Chen, S. Ye, Y. He, and Y. Yang, “Adversarial Laser Beam: Effective Physical-World Attack to DNNs in a Blink,” in 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Nashville, TN, USA: IEEE, June 2021, pp. 16 057–16 066. [14] T. Sato, S. H. V. Bhupathiraju, M. Clifford, T. Sugawara, Q. A. Chen, and S. Rampazzi, “Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign Perception,” in Proceedings 2024 Network and Distributed System Security Symposium, San Diego, CA, USA, February 2024. [15] W. Wang, Y. Yao, X. Liu, X. Li, P. Hao, and T. Zhu, “I Can See the Light: Attacks on Autonomous Vehicles Using Invisible Lights,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. Virtual Event Republic of Korea: ACM, November 2021, pp. 1930–1944. [16] Aumovio SE, “Night-Capable Camera Systems | AUMOVIO,” 2025. [Online]. Available: https://www.aumovio.com/en/solutions/driver-assistance/ automated-assisted-driving/night-capable-camera-systems.html [17] N. Pinchon, O. Cassignol, A. Nicolas, F. Bernardin, P. Leduc, J.-P. Tarel, R. Brémond, E. Bercier, and J. Brunet, “All-Weather Vision for Automotive Safety: Which Spectral Band?” in Advanced Microsystems for Automotive Applications 2018. Cham: Springer International Publishing, 2019, pp. 3–15. [18] Kingbright, “WP7113SF6BT-P22 - T-1 3/4 (5mm) Infrared Emitting Diode,” November 2024. [Online]. Available: https://www.kingbrightusa. com/images/catalog/SPEC/WP7113SF6BT-P22.pdf [19] A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok, “Synthesizing Robust Adversarial Examples,” in Proceedings of the 35th International Conference on Machine Learning, ser. Proceedings of Machine Learning Research, J. Dy and A. Krause, Eds., vol. 80. Stockholm, Sweden: PMLR, July 2018, pp. 284–293.
14
[20] International Commission on Illumination, “CIE DIS 017/E:2016 ILV: International Lighting Vocabulary,” CIE Central Bureau, Vienna, International Standard, 2016, 2nd Edition. [21] L. C. P. Gouveia and B. Choubey, “Advances on CMOS image sensors,” Sensor Review, vol. 36, no. 3, pp. 231–239, June 2016. [22] A. El Gamal and H. Eltoukhy, “CMOS image sensors,” IEEE Circuits and Devices Magazine, vol. 21, no. 3, pp. 6–20, May 2005. [23] Z. Zhou, D. Tang, X. Wang, W. Han, X. Liu, and K. Zhang, “Invisible Mask: Practical Attacks on Face Recognition with Infrared,” March 2018, arXiv:1803.04683 [cs]. [Online]. Available: http://arxiv.org/abs/1803.04683 [24] Y. Wang, Z. Liu, B. Luo, R. Hui, and F. Li, “The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face Recognition,” in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. Salt Lake City UT USA: ACM, December 2024, pp. 3346–3360. [25] M. Coltheart, “The persistences of vision,” Philosophical Transactions of the Royal Society of London. B, Biological Sciences, vol. 290, no. 1038, pp. 57–69, July 1980. [26] E. S. Ferry, “Persistence of vision,” American Journal of Science, vol. 3, no. 261, pp. 192–207, 1892. [27] W. Zhu, X. Ji, Y. Cheng, S. Zhang, and W. Xu, “TPatch: A Triggered Physical Adversarial Patch,” in 32nd USENIX Security Symposium (USENIX Security 23). Anaheim, CA: USENIX Association, August 2023, pp. 661–678. [28] Q. Xia and Q. Chen, “Moiré Injection Attack (MIA) : Compromising Autonomous Vehicle Safety via Exploiting Camera’s Color Filter Array (CFA) to Inject Hidden Traffic Sign,” in 2024 Annual Computer Security Applications