AI Vision Systems Face Real-World Challenges: New Study Explores Traffic Sign Deterioration Impact

August 31, 2026
AI Vision Systems Face Real-World Challenges: New Study Explores Traffic Sign Deterioration Impact
  • The study shows that training with AdvWT-generated damaged signs improves generalization to real-world deterioration, helping identify and address weaknesses in vision systems.

  • AdvWT trains a StarGAN-v2–based image-to-image translation model to learn a latent damage style that reproduces realistic deterioration while preserving sign identity, enabling signs to look damaged yet still be misclassified by AI.

  • The bidirectional model can also restore damaged signs, suggesting potential use in repairing real-world signs and boosting robustness through adversarial training with damaged signs.

  • The work highlights the need to evaluate natural deterioration’s impact on traffic-sign recognition and to strengthen AI robustness for real-world, high-stakes domains like autonomous driving, healthcare, and finance.

  • The paper is titled Adversarial Wear and Tear: Exploiting Natural Damage for Generating Physical-World Adversarial Examples, published in IEEE Transactions on Dependable and Secure Computing in May 2026.

  • The study’s full title is Adversarial Wear and Tear: Exploiting Natural Damage for Generating Physical-World Adversarial Examples, appearing in IEEE Transactions on Dependable and Secure Computing (Volume 23, Issue 3, 2026).

  • A collaboration between SEOULTECH and Kyung Hee University developed AdvWT, a framework using natural wear and tear on traffic signs as an adversarial signal to test and improve vision-system robustness for autonomous driving.

  • Led by Associate Professor Seong Tae Kim and Assistant Professor Hong Joo Lee, the team formulated AdvWT to test and enhance AI robustness under real-world sign degradation.

  • The Kyung Hee University–SEOULTECH effort uses naturally occurring wear on traffic signs to generate adversarial examples for AI vision systems in safety-critical contexts.

  • Across two traffic-sign datasets and eight recognition architectures, AdvWT achieved near-perfect attack success on lightweight CNNs and remained effective against transformer models, with strong cross-model transferability.

  • Evaluations showed near-perfect attack success on models like ResNet-18 and MobileNet, with continued effectiveness against transformers across datasets and architectures.

  • Physical tests involved printing clean and adversarial signs and recapturing them under varying distances, angles, and lighting, with adversarial effects persisting in real-world conditions.

Summary based on 3 sources


Get a daily email with more AI stories

More Stories