Perception Warfare and Adversarial Manipulation in Modern Conflict
Robi Sen
Cognoscenti Labs, LLC
2026/07/09
Perception warfare is the deliberate shaping, degradation, or exploitation of how an adversary senses, interprets, and acts on the world through human operators, software, and machine perception stacks. In practice, it sits at the intersection of camouflage, deception, electronic warfare, cyber operations, optical interference, and adversarial machine learning, with the goal of changing what a target system believes to be true rather than simply destroying it.[1][2][3][4][5]
Overview
image 1: Optical emitters project structured light creating shapes in the air that drones turn away from seeing their wall.
A new conflict layer is emerging in which the decisive effect is not always physical destruction, but the manipulation of perception itself. This includes methods that deceive, confuse, disrupt, degrade, compromise, and, as part of broader attack chains, help enable the loss of reliable control over vehicles, sensors, or computers by corrupting the signals and data on which they rely.[2][4][5][6][1]
Although deception and camouflage are ancient practices, the widespread use of machine vision, autonomy, sensor fusion, and learning systems has created a new operational environment in which small physical changes can produce disproportionately large effects. In recent years, adversarial patches, synthetic camouflage, multispectral deception systems, and projector-based attacks have moved from academic demonstration toward practical defense relevance, including visible discussion tied to battlefield conditions in Ukraine and broader counter-autonomy programs.[7][8][9][10][2]
This matters because optical and sensor-directed effects are no longer only laboratory curiosities. Dazzlers, passive deception systems(in use for decades), structured light concepts, and adversarial examples all point toward the same larger trend: modern conflict is beginning to include deliberate attacks against the sensory and interpretive layers of autonomous and semi-autonomous systems.[2][4][5][7][21]
What perception warfare means
Perception warfare can be understood as competition over the adversary’s sensing and interpretation pipeline. That pipeline may include cameras, infrared imagers, LiDAR, radar, RF receivers, inertial sensors, edge processors, navigation software, operator displays, and the command systems that consume those outputs.[11][12][13][1][2]
The central idea is straightforward: if a system can be made to see the wrong thing, fail to see the right thing, or act on corrupted confidence estimates, then the resulting effect can be operationally equivalent to jamming, sabotage, or defeat. In autonomous or semi-autonomous systems, perception failure can cascade into navigation drift, route replanning, target misclassification, sensor handoff failure, or unsafe control actions.[5][8][14][15][16]
Perception manipulation
Perception manipulation is the application layer of perception warfare: it is how the effect is actually produced. Methods can be passive, active, or hybrid.[1]
Passive methods
Passive methods change the appearance or signature of an object, scene, or platform without radiating energy during use. Examples include adversarial patches, adaptive camouflage patterns, multispectral panels, geometric decoys, thermal shaping, and materials designed to bias machine classifiers while preserving acceptable human-visible camouflage.[4][17][18][19]
This category matters because passive methods scale well, can be low cost, and can remain in place for extended periods. Kallisto Shield, for example, is publicly described as a passive camouflage and deception kit intended to affect visual, infrared, thermal, radar, multispectral, SAR, and hyperspectral detection of military assets.[17][20][4]
Active methods
Active methods radiate or project energy to alter what a sensor perceives. These include optical dazzlers, structured light, projector-based adversarial attacks, spoofing, temporal modulation, false target injection, and dynamic decoys across optical, infrared, RF, or other bands.[21][22][23][24][5]
Active systems can be more adaptive than passive ones because they can respond to geometry, range, ambient conditions, and sensor behavior in real time. That makes them particularly relevant for camera-guided and autonomous vehicles, where carefully timed or spatially coded emissions may degrade detection, depth estimation, tracking, or control.[22][23][5][21]
Hybrid methods
Hybrid methods combine passive structure with active control. A platform may carry an adversarial physical surface, a thermal signature management layer, and a projector or LED array that emits scene-dependent patterns only when needed. This is where structured light, optical fuzzing, and adaptive multispectral deception begin to converge into a coherent engineering discipline.[15][25][26][5]
Adversarial machine learning
Adversarial machine learning is the study and exploitation of the brittleness of learning systems under intentionally crafted inputs. In the perception domain, this usually means manipulating what a model sees so that it misclassifies, fails to detect, localizes incorrectly, or produces unstable outputs under conditions where a human may see nothing unusual.[8][27][7][1]
This matters because modern vehicles, drones, and sensor systems increasingly depend on deep neural networks or learned subsystems for detection, segmentation, depth estimation, tracking, decision support, and sensor fusion. If those learned components can be predictably biased, then the attacker can influence downstream behavior without needing to destroy hardware.[14][26][28][1]
The field is now mature enough to support a useful taxonomy:
· Evasion attacks alter inputs at inference time to change model outputs.[7][1]
· Physical attacks embed those perturbations in real objects, lighting, textures, or projected patterns.[23][8][21]
· Transfer attacks target one model and exploit partial generalization to similar models.[8][7]
· Robustness and detection methods attempt to identify or resist those manipulations.[29][14]
These are not only technical curiosities. They are ways to produce real-world effects against systems that drive, fly, aim, classify, or cue other weapons and sensors.[2][14]
From deception to compromise and control
The most important strategic point is that perception manipulation is not limited to concealment. It can be part of a broader chain that progresses from deception to disruption, then to compromise, and, under some conditions, to functional takeover or loss of reliable control.[6][5][1][2]