Conference (ACSAC). Honolulu, HI, USA: IEEE, December 2024, pp. 988–1001. [29] Y. Man, M. Li, and R. Gerdes, “Remote Perception Attacks against Camera-based Object Recognition Systems and Countermeasures,” ACM Transactions on Cyber-Physical Systems, vol. 8, no. 2, pp. 1–27, April 2024. [30] H. Ji and P. A. Abshire, “Fundamentals of Silicon-Based Phototransduction,” in CMOS Imagers, O. Yadid-Pecht and R. Etienne-Cummings, Eds. Boston, MA: Springer US, 2004, pp. 1–51. [31] A. Perkins and S. Borthakur, “Near Infrared Quantum Efficiency Simulations for CMOS Image Sensors,” Proceedings 2023 International Image Sensor Workshop, 2023. [32] Hamamatsu Photonics K.K., “CCD/CMOS image sensors Image sensors for scientific measurements and industrial equipment,” September 2025. [Online]. Available: https://www.hamamatsu.com/content/dam/hamamatsu-photonics/sites/ documents/99_SALES_LIBRARY/ssd/image_sensor_kmpd0002e.pdf [33] Allied Vision Technologies GmbH, “Alvium 1800 C-240 Alvium 1800 C-240 | 2.4 MP Sony IMX392 CMOS sensor - Allied Vision,” October 2025. [Online]. Available: https://www.alliedvision.com/en/products/ alvium-configurator/alvium-1800-c/240/ [34] Handson Technology, “775 Ball Bearing DC Motor - Data Specs,” November 2025. [Online]. Available: https://www.handsontec.com/ dataspecs/motor_fan/775-Motor.pdf [35] Motraxx Elektrogeräte GmbH, “FK-280SAV-19170,” 2022. [Online]. Available: https://motraxx.com/assets/229020_FK-280SA-19170.pdf [36] Raspberry Pi Ltd., “Camera - Raspberry Pi Documentation,” July 2024. [Online]. Available: https://www.raspberrypi.com/documentation/ accessories/camera.html [37] J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,” Neural Networks, vol. 32, pp. 323–332, August 2012. [38] N. Wang, S. Xie, T. Sato, Y. Luo, K. Xu, and Q. A. Chen, “Revisiting Physical-World Adversarial Attack on Traffic Sign Recognition: A Commercial Systems Perspective,” in Proceedings 2025 Network and Distributed System Security Symposium. San Diego, CA, USA: Internet Society, 2025. [39] K. He, X. Zhang, S. Ren, and J. Sun, “Deep Residual Learning for Image Recognition,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), June 2016. [40] Z. Liu, H. Mao, C.-Y. Wu, C. Feichtenhofer, T. Darrell, and S. Xie, “A ConvNet for the 2020s,” in 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New Orleans, LA, USA: IEEE, June 2022, pp. 11 966–11 976. [41] J. Deng, W. Dong, R. Socher, L.-J. Li, Kai Li, and Li Fei-Fei, “ImageNet: A large-scale hierarchical image database,” in 2009 IEEE Conference
on Computer Vision and Pattern Recognition. Miami, FL: IEEE, June 2009, pp. 248–255. [42] T.-Y. Lin, M. Maire, S. Belongie, J. Hays, P. Perona, D. Ramanan, P. Dollár, and C. L. Zitnick, “Microsoft COCO: Common Objects in Context,” in Computer Vision – ECCV 2014, D. Fleet, T. Pajdla, B. Schiele, and T. Tuytelaars, Eds. Cham: Springer International Publishing, 2014, vol. 8693, pp. 740–755, series Title: Lecture Notes in Computer Science. [43] S. Xie, R. Girshick, P. Dollar, Z. Tu, and K. He, “Aggregated Residual Transformations for Deep Neural Networks,” in 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). Honolulu, HI: IEEE, July 2017, pp. 5987–5995. [44] K. Simonyan and A. Zisserman, “Very Deep Convolutional Networks for Large-Scale Image Recognition,” April 2015, arXiv:1409.1556 [cs]. [Online]. Available: