Evaluating the Impact of Adversarial Attacks on Traffic Sign Classification using the LISA Dataset

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tadessa, Nabeyou, Iyangar, Balaji, Chowdhury, Mashrur
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916939988729856
author Tadessa, Nabeyou
Iyangar, Balaji
Chowdhury, Mashrur
author_facet Tadessa, Nabeyou
Iyangar, Balaji
Chowdhury, Mashrur
contents Adversarial attacks pose significant threats to machine learning models by introducing carefully crafted perturbations that cause misclassification. While prior work has primarily focused on MNIST and similar datasets, this paper investigates the vulnerability of traffic sign classifiers using the LISA Traffic Sign dataset. We train a convolutional neural network to classify 47 different traffic signs and evaluate its robustness against Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks. Our results show a sharp decline in classification accuracy as the perturbation magnitude increases, highlighting the models susceptibility to adversarial examples. This study lays the groundwork for future exploration into defense mechanisms tailored for real-world traffic sign recognition systems.
format Preprint
id arxiv_https___arxiv_org_abs_2509_06835
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Evaluating the Impact of Adversarial Attacks on Traffic Sign Classification using the LISA Dataset
Tadessa, Nabeyou
Iyangar, Balaji
Chowdhury, Mashrur
Computer Vision and Pattern Recognition
Adversarial attacks pose significant threats to machine learning models by introducing carefully crafted perturbations that cause misclassification. While prior work has primarily focused on MNIST and similar datasets, this paper investigates the vulnerability of traffic sign classifiers using the LISA Traffic Sign dataset. We train a convolutional neural network to classify 47 different traffic signs and evaluate its robustness against Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) attacks. Our results show a sharp decline in classification accuracy as the perturbation magnitude increases, highlighting the models susceptibility to adversarial examples. This study lays the groundwork for future exploration into defense mechanisms tailored for real-world traffic sign recognition systems.
title Evaluating the Impact of Adversarial Attacks on Traffic Sign Classification using the LISA Dataset
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2509.06835