{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T07:47:25Z","timestamp":1776844045162,"version":"3.51.2"},"reference-count":55,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T00:00:00Z","timestamp":1776729600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["CNS-2145493, CNS-1929771, CNS-2413877"],"award-info":[{"award-number":["CNS-2145493, CNS-1929771, CNS-2413877"]}]},{"name":"USDOT UTC","award":["69A3552348327"],"award-info":[{"award-number":["69A3552348327"]}]},{"name":"CARMEN+ University Transportation Center","award":["JSPS KAKENHI 24K14943, JST CREST JPMJCR23M4"],"award-info":[{"award-number":["JSPS KAKENHI 24K14943, JST CREST JPMJCR23M4"]}]},{"name":"Toyota InfoTech Labs"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2026,4,30]]},"abstract":"<jats:p>Connected autonomous vehicles must accurately detect, and adhere, to traffic light signals to ensure safe and efficient traffic flow. Misinterpretation of traffic lights can result in potential safety issues for drivers and pedestrians. Recent work demonstrated attacks that projected structured light patterns onto vehicle cameras, causing traffic signs and traffic light color misinterpretation. In this work, we characterize a novel vulnerability of traffic light physical structures that can be exploited by attackers to deceive recognition systems. When visible and invisible laser light is projected onto traffic lights, it is scattered by its internal reflectors. To a vehicle\u2019s camera, the reflected light appears the same as a genuine light source, resulting in dangerous red and green traffic light status misclassifications. We evaluate our attack against three state-of-the-art traffic light recognition models and show successful misclassification up to 25\u2009m from the target traffic light. Furthermore, the attack succeeds both in daytime and nighttime conditions both in static and moving vehicle scenarios up to 10\u2009km\/h speed. To mitigate this threat, we propose a detection system based on light texture patterns that achieve 100% TPR and 1.8% FPR in our real-world scenarios.<\/jats:p>","DOI":"10.1145\/3777451","type":"journal-article","created":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T12:37:57Z","timestamp":1764765477000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["To Go or Not to Go: Shedding Light on Traffic Light Signal Manipulation and Defense Strategies"],"prefix":"10.1145","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-1027-5002","authenticated-orcid":false,"given":"Sri Hrushikesh Varma","family":"Bhupathiraju","sequence":"first","affiliation":[{"name":"Computer Information Science and Engineering, University of Florida, Gainesville, Florida, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4465-5653","authenticated-orcid":false,"given":"Takami","family":"Sato","sequence":"additional","affiliation":[{"name":"Computer Science, University of California Irvine Donald Bren School of Information and Computer Sciences, Irvine, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8316-4929","authenticated-orcid":false,"given":"Michael","family":"Clifford","sequence":"additional","affiliation":[{"name":"Toyota InfoTech Labs, Mountain View, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9356-534X","authenticated-orcid":false,"given":"Takeshi","family":"Sugawara","sequence":"additional","affiliation":[{"name":"The University of Electro-Communications, Chofu, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0316-9285","authenticated-orcid":false,"given":"Qi Alfred","family":"Chen","sequence":"additional","affiliation":[{"name":"Computer Science, University of California Irvine Donald Bren School of Information and Computer Sciences, Irvine, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3630-6269","authenticated-orcid":false,"given":"Sara","family":"Rampazzi","sequence":"additional","affiliation":[{"name":"Computer Information Science and Engineering, University of Florida, Gainesville, Florida, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,4,21]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"crossref","unstructured":"Francis Chapin Breckenridge. 1964. United States Standard for the Colors of Signal Lights Vol. 95 Superintendent of Documents US Government Print Office. Retrieved from https:\/\/nvlpubs.nist.gov\/nistpubs\/Legacy\/hb\/nbshandbook95.pdf","DOI":"10.6028\/NBS.HB.95"},{"key":"e_1_3_2_3_2","unstructured":"Laser Pointer Store. 