On the Realism of LiDAR Spoofing Attacks against Autonomous Driving Vehicle at High Speed and Long Distance

Takami Sato (UCI)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Autonomous Vehicles

Overview

This talk, presented by Rio Suzuki from Ko University and based on joint work with Professor Alfred and Takami Sato from UCI, delves into the critical security vulnerabilities of LiDAR (Light Detection and Ranging) systems in autonomous vehicles (AVs). The core focus is on demonstrating the realism and severe consequences of LiDAR spoofing attacks—specifically, removal attacks—against moving AVs at high speeds and long distances. These attacks aim to either inject non-existent objects into the AV's perception or, more dangerously, remove actual obstacles from its view, potentially leading to catastrophic collisions.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to LiDAR's role and spoofing vulnerability
  2. 2:00 Key limitations of prior LiDAR spoofing research identified
  3. 4:00 Research question and overview of project contributions
  4. 4:40 MVS system: Long-distance LiDAR detection using IR camera
  5. 6:40 Introducing novel adaptive HFR attack against new LiDARs
  6. 8:00 Explaining how adaptive HFR bypasses pulse fingerprinting
  7. 9:40 Real-world spoofing attack at high speed (60km/h)
  8. 10:20 End-to-end attack: Autonomous vehicle crashes due to spoofing

On the Realism of LiDAR Spoofing Attacks against Autonomous Driving Vehicle at High Speed and Long Distance

Speakers: Takami Sato (UCI)

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=ehENTgMxZ7c

Overview

This talk, presented by Rio Suzuki from Ko University and based on joint work with Professor Alfred and Takami Sato from UCI, delves into the critical security vulnerabilities of LiDAR (Light Detection and Ranging) systems in autonomous vehicles (AVs). The core focus is on demonstrating the realism and severe consequences of LiDAR spoofing attacks—specifically, removal attacks—against moving AVs at high speeds and long distances. These attacks aim to either inject non-existent objects into the AV's perception or, more dangerously, remove actual obstacles from its view, potentially leading to catastrophic collisions.

The research directly addresses significant limitations identified in prior studies, which largely focused on stationary setups, low-speed scenarios, or standalone LiDAR sensors rather than integrated AV systems. Furthermore, it investigates the efficacy of these attacks against new generation LiDARs equipped with advanced interference rejection mechanisms like pulse fingerprinting. By developing a novel attack system and methodology, the researchers successfully demonstrated end-to-end spoofing attacks that bypass modern defenses and trigger critical safety failures in a popular autonomous driving software stack, underscoring the urgent need for enhanced security measures in self-driving technology.

This work is of paramount importance to the autonomous driving industry, security researchers, and regulatory bodies. As companies like Waymo and Zoox increasingly rely on LiDAR as a primary sensor for 3D environment perception, validating and mitigating these vulnerabilities is crucial for ensuring the safety and trustworthiness of future autonomous transportation. The findings highlight that despite advancements in LiDAR technology, fundamental design principles can still be exploited, demanding a re-evaluation of current security paradigms for AV sensors.

Background

▶ Watch: Introduction to LiDAR's role and spoofing vulnerability (0:00)

LiDAR technology forms the backbone of many advanced autonomous driving systems, providing high-resolution 3D point cloud data essential for precise object detection, mapping, and navigation. The fundamental principle involves the LiDAR unit emitting laser pulses and then measuring the time-of-flight for these pulses to reflect off objects and return to the sensor. Knowing the speed of light and the laser's angle, the system can accurately determine the distance and precise 3D position of objects in its environment. This capability allows AVs to build a comprehensive, real-time 3D model of their surroundings, enabling informed decision-making for path planning and obstacle avoidance.

However, this reliance on external light reflections inherently makes LiDAR vulnerable to external lasers. Attackers can exploit this by projecting their own lasers into the LiDAR sensor. Such LiDAR spoofing attacks can manifest in two primary ways: injecting fake objects into the LiDAR's data stream, leading the AV to perceive non-existent obstacles, or more critically, performing removal attacks, where actual objects are made to disappear from the AV's perception. The latter poses a direct safety threat, as an AV failing to detect a real obstacle could lead to a severe collision.

