Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural Phenomenon
Yiqi ZhongXianming LiuDeming ZhaiJunjun JiangXiangyang Ji
Demonstrates that casting simple, natural shadows onto traffic signs can deceive vision models in physical-world black-box settings with success rates exceeding 90%, exposing a critical real-world vulnerability in autonomous systems.
Deep neural networks are increasingly deployed in safety-critical visual applications such as autonomous driving. However, these systems remain vulnerable to adversarial physical modifications, such as stickers or artificial light beams, which alter model outputs without human detection. Existing physical attacks often require direct physical tampering or rely on conspicuous artificial projections that are easily noticed by people. The article demonstrates a novel, non-invasive physical attack that uses ordinary natural shadows to stealthily fool vision systems under realistic black-box conditions, where the attacker has no knowledge of internal model parameters.
To implement the attack, the authors model shadows digitally as simple triangular geometric shapes that selectively reduce image lightness. They search for optimal shadow placements using a population-based search algorithm called particle swarm optimization, avoiding the need for model gradients. To ensure the physical viability of these digital patterns across changing viewing angles, distances, and lighting conditions, the framework incorporates transformation modeling and prediction stabilization techniques. The authors evaluate the approach digitally across standard benchmark traffic sign datasets (LISA and GTSRB) and physically using real cardboards outdoors in natural sunlight and flashlights indoors.
The findings show that natural shadows pose an acute and practical security risk. In digital benchmarks, the attack achieves misclassification rates of 98.23% on LISA and 90.47% on GTSRB under typical shadow intensities, requiring only tens to hundreds of model queries. In physical outdoor experiments with a moving camera, the shadow perturbation caused continuous misclassification across 100% of recorded frames, stabilizing on a single incorrect class (misclassifying a speed limit 25 sign as a speed limit 35 sign) over 95% of the time. Furthermore, the article demonstrates simulated scheduled attacks, where natural solar movement triggers deception only during specific times of day, such as peak morning traffic hours, lasting from tens of seconds to several minutes.
These results demonstrate that machine vision models can be severely compromised by subtle, everyday phenomena without arousing human suspicion. Because the shadow continuously induces a specific erroneous class rather than random misclassifications, common defensive voting filters fail. To counter this vulnerability, the authors evaluate an adversarial defense mechanism that adds randomized shadow simulations to training data. This defense increases model robustness against shadow attacks up to 40.93% and dramatically elevates attack difficulty with only a minor decrease in standard classification accuracy.
The attack relies on a single dominant light source and struggles in low-contrast diffuse lighting or multi-source environments, and it currently cannot enforce arbitrary target classes directly. System designers for autonomous vehicles and security-critical computer vision should integrate shadow-augmented training into their machine learning pipelines and maintain caution regarding single-sensor reliability in uncontrolled outdoor environments.
- Paper: Synthesizing Robust Adversarial Examples, Anish Athalye et al. (2017). Its expectation-over-transformation framework establishes how adversarial patterns can remain effective across changing viewpoints and lighting, a key premise of the source’s physically viable shadow attacks.
- Paper: Adversarial examples in the physical world, Alexey Kurakin et al. (2016). It first demonstrates that adversarial examples can survive printing and camera capture, grounding the source’s move from digital shadow patterns to real-world attacks.
- Paper: Adversarial Patch, Tom B. Brown et al. (2017). Its printable, scene-robust physical attack provides an early model for understanding how localized visual changes can fool classifiers outside the lab.
- Paper: Black-box Adversarial Attacks with Limited Queries and Information, Andrew Ilyas et al. (2018). Its treatment of query-limited, gradient-free attacks prepares readers for the source’s black-box search for effective shadow placements.
- Paper: Intriguing properties of neural networks, Christian Szegedy et al. (2014). Its foundational demonstration that tiny input changes can flip neural-network predictions establishes the adversarial vulnerability that the source exploits with natural shadows.
No sufficiently relevant recommendations were found.
