Paper accepted at NDSS 2025: “On the Realism of LiDAR Spoofing Attacks”
Prior work on LiDAR spoofing attacks evaluated them only under limited conditions — a stationary or slow-moving vehicle at close range — leaving attacks at high speed and long distance largely unverified. This work systematically examines how far such attacks hold up under realistic conditions, using a real vehicle and a real LiDAR unit.
In experiments on a vehicle running the open-source autonomous driving software Autoware, the team showed that LiDAR sensing can be disabled from 110 m away against a vehicle traveling at 60 km/h. The attack can not only erase the perception of obstacles, risking collisions or a system shutdown, but also make the vehicle perceive obstacles that are not there and brake abruptly. The paper discusses the implications and possible countermeasures.
[Paper]
Takami Sato*, Ryo Suzuki*, Yuki Hayakawa*, Kazuma Ikeda, Ozora Sako, Rokuto Nagata, Ryo Yoshida, Qi Alfred Chen, Kentaro Yoshioka, “On the Realism of LiDAR Spoofing Attacks against Autonomous Driving Vehicle at High Speed and Long Distance,” Network and Distributed System Security Symposium (NDSS 2025), San Diego, CA, USA, February 2025. (* co-first authors)