Skip to main navigation Skip to search Skip to main content

FIGhost: Fluorescent Ink-based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition

  • Shuai Yuan
  • , Guowen Xu*
  • , Hongwei Li
  • , Rui Zhang
  • , Xinyuan Qian
  • , Hangcheng Cao
  • , Qingchuan Zhao
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

Traffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost’s effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses. © 2026 IEEE. All rights reserved.
Original languageEnglish
Number of pages14
JournalIEEE Transactions on Dependable and Secure Computing
DOIs
Publication statusOnline published - 16 Feb 2026

Research Keywords

  • Fluorescent ink
  • Physical backdoor attack
  • Traffic sign recognition

Fingerprint

Dive into the research topics of 'FIGhost: Fluorescent Ink-based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition'. Together they form a unique fingerprint.

Cite this