/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers show Tesla's Autopilot can be tricked to change speeds or stop abruptly by projecting virtual road signs or people in front of it for under a second

Aatif Sulleyman / Newsweek :

Newsweek Aatif Sulleyman

Context & Ripple Effects

This is the second documented class of adversarial attack on Tesla's driver-assist stack: in 2019 researchers showed stickers on lane markings could steer Autopilot into oncoming traffic (initially reported) before Tesla issued a patch (follow-up). The new work escalates the threat model — instead of physically modifying the road, an attacker only needs to project imagery at the windshield-facing cameras for under a second to trigger speed changes or abrupt stops.

The timing matters because Tesla was already defending Autopilot's design choices: IIHS had warned that names like Autopilot lead drivers to overestimate capabilities (IIHS naming critique), and an Autopilot trial over a fatal 2018 crash is examining whether Tesla studied how fast drivers can retake control (the 2024 trial coverage). Each successful spoof feeds directly into that evidentiary record.

First-order effects

  • Tesla faces another demonstrated perception vulnerability its camera-based system cannot trivially distinguish from real signage, forcing engineering response beyond the 2019 patch.
  • Owners using Autopilot's speed control are exposed to a cheap physical-world attack — a projection lasting under a second — that can cause braking behavior without any tampering with the vehicle itself.

Second-order effects

  • Rivals betting on sensor redundancy beyond cameras, notably Waymo whose Austin robotaxi fleet operates without human monitors while Tesla's ~30-vehicle deployment still uses safety drivers, gain a concrete safety-differentiation argument from each new spoofing result.
  • The accumulating demonstrations give litigators and safety investigators material for exactly the kind of scrutiny underway in the fatal-crash trial, raising the cost of Tesla's camera-only positioning.

Third-order effects

  • If brief-projection attacks keep defeating vision-only systems faster than patches close them, the industry-wide question shifts from whether driver assistance can be spoofed to whether regulators require multi-sensor validation before high-speed automation ships to consumers.
  • The recurring gap between what 'Autopilot'-style branding implies and what the systems demonstrably do points toward standardized capability disclosure rules for automated driving features.

The trend: Adversarial research against camera-based driver assistance is accumulating faster than patches, steadily shifting the debate toward redundant sensing requirements and stricter disclosure rules for automated driving features.

Discussion

  • @wired @wired on x
    With just a few frames of a road sign injected on a billboard's video, researchers could trick Tesla's autopilot system into automatically stopping without warning https://www.wired.com/...
  • @kevin_raposo @kevin_raposo on x
    Researchers found they could stop a Tesla by flashing a few frames of a stop sign for less than half a second on an internet-connected billboard https://www.wired.com/...
  • @mark_riedl Mark O. Riedl on x
    Good thing electric billboards can't be hacked https://twitter.com/...
  • @getjeda Jeda Products on x
    Tesla will likely figure out a way to tackle this. What're your thoughts? It's a bit disconcerting, but no doubt something that could be fixed via a software update. https://www.wired.com/...
  • @tuna_tugcu Tuna Tugcu on x
    New challenge for autonomous driving: Can stop a car by displaying images on a billboard for a split-second https://www.wired.com/...
  • @mitsloanexperts MIT Sloan Experts on x
    “Just like a self-driving car learns over time and benefits from the data being fed back to the company from all drivers, Song says that the same dynamic is at work with the hearing aid, which learns how to process signals better over time.” https://twitter.com/...
  • @hkanji Hussein Kanji on x
    How to beat Tesla autopilot. Every single time. https://www.wired.com/...
  • @oliviasolon Olivia Solon on x
    Researchers have shown that you can trick a Tesla in autopilot into changing speed, swerving or stopping abruptly, by projecting fake road signs or virtual objects in front of them https://www.newsweek.com/...