2021. Mini Series Laser Pointer Manual. Retrieved from https:\/\/laserpointerstore.com\/wp-content\/uploads\/2021\/07\/Mini-Series-Laser-Pointer-Manual.pdf"},{"key":"e_1_3_2_4_2","unstructured":"Baidu Inc. 2023. Apollo. Retrieved from https:\/\/github.com\/ApolloAuto\/apollo"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_21"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.14722\/vehiclesec.2024.23024"},{"key":"e_1_3_2_7_2","unstructured":"John D. Bullough Jeremy D. Snyder Aaron M. Smith and Terence R. Klein. 2009. Replacement Processes for Light Emitting Diode (Led) Traffic Signals. Contractor\u2019s Final Report for NCHRP Project 20\u201307."},{"key":"e_1_3_2_8_2","volume-title":"USENIX Security","author":"Cao Yulong","year":"2023","unstructured":"Yulong Cao, S. Hrushikesh Bhupathiraju, Pirouz Naghavi, Takeshi Sugawara, Z. Morley Mao, and Sara Rampazzi. 2023. You can\u2019t see me: Physical removal attacks on LiDAR-based autonomous vehicles driving frameworks. In USENIX Security."},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23222"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3540653"},{"key":"e_1_3_2_12_2","unstructured":"CivilLaser. 2018. 780nm 1W 2W Powerful IR Laser Module Dot with Cooling Fan. Retrieved from https:\/\/www.civillaser.com\/index.php?main_page=product_info&products_id=477"},{"key":"e_1_3_2_13_2","unstructured":"comma_ai. 2025.\u2009OpenPilot: Open Source Driving Agent. Retrieved from https:\/\/github.com\/commaai\/openpilot"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"e_1_3_2_15_2","unstructured":"Ivan Fursa Elias Fandi Valentina Musat Jacob Culley Enric Gil Izzeddin Teeti Louise Bilous Isaac Vander Sluis Alexander Rast and Andrew Bradley. 2021. Worsening perception: Real-time degradation of autonomous vehicle perception performance for simulation of adverse weather conditions. arXiv:2103.02760. Retrieved from https:\/\/arxiv.org\/abs\/2103.02760"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.14722\/sent.2015.23001"},{"key":"e_1_3_2_17_2","volume-title":"8th USENIX conference on Offensive Technologies","author":"Ghena Branden","year":"2014","unstructured":"Branden Ghena, William Beyer, Allen Hillaker, Jonathan Pevarnek, and J. Alex Halderman. 2014. Green lights forever: Analyzing the security of traffic infrastructure. In 8th USENIX conference on Offensive Technologies."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-43205-1_2"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643832.3661854"},{"key":"e_1_3_2_20_2","first-page":"975","article-title":"Watch out! motion is blurring the vision of your deep neural networks","volume":"33","author":"Guo Qing","year":"2020","unstructured":"Qing Guo, Felix Juefei-Xu, Xiaofei Xie, Lei Ma, Jian Wang, Bing Yu, Wei Feng, and Yang Liu. 2020. Watch out! motion is blurring the vision of your deep neural networks. In Advances in Neural Information Processing Systems, Vol. 33, 975\u2013985.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.4324\/9780240814315"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.robot.2018.10.004"},{"key":"e_1_3_2_23_2","unstructured":"Andrew G. Howard Menglong Zhu Bo Chen Dmitry Kalenichenko Weijun Wang Tobias Weyand Marco Andreetto and Hartwig Adam. 2017. MobileNets: Efficient convolutional neural networks for mobile vision applications. arXiv:1704.04861. Retrieved from https:\/\/arxiv.org\/abs\/1704.04861"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2017.07.003"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2015.2509509"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCPS.2018.00035"},{"key":"e_1_3_2_27_2","unstructured":"Leopard Imaging Inc. 2016. LI-USB30-AR023ZWDR Data Sheet. Retrieved from https:\/\/mm.digikey.com\/Volume0\/opasdata\/d220001\/medias\/docus\/6621\/LIUSB30AR023ZWDRdatasheet1101519.pdf"},{"key":"e_1_3_2_28_2","first-page":"1865","volume-title":"USENIX Security","author":"Lovisotto Giulio","year":"2021","unstructured":"Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, and Ivan Martinovic. 2021. SLAP: Improving physical adversarial examples with short-lived adversarial perturbations. In USENIX Security, 1865\u20131882."},{"key":"e_1_3_2_29_2","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses","author":"Man Yanmao","year":"2020","unstructured":"Yanmao Man, Ming Li, and Ryan Gerdes. 2020. GhostImage: Remote perception attacks against camera-based image classification systems. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses."},{"key":"e_1_3_2_30_2","article-title":"Remote perception attacks against camera-based object recognition systems and countermeasures","author":"Man Yanmao","year":"2023","unstructured":"Yanmao Man, Ming Li, and Ryan Gerdes. 