Despite the critical nature of these vulnerabilities, prior research faced several key limitations that hindered the demonstration of realistic, real-world attacks:

  1. Limited Realism in Movement and Distance: Many previous studies focused on stationary LiDAR setups or scenarios involving moving vehicles at very low speeds (around 5 kilometers per hour) and short distances (approximately 15 meters), often in cross-lane configurations. These conditions do not accurately represent the dynamic and complex environments autonomous vehicles operate in. A major challenge in achieving realistic attacks against moving targets was the lack of practical systems for accurately detecting and tracking the target LiDAR over distance.
  2. Absence of Closed-Loop Evaluation: Prior work typically evaluated attacks against standalone LiDAR sensors rather than fully integrated autonomous driving systems. This meant that the actual end-to-end impact on an AV's decision-making and safety was unclear. There was a lack of dedicated laser systems designed for stable, continuous attacks against moving targets, preventing comprehensive closed-loop evaluations.
  3. Neglect of New Generation LiDAR Defenses: Newer generations of LiDAR sensors incorporate advanced interference rejection mechanisms, such as pulse fingerprinting. This feature authenticates received laser pulses by verifying unique signal shapes or intervals, making these LiDARs more resistant to conventional spoofing attempts that rely on simple, unauthenticated laser projections. However, the security implications and potential vulnerabilities of these advanced features had not been thoroughly investigated, leaving a critical gap in understanding the resilience of modern LiDARs.

Motivated by these gaps, the presented research sought to answer a fundamental question: "Can LiDAR spoofing attacks actually have end-to-end safety impacts in practical autonomous driving scenarios?" By addressing the limitations of prior work, the researchers aimed to provide a more realistic and comprehensive assessment of LiDAR security in the context of modern AVs.

Key Findings

▶ Watch: Research question and overview of project contributions (4:00)

The research presented several significant contributions and key findings that advance the understanding of LiDAR security in autonomous driving:

  1. Development of the Moving Vehicle Spoofing System (MVS System): A novel, three-subsystem attack platform was designed and implemented, enabling stable and accurate tracking of moving vehicles and precise projection of attack lasers over long distances. This system overcame the limitations of previous setups, facilitating realistic attack scenarios.
  2. Discovery of a Vulnerability in Pulse Fingerprinting: The team identified a critical flaw in the implementation of pulse fingerprinting, a key security feature in new generation LiDARs. They found that by projecting a sufficient number of malicious laser pulses, attackers could bypass this authentication mechanism, making modern LiDARs susceptible to spoofing.
  3. Introduction of Adaptive HFR: Building on the pulse fingerprinting vulnerability, a novel removal attack technique called Adaptive HFR was developed. This method adaptively manages laser projection frequency to prevent spoofer overheating while ensuring successful bypass of pulse fingerprinting, enabling effective removal of objects from the LiDAR's point cloud.
  4. Demonstration of Realistic, High-Speed, Long-Distance Attacks: The research successfully demonstrated LiDAR removal attacks against vehicles traveling at speeds up to 60 kilometers per hour and at distances up to 40 meters. This significantly pushes the boundaries of attack realism compared to prior work.
  5. End-to-End Safety Impact Evaluation: Crucially, the researchers conducted closed-loop evaluation using Autoware.AI, a popular open-source autonomous driving software stack. The attacks resulted in the AV failing to detect a real vehicle and subsequently crashing into it, unequivocally proving the end-to-end safety impact of LiDAR spoofing in practical AD scenarios.

These findings collectively highlight that LiDAR spoofing is not merely a theoretical threat but a practical and severe vulnerability that can compromise the safety of autonomous vehicles, even those equipped with advanced defensive features. The work provides concrete evidence that current LiDAR security measures are insufficient against sophisticated, well-engineered attacks.

Technical Deep Dive

▶ Watch: Introducing novel adaptive HFR attack against new LiDARs (6:40)

The core of this research's success lies in its sophisticated approach to overcoming the challenges of attacking moving targets and bypassing modern LiDAR defenses. This involved the development of a specialized attack system and a novel attack methodology.

