Yes—under specific experimental conditions, small physical changes to a real stop sign caused a road-sign classifier to label it as something else, even while people could still recognize it as a stop sign. In a 2018 study, black-and-white stickers produced the researchers’ chosen wrong label in all tested laboratory images and in 84.8% of video frames captured from a moving vehicle. Those results apply to the study’s target classifier, not to every self-driving car or traffic-sign system.
What the researchers changed—and what the classifier did
In “Robust Physical-World Attacks on Deep Learning Visual Classification,” presented at CVPR 2018, Kevin Eykholt and co-authors tested whether a deliberately designed physical pattern could make a vision classifier misclassify a real road sign. Their headline stop-sign experiment used black-and-white stickers. The classifier assigned the sign a targeted incorrect label, while the sign remained recognizable to people.
The method, called Robust Physical Perturbations (RP2), was designed for the physical world rather than for changing a single digital image. A pattern that works in one image may fail when the camera moves or conditions change, so the researchers evaluated images under controlled laboratory conditions and video recorded from a moving vehicle.
The study and contemporary reporting described other visual forms, including fading and camouflage-like graffiti or art. These are experimental examples, not directions for changing real traffic signs.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
What the 100% and 84.8% results mean
| Result | What was measured | What it does not mean |
|---|---|---|
| 100% | The target classifier produced the researchers’ targeted misclassification for all tested laboratory images of the sticker-modified stop sign. | It does not mean every model, camera, or real-world encounter would fail. |
| 84.8% | The target classifier produced the targeted misclassification in 84.8% of the captured video frames in the moving-vehicle field test. | It is a share of recorded frames, not a failure rate for vehicles, trips, or all autonomous-driving systems. |
Both figures are reported in the IEEE/CVF CVPR 2018 study. The moving-vehicle result matters because it tests more than a fixed laboratory image, but it remains a result for the tested sign, target classifier, and recorded conditions.
Why a sign can look right to a person but wrong to a model
People generally interpret a stop sign using its overall shape, color, lettering, and context. A machine-learning classifier instead bases its decision on learned visual patterns. It need not weigh those features in the same way a person does. RP2 sought a physical pattern that shifted the classifier’s learned cues while preserving the sign’s human-recognizable appearance.
Rank #2
- Use scikit-learn to track an example ML project end to end
- Explore several models, including support vector machines, decision trees, random forests, and ensemble methods
- Exploit unsupervised learning techniques such as dimensionality reduction, clustering, and anomaly detection
- Dive into neural net architectures, including convolutional nets, recurrent nets, generative adversarial networks, autoencoders, diffusion models, and transformers
- Use TensorFlow and Keras to build and train neural nets for computer vision, natural language processing, generative models, and deep reinforcement learning
That gap between human recognition and machine classification is the central point: a change can be visually subtle to a person yet influential to a particular model. It does not show that the system has no ability to recognize signs, or that a sign can be made invisible to every camera.
What this experiment does—and does not—establish
It establishes a specific physical-world vulnerability
The study showed that targeted adversarial patterns can affect a real road sign in both laboratory images and moving-vehicle footage. Physical attacks are harder to make reliable than digital image edits because distance, viewing angle, lighting, background, motion, and camera processing can all affect the captured pattern.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
It does not establish a universal self-driving-car failure
The results concern evaluated standard-architecture road-sign classifiers and the target model used for the headline test. They do not establish that every autonomous vehicle, commercial perception stack, or traffic-sign recognition system would make the same error. The study was evidence of a security and safety risk, not a finished attack product or a universal exploit.
It was not a standardized benchmark
The authors proposed a two-stage evaluation methodology because, at the time, there was no standardized procedure for assessing robust physical adversarial examples. Results from one setup therefore should not be treated as directly comparable to every later model or test without accounting for differences in architecture, data, cameras, and conditions.
Rank #4
What the finding means for road-perception safety
The practical lesson is not that a single sticker experiment predicts how a deployed vehicle will behave. It is that safety evaluations should test perception systems against physical-world conditions, including adversarially altered appearances, rather than relying only on ordinary images or digital tests.
- Test across conditions: Vary viewing angle, distance, lighting, backgrounds, motion, and camera processing; a pattern’s effect may not persist across them.
- Measure the right outcome: Distinguish a targeted wrong label from an object that disappears, and report laboratory and field results separately.
- Check system-level safeguards: Evaluate whether sign interpretation is cross-checked through independent sensors, other visual evidence, or rule-based checks. The cited experiment does not validate any one defense or guarantee that redundancy prevents failure.
- Avoid overgeneralizing a single model: Compare architectures and training data, and test the actual system and operating conditions relevant to a deployment.
The 2018 result is a clear demonstration that physical appearance can exploit a classifier’s learned features. It is not evidence that all autonomous vehicles can be fooled in the same way, nor does it identify a universally effective defense.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