2023. Remote perception attacks against camera-based object recognition systems and countermeasures. ACM Transactions on Cyber-Physical Systems (2023).","journal-title":"ACM Transactions on Cyber-Physical Systems"},{"key":"e_1_3_2_31_2","unstructured":"MarkLines Co. Ltd. 2020. BMW 320i Teardown: ADAS\/onboard devices. Retrieved from https:\/\/www.marklines.com\/en\/report_all\/rep2018_202004"},{"key":"e_1_3_2_32_2","first-page":"32","volume-title":"Introduction to Comsol Multiphysics\u00ae","author":"COMSOL Multiphysics","year":"1998","unstructured":"COMSOL Multiphysics. 1998. Introduction to Comsol Multiphysics\u00ae. COMSOL Multiphysics, Burlington, MA, 32."},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423359"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3375706.3380554"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.5194\/isprs-archives-XLVI-4-W5-2021-411-2021"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/964967.801169"},{"key":"e_1_3_2_37_2","unstructured":"Generation Robotics. 2023. AgileX Robotics Autoware Open Sourse Autonomous Kit. Retrieved from https:\/\/static.generation-robots.com\/media\/agilex-robotics-autoware-user-manual-2.pdf"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.14722\/vehiclesec.2023.23055"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.241053"},{"key":"e_1_3_2_40_2","unstructured":"Chris Sebes. 2023. Why Is There a Blue Lens on the Traffic Light? Retrieved from https:\/\/mytrafficlights.com\/why-does-the-green-lens-on-my-traffic-light-look-blue\/"},{"key":"e_1_3_2_41_2","unstructured":"Shenzhen Fama Intelligent Equipment CO. Ltd. 2020. The Different Types of Traffic Lights that Are Currently Being Used. Retrieved from https:\/\/www.ledsemaforo.com\/news_view-55.html"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.5978\/islsm.20.95"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1021\/ed039p333"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_2_45_2","unstructured":"AgileX Robotics Team. 2023. HUNTER2.0 USER MANUAL. Retrieved from https:\/\/cdn.shopify.com\/s\/files\/1\/0551\/0630\/6141\/files\/HUNTER2.0_USER_MANUAL2023.12_50805.pdf?v=1711434366"},{"key":"e_1_3_2_46_2","unstructured":"Tesla Inc. 2025. Tesla Autopilot. Retrieved from https:\/\/www.tesla.com\/autopilot"},{"key":"e_1_3_2_47_2","unstructured":"The Autoware Foundation. 2021. The Traffic Light Map Based Detector Package. Retrieved from https:\/\/autowarefoundation.github.io\/autoware.universe\/main\/perception\/traffic_light_map_based_detector\/"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2008.4587440"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484766"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3114024"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.3390\/su15010808"},{"issue":"8","key":"e_1_3_2_52_2","first-page":"109","article-title":"Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle","volume":"24","author":"Yan Chen","year":"2016","unstructured":"Chen Yan, Wenyuan Xu, and Jianhao Liu. 2016. Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle. Def Con 24, 8 (2016), 109.","journal-title":"Def Con"},{"key":"e_1_3_2_53_2","first-page":"1957","volume-title":"USENIX Security","author":"Yan Chen","year":"2022","unstructured":"Chen Yan, Zhijian Xu, Zhanyuan Yin, Xiaoyu Ji, and Wenyuan Xu. 2022. Rolling colors: Adversarial laser exploits against traffic light recognition. In USENIX Security, 1957\u20131974."},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1364\/OE.20.024382"},{"key":"e_1_3_2_55_2","unstructured":"Junko Yoshida. 2020. Teardown: Lessons Learned from Audi A8. Retrieved from https:\/\/www.eetasia.com\/teardown-lessons-learned-from-audi-a8\/"},{"key":"e_1_3_2_56_2","first-page":"1885","volume-title":"USENIX Security","author":"Zhou Ce","year":"2022","unstructured":"Ce Zhou, Qiben Yan, Yan Shi, and Lichao Sun. 2022. DoubleStar: Long-range attack towards depth estimation based obstacle avoidance in autonomous systems. In USENIX Security, 1885\u20131902."}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3777451","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3777451","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T06:34:30Z","timestamp":1776839670000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3777451"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,21]]},"references-count":55,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,4,30]]}},"alternative-id":["10.1145\/3777451"],"URL":"https:\/\/doi.org\/10.1145\/3777451","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,21]]},"assertion":[{"value":"2024-09-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-28","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}