Researchers tricked Tesla Autopilot into steering into oncoming traffic by using stickers on the lane markings; Tesla has since patched, but questions remain
Cory Doctorow / Boing Boing :
Context & Ripple Effects
The sticker attack is the latest entry in a running file on Autopilot's vulnerability to small visual perturbations: researchers placed stickers on lane markings and the system steered toward oncoming traffic, with Tesla responding that it had already shipped a patch. The team behind it fits a pattern — Tencent's Keen Lab has spent years exposing Autopilot flaws, making Tesla one of the most probed driver-assistance systems in the field.
What keeps the story alive past the patch is the surrounding record: an [[a:930455|NTSB preliminary report on a fatal Model X crash found Autopilot active seconds before impact]], and a year later researchers showed projected fake road signs could make Autopilot brake or change speed in under a second (the projection attack). Patch-by-patch fixes are colliding with a question regulators have not answered: how do you certify a vision system against adversaries who can alter the road itself?
First-order effects
- Tesla owners running Autopilot receive a software update that changes lane-keeping behavior, while the researchers' demonstration shows a few dollars of stickers can defeat the system's lane detection in the real world.
Second-order effects
- Adversarial testing becomes a standing beat for security labs like Keen Lab, forcing Tesla into a reactive cycle where each published exploit triggers a patch and another round of scrutiny from NTSB-style investigators already examining Autopilot-involved crashes.
Third-order effects
- If small physical-world perturbations keep defeating camera-based lane keeping, certification regimes for driver-assistance systems will likely need adversarial-robustness requirements rather than crash statistics alone — a structural shift that lands hardest on camera-first designs like Tesla's.
The trend: Driver-assistance systems are moving from crash-driven oversight toward adversarial-security review, as researchers repeatedly show that cheap manipulations of the visual environment can defeat camera-based autonomy.