TLDR: the authors demonstrate that it's possible to apply minor perturbations to signs (for instance, rectangular stickers) that don't significantly change the appearance to humans but cause a classifier to confuse a stop sign with a speed-limit sign.
https://arxiv.org/abs/1707.08945
TLDR: the authors demonstrate that it's possible to apply minor perturbations to signs (for instance, rectangular stickers) that don't significantly change the appearance to humans but cause a classifier to confuse a stop sign with a speed-limit sign.