Researchers tricked Tesla Autopilot into steering into the oncoming traffic lane by using stickers on the lane markings; Tesla says it has now patched the flaw
Researchers from Tencent Keen Security Lab have published a report detailing their successful attacks on Tesla firmware … Tweets: @dan_rowinski , @davezatz , and @nash076 Tweets: @dan_rowinski : This is not something easily “patched.” Adversarial examples are a systemic problem for neural networks. It's not just a bug you fix with a few new lines of code. http://twitter.com/... Dave Zatz / @davezatz : 1) We already knew Teslas can be pulled off target. Although the weaponizing is new. 2) An over-the-air update to mitigate is way more efficient and effective than a traditional automaker's recall for repair. http://twitter.com/... @nash076 : Stickers. Stickers can make a Tesla drive into oncoming traffic. Maybe - JUST MAYBE - we're moving too fast on this “autonomous automobile” thing. http://twitter.com/...
Context & Ripple Effects
This is the latest entry in a running series: Tencent Keen Security Lab has exposed Autopilot flaws repeatedly, as a profile of the lab published days later documents, and it follows an NTSB preliminary report finding Autopilot was active when a Model X sped up and steered left before a fatal March crash. What is new here is the attack surface — stickers placed on real lane markings that fool the vision system in the physical world, not just in simulation.
The debate in the immediate reaction frames why it matters: one commentator argues adversarial examples are a systemic weakness of neural networks rather than a bug fixable in code, while another notes Tesla's over-the-air update is far faster than a traditional automaker's recall.
First-order effects
- Tesla ships an over-the-air firmware patch to close the specific sticker exploit, avoiding a physical recall that a conventional automaker would have needed for the same defect.
- Owners using Autopilot remain exposed to the broader class of attack until perception itself hardens — the patch addresses this trigger, not the underlying model's susceptibility to manipulated lane markings.
Second-order effects
- The attack template spreads: by late 2020 researchers show Autopilot can be made to change speed or brake abruptly by projecting phantom road signs or people for under a second (projection-based spoofing), confirming physical-world adversarial inputs generalize beyond stickers.
- Keen Lab's track record turns coordinated disclosure into a de facto audit channel for Tesla, pressuring the company to keep shipping rapid OTA mitigations rather than disputing findings.
Third-order effects
- If each patch closes only the demonstrated trigger while the neural network stays vulnerable to adversarial perturbations, camera-reliant driver-assistance systems will need adversarial robustness as a formal part of their safety case — a gap regulators like NHTSA have barely begun to test.
- The pattern compounds Tesla's safety-record problem: leaked customer complaint data covering self-acceleration and other FSD issues from 2015 to 2022 shows how accumulated defect disclosures feed regulatory and litigation exposure over time.
The trend: Physical-world adversarial attacks are becoming a recurring stress test of camera-based driver assistance, with over-the-air patches absorbing each disclosed flaw without resolving the underlying fragility.