The Moving Vehicle Spoofing System (MVS System)

To achieve stable and continuous LiDAR spoofing against moving vehicles, the researchers designed the Moving Vehicle Spoofing System (MVS system). This integrated platform comprises three distinct but interconnected subsystems:

  1. Detection and Tracking System:
  • Challenge: Accurately detecting and tracking the target vehicle's LiDAR sensor at long distances is difficult. Normal visible light cameras, commonly used in prior works, struggle because LiDAR units appear too small beyond about 10 meters, making precise aiming impossible.
  • Solution: The MVS system employs an infrared (IR) camera equipped with a band-pass filter. This filter is specifically matched to the known wavelength of the target LiDAR's emitted lasers. By focusing on the infrared spectrum and filtering out other light, the system can clearly "see" the target LiDAR's emissions, making it stand out brightly against the background.
  • Performance: Testing revealed that while normal cameras failed to detect the LiDAR beyond 10 meters, the IR camera-based detection system maintained stable and accurate detection even at 20 meters, providing the necessary range for realistic attacks. This precise detection is crucial for the subsequent aiming phase.
  1. Aiming System:
  • Challenge: Even with accurate detection, maintaining a precise laser aim on a moving target, especially given road vibrations and vehicle movements, is complex.
  • Solution: The aiming system utilizes a high-precision servo motor. This motor allows for fine-grained, continuous adjustments to the attack laser's trajectory, compensating for dynamic changes in the target vehicle's position and orientation. The high precision ensures that the attack lasers remain focused on the target LiDAR's aperture.
  1. Spoofing System:
  • Challenge: Delivering a consistent and effective laser attack despite minor angular errors and environmental factors.
  • Solution: The spoofing system employs two parallel lasers equipped with 2-inch lenses. This design creates a broader attack beam, covering an area over 100 times larger than the narrow beams used in prior works. This wider coverage provides a margin of error for aiming, making the attack more robust against slight deviations caused by road vibrations or minor tracking inaccuracies, thus enhancing the stability of continuous attacks.

Novel Removal Attack Against New Generation LiDARs: Adaptive HFR

A significant contribution of this work is the development of a novel removal attack, Adaptive HFR, specifically designed to bypass the advanced defenses of new generation LiDARs.

  • Pulse Fingerprinting Background: Modern LiDARs, such as the Hesai 8128 used in this study, implement security features like pulse fingerprinting to mitigate spoofing. This mechanism attempts to authenticate received laser signals by looking for unique characteristics, such as specific signal shapes or varying pulse intervals for each ranging measurement. Conventional spoofing attacks, like basic HFR (High Frequency Removal), typically project a few malicious pulses at random times. With pulse fingerprinting enabled, these randomly timed pulses are rejected by the LiDAR, causing the attack to fail.
  • Vulnerability in Current Pulse Fingerprinting: The researchers' investigation revealed a critical vulnerability in the current implementation of pulse fingerprinting. They found that many systems rely solely on the intervals between pulses for authentication. The key insight was that a group of malicious pulses, even if individually "unfingerprinted," will inherently contain multiple pulse intervals within the group. If an attacker projects a sufficiently large number of pulses, the probability increases that at least one pair of these malicious pulses will coincidentally match an expected "fingerprint" interval, thereby bypassing the authentication.
  • Adaptive HFR Design: To exploit this vulnerability, the researchers designed Adaptive HFR.
  • Overcoming Overheating: A limitation of conventional HFR is that continuous, high-frequency laser projection can cause the spoofer device to overheat. Adaptive HFR addresses this by intelligently managing the attack frequency. It only projects lasers when the target LiDAR is actively scanning the victim object (e.g., the car to be removed). During the rest of the time, when the LiDAR is scanning other areas or between scans, the spoofer is allowed to cool down. This adaptive approach ensures the spoofer's longevity and stability during prolonged attacks.
  • Bypassing Authentication: By projecting a high density of pulses during the active scanning window, Adaptive HFR ensures that enough pulse intervals are present to bypass the LiDAR's authentication mechanism.
  • Results (Hesai 8128): A comparison against the Hesai 8128 LiDAR demonstrated the effectiveness of Adaptive HFR. While conventional HFR (which produces a "browser shape" in the point cloud due to partial removal) remained identifiable and largely ineffective against pulse fingerprinting, Adaptive HFR was able to almost entirely remove the target's point cloud. Outdoor experiments confirmed this, showing the complete removal of a car from the LiDAR's perception.