A navigation or autonomy stack often depends on camera-derived or fused perception outputs to maintain position, avoid obstacles, classify scenes, select routes, track targets, or authorize actions. If those inputs are persistently corrupted, the system may drift, halt, re-route, mis-prioritize, expose itself, or hand control to fallback logic that may itself be vulnerable or poorly suited to the situation.[16][5][11][14][15]
In that sense, perception warfare overlaps with cyber and electronic warfare even when the initial attack surface is optical or physical. The attacker does not need to break encryption or penetrate a network first; inducing machine error at the sensor or model layer can still create mission-level compromise.[5][1][2][8]
Optical fuzzing and structured light
The optical fuzzer concept is a strong example of this evolution. The disclosed method trains a machine-learning system to adapt light transmitted from an array of emitters so that it affects image processing and navigation control in a camera-based navigation system. That framing is important because it treats light not merely as illumination or obscuration, but as a programmable attack surface against autonomy.[6][5]
Structured light broadens that concept further. Traditionally used for metrology, depth sensing, and imaging, structured light can also be used offensively or defensively to inject false geometric cues, degrade obstacle maps, distort optical flow, and interfere with depth estimation or classification.[26][11][15][22][23]
Projector-based adversarial attacks have already shown that transient projected patterns can cause object detectors and depth-estimation systems to fail under real-world conditions. A logical next step is the move from attacking a single object surface toward shaping larger perceptual volumes with multiple projectors or emitters, affecting the space through which a drone or vehicle observes or moves.[15][21][22][23][26]
Ukraine and the last decade of visible change
Over roughly the last decade, the public record has shifted from mostly theoretical discussion to a growing body of practical systems and battlefield-adjacent experimentation. Public reporting and company disclosures show passive deception systems, synthetic-data-driven evaluation of camouflage, projector-based attacks, and broader concern over AI-guided reconnaissance and targeting.[10][4][23][2][7]
Ukraine has been especially important as a forcing function because dense drone use, persistent ISR, rapid adaptation, and the need for low-cost battlefield asymmetries reward anything that can confuse, hide from, or redirect machine-enabled sensing. This does not mean every method is mature or decisively proven, but it does mean the paradigm has escaped the lab and entered the operational imagination of states, startups, and defense planners.[9][4][10][2]
Why this is a new conflict paradigm
The broader significance is that conflict is moving toward competition over cognitive and machine-mediated interpretation. In earlier eras, concealment was often about defeating a human observer. In the current era, it must increasingly defeat data pipelines, detection models, autonomy stacks, sensor fusion logic, and operators interpreting machine-curated displays.[4][17][26][1][2]
That creates several asymmetries:
· Small, low-cost changes can create outsized effects if they hit a brittle learned subsystem.[7][8]
· Effects can be reversible, deniable, and hard to attribute because they may leave no obvious physical damage.[23][1]
· Tools can scale quickly from software to materials, panels, projectors, emitters, and decoys.[25][21][4]
· The same techniques can support offense, defense, deception, testing, and hardening.[30][14]
In practical terms, the side that becomes proficient at augmenting operations with perception manipulation will gain advantages in survivability, target protection, denial, confusion, and autonomy disruption.[2][4]
What this means for the United States
The United States has strong underlying capabilities in machine learning, optics, microelectronics, sensing, EW, autonomy, and defense integration, but that does not automatically translate into leadership in perception warfare. Leadership will require treating perception manipulation as a serious discipline rather than a niche curiosity.[3][30][1][2]
That implies several lines of effort:
· Build doctrine and threat models for perception warfare across services and mission sets.[30][1]
· Fund offensive and defensive R&D in passive, active, and hybrid counter-perception methods.[25][26][4]
· Develop realistic test and evaluation infrastructure for adversarial perception, including synthetic environments and live hardware-in-the-loop ranges.[10][14][29]
· Integrate optics, structured light, RF deception, cyber, and autonomy research instead of treating them as separate stovepipes.[26][5][2]
· Harden fielded perception stacks while building indigenous capability to impose perception effects on adversaries.[14][30]
The strategic argument is simple: this field is growing, the barriers to experimentation are falling, and the military value of perception effects is increasing. If the United States does not lead, others will shape the doctrine, tools, and norms of a conflict space that is already forming.[4][30][2]
Closing assessment
Perception warfare is best understood as the organized contest to shape what machines and people believe they are seeing, and what they do next because of it. Perception manipulation and adversarial machine learning are not separate from that contest; they are among its most important mechanisms.[1][2][7]
Used well, these methods can hide assets, degrade detection, confuse tracking, redirect navigation, compromise autonomy, and create pathways to broader system disruption. They have existed in quieter forms for years, but recent advances in AI-enabled sensing, autonomy, and battlefield adaptation suggest that a new paradigm of conflict is emerging faster than many institutions are prepared to recognize.[9][22][5][10][2][4]
As these systems become more robust and more deeply integrated into regular warfare, the manipulation of human and machine sensorium will become both more important and more contested. Early effects may appear simple, but capable adversaries will adapt. The more durable advantage will come from combining perception effects with terrain, camouflage, sensor fusion, autonomy, EW, and conventional operations rather than treating them as isolated tricks.
