Adversarial Robustness and Vulnerability Assessment of Modified OverFeat CNN Perception Models Against Physical-World Optical Attacks in Autonomous Driving Systems
- Authors
-
-
Abey city
LautechAuthor
-
- Keywords:
- Adversarial Robustness, OverFeat CNN, Physical-World Attacks, Optical Adversarial Attacks, Autonomous Driving Systems, Vulnerability Assessment
- Abstract
-
Abstract
The deployment of deep learning-based perception systems in autonomous vehicles has revolutionized self-driving technology, yet these models remain critically vulnerable to adversarial attacks that can compromise safety and reliability. While substantial research has focused on digital adversarial perturbations, the gap between digital threat models and physically realizable optical attacks in real-world driving environments remains insufficiently addressed. This study presents a comprehensive vulnerability assessment of modified OverFeat Convolutional Neural Network (CNN) perception models against physical-world optical adversarial attacks, including adversarial lens flares, structured light perturbations, and camera-side optical manipulations. The research employs a hybrid methodology combining digital simulation of optical attack vectors with physical validation using a custom-built testbed featuring controlled lighting environments and camera systems. Quantitative evaluation reveals that modified OverFeat models achieve baseline detection accuracy of 89.4% under clean conditions, which degrades to 46.2% under adversarial lens flare attacks, representing a 43.2 percentage point reduction in detection performance. Transformer-based architectures demonstrate systemic depth spoofing vulnerabilities, while lightweight CNNs exhibit higher safety-critical error rates of 31.7% under optical attack conditions. The proposed adversarial-aware risk assessment framework establishes deployable safety thresholds and mitigation strategies compliant with ISO 21448 (SOTIF) standards. These findings provide critical insights for developing robust perception systems capable of maintaining operational safety under physical adversarial conditions, with implications for autonomous vehicle manufacturers, safety regulators, and AI security researchers.
- Downloads
- Published
- 08/24/2026
- Section
- Articles
- License
-
Copyright (c) 2026 Abey city (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
