Search...

AI-based vulnerability has been identified in modern vehicles

AI-based vulnerability has been identified in modern vehicles

Researchers have identified an unexpected weakness in AI systems used in autonomous vehicles and unmanned aerial vehicles (UAVs). According to the findings, some vision–language models (VLMs) can interpret text seen on road signs and in public spaces not just as informational content, but as direct commands that should be executed.

In simulated driving scenarios conducted for testing purposes, the autonomous system behaved correctly under normal conditions, responding appropriately to a stop sign and a pedestrian crossing. However, when a sign containing directive phrases such as “turn” or “proceed” entered the camera’s field of view, the same system interpreted the text as an instruction. As a result, it changed its decision and attempted a potentially unsafe maneuver, even though the surrounding environment had not changed. Since this occurred without any differences in road layout, traffic lights, or pedestrian movement, the risk is linked specifically to misleading or manipulated text on road signs.

Experts describe this method as an indirect influence, meaning that a malicious actor could affect an AI model’s decisions without injecting code, simply by placing visible text in the environment. Tests also suggest that the language used is not the main determining factor: commands written in different languages, including mixed-language forms, can produce similar outcomes. In addition, the way the text is presented such as color contrast, font, and placement has been noted as another factor that may shape the system’s response.

Similar results have been observed in drone-related scenarios. For example, it was reported that adding certain words can cause the system to misidentify objects. This supports the concern that some autonomous systems rely not only on visual cues but also place excessive trust in written language within the image.

Experts emphasize that traditional cybersecurity measures do not fully address this type of scenario. This is because the attack may not involve a digital file or conventional malware but can instead be carried out through text placed in the physical world. As a result, reducing this risk is largely seen as the responsibility of system developers and manufacturers.

Recommendations highlight that autonomous decision-making systems should be strengthened with additional validation mechanisms so that public text is treated as contextual information rather than as executable instructions. Until such safeguards are widely implemented, users are advised to be cautious when using autonomous features and to maintain manual oversight, especially in higher-risk situations

© 2011-2026 All rights reserved