Future systems may use terrain, surfaces, light, materials, and dynamic signatures to create false cues or deny reliable interpretation across a battlespace. In that environment, perception warfare will not merely deceive sensors. It will shape decision cycles, platform behavior, and the balance of tactical advantage in increasingly automated battlespaces.[1][2]
References
1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2023.pdf
2. https://techinsightdaily.com/982/adversarial-intelligence-how-counter-drone-ai-uses-computer-vision-attacks-against-autonomous-weapons/
3. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf
4. https://defence-blog.com/spanish-startup-creates-camouflage-for-ai-battlefield/
5. https://patents.google.com/patent/US12315233B1/en
6. https://patents.justia.com/patent/20250285421
7. https://arxiv.org/pdf/1911.05268.pdf
8. https://beerkay.github.io/cs529/content/papers/yuan.pdf
9. https://nextgendefense.com/kallisto-shield-camouflage-system/
10. https://www.linkedin.com/pulse/press-release-evaluation-camouflage-concealment-deception-systems-i6zkf
11. https://www.archivesoftransport.com/index.php/aot/article/view/238
12. https://www.terma.com/products/radars/3d-drone-detection/
13. https://www.spotterglobal.com/drone-detection-ax-series
14. https://dl.acm.org/doi/10.1145/3450267.3450535
15. https://www.ecva.net/papers/eccv_2020/papers_ECCV/papers/123680732.pdf
16. https://arxiv.org/abs/2311.12722
17. https://publica.fraunhofer.de/entities/publication/48da286d-c6a4-406e-a473-35273f347ef8
18. https://appl.ai/projects/adversarialai
19. https://www.mdpi.com/1424-8220/26/6/1895
20. https://www.kallistoshield.eu
21. https://arxiv.org/pdf/2209.09652.pdf
22. https://arxiv.org/pdf/2512.24792.pdf
23. https://www.themoonlight.io/en/review/transient-adversarial-3d-projection-attacks-on-object-detection-in-autonomous-driving
24. https://www.unmannedsystemstechnology.com/2016/09/invisage-launches-micro-lidar-module-for-autonomous-drone-flight/
25. https://www.swri.org/what-we-do/internal-research-development/2021/defense-security/enhanced-adaptive-camouflage-using-generative-adversarial-networks-10-r6136
26. https://elight.springeropen.com/articles/10.1186/s43593-025-00102-z
27. https://pmc.ncbi.nlm.nih.gov/articles/PMC10427626/
28. https://www.sciencedirect.com/science/article/pii/S2214212622002423
29. https://umu.diva-portal.org/smash/get/diva2:2053102/FULLTEXT01.pdf
30. https://www.energy.gov/topics/artificial-intelligence



Perception management can be extended to strategic level applications as well. Let’s say you start development of weapons system or family of systems based on a new technology that would be extremely expensive to defeat (like Regan’s Star Wars efforts). Perhaps the intention is never to produce them, but only to force your opponents into excessive spending that will decimate their economy. Did Star Wars break the USSR? Were those systems actually intended to be built? We’ll likely never know.
Excellent framing, Robi. The transparent battlefield does not eliminate concealment; it shifts the contest from hiding platforms to corrupting the sensing-to-decision chain. As autonomy spreads, camouflage, EW, cyber, and adversarial ML become a single fight over trust in the data—and therefore tempo. The lasting advantage will go to forces that can impose, detect, and recover from perceptual uncertainty fastest.