Monday 24 March 2025
The quest for stealthy adversarial attacks on autonomous vehicles has led researchers to develop a new technique that can evade detection by state-of-the-art defenses. The approach, dubbed AdvSwap, relies on wavelet-based high-frequency information swapping to generate covert adversarial examples.
Autonomous vehicles rely heavily on computer vision to navigate the road and make decisions in real-time. However, this reliance on complex algorithms makes them vulnerable to adversarial attacks, which can be designed to deceive these systems into making incorrect decisions. Adversarial attacks have been a growing concern in the field of autonomous driving, as they can potentially lead to accidents or compromise vehicle safety.
Researchers have been exploring various techniques to develop stealthy adversarial attacks that can evade detection by state-of-the-art defenses. One approach involves injecting noise into images or videos to manipulate their content and make them difficult for AI systems to recognize. However, these methods often result in visible distortions that can be detected by humans or automated systems.
AdvSwap takes a different approach by focusing on the high-frequency components of an image, which are responsible for its texture and fine details. By swapping this information between different images, the algorithm creates covert adversarial examples that are difficult to detect using traditional methods.
The AdvSwap technique involves several key steps. First, the algorithm uses wavelet transform to decompose an image into its high-frequency components, known as wavelet coefficients. These coefficients contain information about the texture and fine details of the image.
Next, the algorithm selects a set of target images that are designed to fool the autonomous vehicle’s perception system. The goal is to create adversarial examples that can be used to deceive the vehicle into making incorrect decisions.
The AdvSwap algorithm then swaps the high-frequency coefficients between the target images and the original image, creating a new set of adversarial examples. These examples are designed to mimic the original image while introducing subtle changes that can evade detection by traditional defenses.
To evaluate the effectiveness of AdvSwap, researchers conducted experiments on two popular traffic sign datasets: GTSRB and nuScenes. The results showed that AdvSwap was able to generate covert adversarial examples that could fool state-of-the-art object detectors with high accuracy.
Moreover, the algorithm demonstrated strong transferability across different classification models, making it a versatile tool for developing stealthy adversarial attacks on autonomous vehicles. The researchers also found that AdvSwap was effective in evading detection by common defenses, such as JPEG compression and shield-based defense mechanisms.
Cite this article: “Stealthy Adversarial Attacks on Autonomous Vehicles Using Wavelet-Based High-Frequency Information Swapping”, The Science Archive, 2025.
Stealthy Adversarial Attacks, Autonomous Vehicles, Computer Vision, Adversarial Examples, Wavelet Transform, High-Frequency Components, Image Manipulation, Object Detection, Transferability, Defense Evasion







