DOI: 10.1177/09544070261475747 ISSN: 0954-4070

Enhancing adversarial robustness of lightweight neural networks for on-vehicle traffic sign recognition systems

Yun Zhao, Shang Gao, Jieliang Zhao

In recent years, with the rapid development of autonomous driving technology, lightweight neural networks (LNNs) have been increasingly applied in-vehicle and edge computing devices. A growing number of studies have focused on deploying LNNs in resource-constrained environments to achieve real-time traffic sign recognition, obstacle detection, and other tasks. However, while LNNs maintain high inference efficiency, their robustness has become an increasingly important concern. Research has shown that adversarial attacks targeting traffic signs can significantly disrupt the predictions of LNNs, leading to misclassifications. To enhance the adversarial robustness of LNNs, we propose TRADES-JR, a TRADES loss function guided by Jacobian regularization. This approach simultaneously considers the prediction distribution differences between clean and adversarial samples while penalizing the Frobenius norm of the network output’s Jacobian with respect to the input. By constraining the sensitivity to input perturbations, our method enhances the adversarial robustness of LNNs. We evaluate the proposed algorithm on the GTSRB and TSRD datasets. The results demonstrate that our method significantly improves the adversarial robustness of LNNs under both white-box and black-box attacks. Therefore, this method enables LNNs to maintain robust and high-accuracy traffic sign recognition even in adversarial environments, thereby enhancing the reliability of the autonomous driving system.

More from our Archive