http://arxiv.org/abs/1409.1556 [45] A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, J. Uszkoreit, and N. Houlsby, “An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale,” in 2021 International Conference on Learning Representations, Virtual Event, May 2021. [46] G. Jocher and J. Qiu, “Ultralytics YOLO11,” 2024. [Online]. Available: https://github.com/ultralytics/ultralytics [47] S. Ren, K. He, R. Girshick, and J. Sun, “Faster R-CNN: Towards RealTime Object Detection with Region Proposal Networks,” in Advances in Neural Information Processing Systems, C. Cortes, N. Lawrence, D. Lee, M. Sugiyama, and R. Garnett, Eds., vol. 28. Curran Associates, Inc., 2015. [48] OSRAM GmbH, “Night Breaker LED Vintage H4,” December 2025. [Online]. Available: https://www.osram.co.uk/appsj/pdc/pdf.do?cid=GPS01_34401769& vid=MP_EUROPE_UK_eCat&lid=EN&mpid=ZMP_4069705 Nations, “E/ECE/324/Rev.2/Add.111/Rev.4, E/ECE/[49] United TRANS/505/Rev.2/Add.111/Rev.4: Uniform provisions concerning the approval of motor vehicle headlamps emitting an asymmetrical passing-beam or a driving-beam or both and equipped with filament light sources and/or light-emitting diode (LED) modules,” United Nations, Agreement, September 2023. [50] DIN Deutsches Institut für Normung e. V., “DIN 67520:2025-06: Retroreflecting materials for traffic safety - Photometric minimum requirements for retro-reflective sheetings,” DIN Deutsches Institut für Normung e. V., Berlin, Deutsche Norm, June 2025. [51] European Committee for Standardization, “EN 12899-1:2007:E: Fixed, vertical road traffic signs – Part 1: Fixed signs,” European Committee for Standardization, B-1050 Brussels, European Standard, November 2007. [52] United Nations Economic Commission for Europe, “ECE/TRANS/196: Convention on Road Signs and Signals of 1968 European Agreement Supplementing the Convention and Protocol on Road Markings, Additional to the European Agreement,” United Nations Economic Commission for Europe, United Nations Publication, December 2006. [53] BTE Bedampfungstechnik GmbH, “Infrared-Filter (IR-Filter),” 2025. [Online]. Available: https://www.bte-born.com/fileadmin/bte/Downloads/ Datenbl%C3%A4tter/BTE_Datenblatt_IR_ENG_29042025_fin.pdf [54] Optics Balzers AG, “Coated Optics for Sensor Applications,” 2025. [Online]. Available: https: //www.materionbalzersoptics.com/de/service/datenblaetter/download/ e4554a6778fe4b4481fa970161eaef40cabf82b74bfee1f81fcc572f327ce782 [55] T. H. Cormen, C. E. Leiserson, R. L. Rivest, and C. Stein, “Elementary Graph Algorithms,” in Introduction to Algorithms, 3rd ed. The MIT Press, 2009, pp. 589–623. [56] A. Chahe, C. Wang, A. Jeyapratap, K. Xu, and L. Zhou, “Dynamic Adversarial Attacks on Autonomous Driving Systems,” May 2024, arXiv:2312.06701 [cs]. [Online]. Available: http://arxiv.org/abs/2312. 06701 [57] N. Patel, P. Krishnamurthy, S. Garg, and F. Khorrami, “Overriding Autonomous Driving Systems Using Adaptive Adversarial Billboards,” IEEE Transactions on Intelligent Transportation Systems, vol. 23, no. 8, pp. 11 386–11 396, August 2022. [58] B. E. Bayer, “Color Imaging Array,” USA Patent United States Patent 3,971,065, Jul., 1976. [59] Sony Electronics Inc., “ILCE-6400 Specifications | Sony USA,” January 2025. [Online]. Available: https://www.sony.com/electronics/support/ e-mount-body-ilce-6000-series/ilce-6400/specifications
15