Seoul Tech Unveils AI Framework for Vision System Testing

Seoul National University of Science & Technology

In computer vision and robotics, ensuring that AI systems remain reliable under real-world conditions is a growing challenge. Deep neural network (DNN)-based vision systems are increasingly used in safety-critical applications such as autonomous driving, where misinterpreting a traffic sign could potentially lead to unsafe decisions. Everyday wear and tear can subtly alter traffic signs, raising questions about whether naturally occurring damage could also expose vulnerabilities in AI-based recognition systems.

To understand and address the problem, a research team led by Associate Professor Seong Tae Kim from Kyung Hee University and Assistant Professor Hong Joo Lee from SEOULTECH developed Adversarial Wear and Tear (AdvWT)—a framework that exploits natural wear and tear as an adversarial signal. Their findings were made available online on February 3, 2026, and published in Volume 23, Issue 3 of IEEE Transactions on Dependable and Secure Computing on May 12, 2026.

"We focused on traffic signs because they are exposed to weather and environmental damage throughout their lifetime, and their accurate recognition is essential for safety-critical applications," says Dr. Lee. "Unlike temporary optical attacks, natural deterioration can persist until a physical object is repaired or replaced."

To create AdvWT, the team trained a generative image-to-image translation model to learn the visual characteristics of damaged and undamaged traffic signs. The model, based on StarGAN-v2, learned a latent "damage style" representation that can reproduce diverse forms of realistic deterioration while preserving the identity and meaning of the sign.

By progressively adjusting the damage representation, they generated signs that looked naturally degraded but were more likely to be misclassified by an AI system. In a human study involving 32 participants, AdvWT-generated images received high naturalness ratings, closely matching the perceived realism of real damaged traffic signs.

The framework was evaluated against two traffic-sign datasets and tested against eight recognition architectures. Across the evaluated models and datasets, AdvWT achieved near-perfect attack success rates on lightweight CNNs such as ResNet-18 and MobileNet, while also remaining effective against transformer-based models. AdvWT also achieved the highest average transferability across most tested model combinations, suggesting that the adversarial perturbations could transfer across different model architectures.

To test the framework in a physical setting, the researchers printed clean and adversarial speed-limit signs and photographed them under different distances, viewing angles, and indoor and outdoor conditions. The resulting images remained effective at misleading the traffic-sign classifier, showing that the adversarial effect persisted after printing and recapturing under varied physical conditions.

The researchers also demonstrated that the same bidirectional model could be used to restore naturally damaged traffic signs, suggesting potential applications beyond adversarial testing. Importantly, training models with AdvWT-generated damaged signs improved their ability to generalize to real-world damaged traffic signs, suggesting that simulated natural deterioration could be used to identify and strengthen weaknesses in vision systems.

"Building reliable AI requires more than improving average performance. It requires continuously identifying where AI systems fail, understanding why those failures occur, and using those insights to make the systems more robust. Over the next five to ten years, research in this direction could play an important role in developing AI systems that can be deployed more reliably in real-world, high-stakes domains such as healthcare and finance," says Dr. Kim.

For autonomous driving, the findings highlight the need to evaluate how natural damage affects traffic-sign recognition and improve AI robustness to real-world deterioration.

Reference

Title of original paper: Adversarial Wear and Tear: Exploiting Natural Damage for Generating Physical-World Adversarial Examples

Journal: IEEE Transactions on Dependable and Secure Computing

DOI: https://doi.org/10.1109/TDSC.2026.3660107

About the institute Seoul National University of Science and Technology (SEOULTECH)

Seoul National University of Science and Technology, commonly known as 'SEOULTECH,' is a national university located in Nowon-gu, Seoul, South Korea. Founded in April 1910, around the time of the establishment of the Republic of Korea, SEOULTECH has grown into a large and comprehensive university with a campus size of 504,922 m2. It comprises 10 undergraduate schools, 35 departments, 6 graduate schools, and has an enrollment of approximately 14,595 students.

Website: https://en.seoultech.ac.kr/

About Assistant Professor Hong Joo Lee

Dr. Hong Joo Lee is an Assistant Professor in the Department of Applied Artificial Intelligence at Seoul National University of Science and Technology (SEOULTECH). He received a Ph.D. in 2023 from Prof. Yong Man Ro's group at KAIST and completed his postdoctoral research at Prof. Nassir Navab's group at TUM. His lab is dedicated to advancing Reliable AI for safety-critical applications such as autonomous driving and healthcare. His research focuses on developing trustworthy AI systems through robustness, interpretability, privacy preservation, and data integrity.

About Associate Professor Seong Tae Kim

Dr. Seong Tae Kim is an Associate Professor of Computer Science and Engineering at Kyung Hee University, South Korea. He earned his B.S. from Korea University (2012) and his M.S. and Ph.D. from KAIST (2014, 2019). Previously, he was a visiting researcher at the University of Toronto (2015) and a senior research scientist at the Technical University of Munich (2019–2021). With over 90 peer-reviewed papers to his credit, his research focuses on multimodal AI, explainable AI, and data-efficient deep learning.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.