A new AI-based framework called AdvWT, developed by Seoul National University of Science and Technology (SeoulTech), has been used to demonstrate how naturally occurring damage to traffic signs can cause DNN-based vision systems to misclassify them. Testing across multiple AI architectures showed attack transferability and physical-world robustness, with researchers stating that training models with AdvWT-generated damaged signs could help identify vulnerabilities and improve AI generalisation to real-world damage.
In computer vision and robotics, ensuring that AI systems remain reliable under real-world conditions is a growing challenge. Deep neural network-based vision systems are increasingly used in safety-critical applications such as autonomous driving, where misinterpreting a traffic sign could potentially lead to unsafe decisions. Everyday wear and tear can subtly alter traffic signs, raising questions about whether naturally occurring damage could also expose vulnerabilities in AI-based recognition systems.
To understand and address the problem, a research team led by associate professor Seong Tae Kim from Kyung Hee University and assistant professor Hong Joo Lee from SeoulTech developed Adversarial Wear and Tear (AdvWT), a framework that exploits natural wear and tear as an adversarial signal.
“We focused on traffic signs because they are exposed to weather and environmental damage throughout their lifetime, and their accurate recognition is essential for safety-critical applications,” explained Dr Lee. “Unlike temporary optical attacks, natural deterioration can persist until a physical object is repaired or replaced.”
To create AdvWT, the team trained a generative image-to-image translation model to learn the visual characteristics of damaged and undamaged traffic signs. The model, based on StarGAN-v2, learned a latent “damage style” representation that can reproduce diverse forms of realistic deterioration while preserving the identity and meaning of the sign.
By progressively adjusting the damage representation, they generated signs that looked naturally degraded but were more likely to be misclassified by an AI system. In a human study involving 32 participants, AdvWT-generated images received high naturalness ratings, closely matching the perceived realism of real damaged traffic signs.
The framework was evaluated against two traffic-sign datasets and tested against eight recognition architectures. Across the evaluated models and datasets, AdvWT achieved near-perfect attack success rates on lightweight CNNs such as ResNet-18 and MobileNet, while also remaining effective against transformer-based models. AdvWT also achieved the highest average transferability across most tested model combinations, suggesting that the adversarial perturbations could transfer across different model architectures.
To test the framework in a physical setting, the researchers printed clean and adversarial speed-limit signs and photographed them under different distances, viewing angles as well as indoor and outdoor conditions. The resulting images remained effective at misleading the traffic-sign classifier, showing that the adversarial effect persisted after printing and recapturing under varied physical conditions.
The researchers also demonstrated that the same bidirectional model could be used to restore naturally damaged traffic signs, suggesting potential applications beyond adversarial testing. Importantly, training models with AdvWT-generated damaged signs improved their ability to generalize to real-world damaged traffic signs, suggesting that simulated natural deterioration could be used to identify and strengthen weaknesses in vision systems.
“Building reliable AI requires more than improving average performance. It requires continuously identifying where AI systems fail, understanding why those failures occur, and using those insights to make the systems more robust,” said said Dr Kim. “Over the next five to 10 years, research in this direction could play an important role in developing AI systems that can be deployed more reliably in real-world, high-stakes domains such as healthcare and finance.”
Recent news, AI co-driver turns spoken observations into structured test data