Through these technical innovations, the research showcased a practical and effective method for conducting realistic LiDAR spoofing attacks, even against modern sensors with advanced defensive features.

Demo / Proof of Concept

▶ Watch: Explaining how adaptive HFR bypasses pulse fingerprinting (8:00)

The efficacy and realism of the developed MVS system and Adaptive HFR attack were rigorously demonstrated through real-world experiments, culminating in an end-to-end evaluation against an autonomous driving stack.

The primary demonstration involved a real-world scenario where a victim vehicle was traveling at speeds up to 60 kilometers per hour. The attacker's MVS system, positioned on the roadside, was tasked with performing a removal attack against the victim's LiDAR. The results were visually compelling: the attacker successfully removed the victim's point cloud from the LiDAR's perception. This was clearly shown in the presentation, with the target vehicle disappearing from the 3D point cloud data at distances as far as 40 meters. This demonstration validated the system's ability to maintain stable tracking and effective spoofing against high-speed, long-distance targets, a significant improvement over prior work.

Crucially, the researchers went beyond standalone sensor testing and conducted an end-to-end attack evaluation using Autoware.AI. Autoware.AI is a widely adopted open-source software stack for autonomous driving, making this demonstration highly relevant to real-world AV deployments. In this closed-loop scenario, under the attack condition, the autonomous driving vehicle's perception system, relying on the compromised LiDAR data, failed to detect the real car in front of it. The visual evidence from the demonstration showed the AV proceeding without recognizing the obstacle, leading to a collision with the car. This direct consequence unequivocally proved that LiDAR spoofing attacks are not just theoretical vulnerabilities but can translate into critical safety failures in fully integrated autonomous driving systems. The collision scenario effectively highlighted the severe implications of removal attacks, where the AV acts as if an obstacle is simply not there, with potentially fatal outcomes.

Defensive Implications

▶ Watch: End-to-end attack: Autonomous vehicle crashes due to spoofing (10:20)

The findings of this research carry profound implications for the design and deployment of secure autonomous driving systems. While the talk itself briefly touched upon limitations and potential countermeasures, a deeper analysis reveals several key areas where defenders must focus their efforts.

First, the research explicitly highlighted two potential counter-measures:

  1. Availability Check: This involves implementing mechanisms to verify the continuous presence or sudden disappearance of expected objects. If a large, previously detected object (like a car) suddenly vanishes from the LiDAR's point cloud without a plausible physical explanation (e.g., it drove away), the AV system should flag this as an anomaly and not blindly trust the sensor data. This could involve cross-referencing with predicted trajectories or external contextual information.
  2. Ensuring Redundancy by Multi-Sensor Fusion: This is perhaps the most critical defense. Autonomous vehicles are typically equipped with an array of sensors, including cameras, radar, ultrasonic sensors, and LiDAR. By fusing data from multiple, diverse sensor modalities, the system can achieve a more robust and resilient perception of its environment. If a LiDAR-based removal attack causes an object to disappear from the point cloud, a camera or radar system might still detect its presence. The AV's decision-making system should be designed to prioritize or cross-validate information from multiple sensors, preventing a single point of failure introduced by a compromised LiDAR.

Beyond these points, the technical details of the attack suggest additional defensive strategies:

  • Enhancing Pulse Fingerprinting Robustness: The discovered vulnerability in pulse fingerprinting indicates that current implementations are too simplistic, relying primarily on pulse intervals. Future LiDAR designs must incorporate more sophisticated authentication mechanisms. This could involve more complex, randomized pulse sequences that are harder to guess or replicate, or even cryptographic methods where possible. The "fingerprint" should be dynamic and unpredictable, not easily reverse-engineered or bypassed by brute-forcing intervals.
  • Anomaly Detection in Point Cloud Data: Implementing advanced algorithms for detecting anomalies within the LiDAR point cloud itself could be beneficial. This might include:
  • Density Analysis: Sudden, localized drops in point cloud density where an object should be could indicate a removal attack.
  • Consistency Checks: Comparing the current point cloud with previous frames or predicted object positions. An abrupt disappearance of a stable object should trigger an alert.
  • Environmental Context: Using high-definition maps and real-time environmental data to identify unexpected discrepancies.
  • Physical Hardening and Anti-Tampering: While not directly addressed in the talk, the physical nature of laser-based attacks suggests the need for physical hardening of LiDAR units. This could involve incorporating optical filters that selectively block known malicious laser wavelengths (if identifiable) or designing LiDAR apertures that are less susceptible to focused external laser injections. Anti-tampering measures could also detect if a LiDAR unit has been physically compromised.
  • Secure Software and Firmware Updates: Ensuring that LiDAR firmware and the AV's perception software are regularly updated with patches against known vulnerabilities is crucial. The ability to push secure updates can help mitigate newly discovered attack vectors.

The end-to-end collision demonstration with Autoware.AI serves as a stark warning. It underscores that even popular, widely used AD stacks are vulnerable if their underlying sensor data can be manipulated. Therefore, the development community for autonomous driving software must prioritize robust sensor data validation and multi-sensor fusion architectures that are inherently resilient to single-sensor failures or malicious attacks.

Key Takeaways

  • Realistic LiDAR Spoofing is Achievable: LiDAR spoofing, specifically removal attacks, can be successfully executed against moving autonomous vehicles at realistic speeds (up to 60 km/h) and long distances (up to 40m), proving it's a practical, not just theoretical, threat.
  • Advanced Attack Systems are Key: The Moving Vehicle Spoofing System (MVS system), incorporating an IR camera for long-range detection and parallel lasers for stable aiming, is crucial for conducting effective attacks against dynamic targets.
  • Pulse Fingerprinting is Vulnerable: New generation LiDARs' pulse fingerprinting defense mechanism, designed to reject malicious signals, can be bypassed by projecting a sufficient density of laser pulses, exploiting its reliance on simple interval authentication.
  • Adaptive HFR Bypasses Modern Defenses: The novel Adaptive HFR attack technique successfully overcomes both spoofer overheating issues and pulse fingerprinting defenses, enabling near-complete removal of objects from the point cloud of LiDARs like the Hesai 8128.
  • End-to-End Safety Impact is Proven: The research demonstrated a critical end-to-end safety failure, where an AV running Autoware.AI failed to detect an obstacle due to a spoofing attack, leading to a collision, highlighting the severe real-world consequences.
  • Multi-Sensor Fusion and Anomaly Detection are Critical Defenses: To counter these attacks, autonomous driving systems must implement robust multi-sensor fusion to cross-validate data and employ availability checks and advanced anomaly detection algorithms to identify suspicious disappearing objects.

About the Speaker(s)

The work presented was a collaborative effort involving researchers from Ko University and the University of California, Irvine (UCI). The presentation at the NDSS Symposium was delivered by Rio Suzuki, a master's student from Ko University, who presented the initial part of the research. The later segments of the talk were to be presented by Yuki. The project itself was a joint endeavor with Professor Alfred and his student, Takami Sato, from UCI. Takami Sato is listed as the primary speaker for the conference, indicating his leading role in the research and its presentation. Their combined expertise contributed to the development of the novel attack system and the comprehensive evaluation of LiDAR spoofing vulnerabilities in autonomous driving contexts.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid, technically grounded research that meaningfully advances the LiDAR spoofing literature by moving from lab-bench stationary setups to real-world, high-speed, long-distance attacks against an integrated AV stack. The pulse fingerprinting bypass is the headline contribution — it's not a theoretical flaw, they built hardware to exploit it and drove a car into something to prove the point.

Heather Calloway (CISO) — WEAK

Technically credible work that meaningfully advances LiDAR spoofing research — real-world speeds, closed-loop evaluation, a genuine bypass of pulse fingerprinting. But the defensive and governance implications are thin, and the talk never reaches the audience that needs to act on this finding.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025