LiDAR Spoofing Meets the New-Gen: Capability Improvements, Broken Assumptions, and New Attack Strategies (2303.10555v2)
Abstract: LiDAR (Light Detection And Ranging) is an indispensable sensor for precise long- and wide-range 3D sensing, which directly benefited the recent rapid deployment of autonomous driving (AD). Meanwhile, such a safety-critical application strongly motivates its security research. A recent line of research finds that one can manipulate the LiDAR point cloud and fool object detectors by firing malicious lasers against LiDAR. However, these efforts face 3 critical research gaps: (1) considering only one specific LiDAR (VLP-16); (2) assuming unvalidated attack capabilities; and (3) evaluating object detectors with limited spoofing capability modeling and setup diversity. To fill these critical research gaps, we conduct the first large-scale measurement study on LiDAR spoofing attack capabilities on object detectors with 9 popular LiDARs, covering both first- and new-generation LiDARs, and 3 major types of object detectors trained on 5 different datasets. To facilitate the measurements, we (1) identify spoofer improvements that significantly improve the latest spoofing capability, (2) identify a new object removal attack that overcomes the applicability limitation of the latest method to new-generation LiDARs, and (3) perform novel mathematical modeling for both object injection and removal attacks based on our measurement results. Through this study, we are able to uncover a total of 15 novel findings, including not only completely new ones due to the measurement angle novelty, but also many that can directly challenge the latest understandings in this problem space. We also discuss defenses.
- C. Urmson, J. A. Bagnell, C. Baker, M. Hebert, A. Kelly, R. Rajkumar, P. E. Rybski, S. Scherer, R. Simmons, S. Singh et al., “Tartan Racing: A Multi-Modal Approach to the DARPA Urban challenge,” 2007.
- “Waymo Has Launched its Commercial Self-Driving Service in Phoenix,” https://www.businessinsider.com/waymo-one-driverless-car-service-launches-in-phoenix-arizona-2018-12, 2018.
- “Cruise,” https://www.getcruise.com/.
- “Motional,” https://motional.com/.
- “Nuro,” https://www.nuro.ai/.
- “NTSB Investigation Into Deadly Uber Self-Driving Car Crash Reveals Lax Attitude Toward Safety,” https://spectrum.ieee.org/ntsb-investigation-into-deadly-uber-selfdriving-car-crash-reveals-lax-attitude-toward-safety.
- J. Petit, B. Stottelaar, M. Feiri, and F. Kargl, “Remote Attacks on Automated Vehicles Sensors: Experiments on Camera and Lidar,” Black Hat Europe, vol. 11, p. 2015, 2015.
- H. Shin, D. Kim, Y. Kwon, and Y. Kim, “Illusion and Dazzle: Adversarial Optical Channel Exploits Against Lidars for Automotive Applications,” in International Conference on Cryptographic Hardware and Embedded Systems. Springer, 2017, pp. 445–467.
- Y. Cao, C. Xiao, B. Cyr, Y. Zhou, W. Park, S. Rampazzi, Q. A. Chen, K. Fu, and Z. M. Mao, “Adversarial Sensor Attack on Lidar-Based Perception in Autonomous Driving,” in ACM SIGSAC Conference on Computer and Communications Security (CCS), 2019, pp. 2267–2281.
- J. Sun, Y. Cao, Q. A. Chen, and Z. M. Mao, “Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures,” in USENIX Security Symposium, 2020.
- Y. Cao, N. Wang, C. Xiao, D. Yang, J. Fang, R. Yang, Q. A. Chen, M. Liu, and B. Li, “Invisible for Both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving under Physical-World Attacks,” in IEEE Symposium on Security and Privacy (SP), 2021, pp. 176–194.
- R. S. Hallyburton, Y. Liu, Y. Cao, Z. M. Mao, and M. Pajic, “Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles,” in USENIX Security Symposium, 2022.
- Y. Cao, S. H. Bhupathiraju, P. Naghavi, T. Sugawara, Z. M. Mao, and S. Rampazzi, “You Can’t See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks,” in USENIX Security Symposium, 2023.
- Z. Hau, K. Co, S. Demetriou, and E. Lupu, “Object Removal Attacks on LiDAR-based 3D Object Detectors,” in NDSS Workshop on Automotive and Autonomous Vehicle Security (AutoSec), 2021.
- “VLP-16 User Manual,” https://velodynelidar.com/wp-content/uploads/2019/12/63-9243-Rev-E-VLP-16-User-Manual.pdf.
- Z. Hau, S. Demetriou, L. Muñoz-González, and E. C. Lupu, “Shadow-Catcher: Looking into Shadows to Detect Ghost Objects in Autonomous Vehicle 3D Sensing,” in European Symposium on Research in Computer Security. Springer, 2021, pp. 691–711.
- K. Yoshioka, “A Tutorial and Review of Automobile Direct ToF LiDAR SoCs: Evolution of Next-Generation LiDARs,” IEICE Transactions on Electronics, vol. E105.C, no. 10, pp. 534–543, 2022.
- “Ultra Puck Surround View Lidar Sensor — Velodyne Lidar,” https://velodynelidar.com/products/ultra-puck/.
- D. Wang, C. Watkins, and H. Xie, “MEMS Mirrors for LiDAR: A Review,” Micromachines, vol. 11, no. 5, p. 456, 2020.
- R. Roriz, J. Cabral, and T. Gomes, “Automotive LiDAR Technology: A Survey,” IEEE TITS, 2021.
- “Ouster Introduces Digital Flash (DF) Series Lidar for Automotive,” https://ouster.com/blog/ouster-automotive-df-series/.
- “datasheet-rev06-v2p3-os1.pdf,” https://data.ouster.io/downloads/datasheets/datasheet-rev06-v2p3-os1.pdf.
- “RS-Helios,” https://www.robosense.ai/en/rslidar/RS-Helios.
- “XT32 - HESAI,” https://www.hesaitech.com/en/XT32.
- Y. Li, R. Bu, M. Sun, W. Wu, X. Di, and B. Chen, “PointCNN: Convolution on X-Transformed Points,” Advances in Neural Information Processing Systems (NeurIPS), vol. 31, 2018.
- R. Qian, X. Lai, and X. Li, “3D Object Detection for Autonomous Driving: A Survey,” Pattern Recognition, 2022.
- A. H. Lang, S. Vora, H. Caesar, L. Zhou, J. Yang, and O. Beijbom, “PointPillars: Fast Encoders for Object Detection from Point Clouds,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2019, pp. 12 697–12 705.
- Y. Yan, Y. Mao, and B. Li, “SECOND: Sparsely Embedded Convolutional Detection,” Sensors, vol. 18, no. 10, p. 3337, 2018.
- S. Shi, Z. Wang, J. Shi, X. Wang, and H. Li, “From Points to Parts: 3D Object Detection from Point Cloud with Part-Aware and Part-Aggregation Network,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 43, no. 8, pp. 2647–2664, 2020.
- Z. Yang, Y. Sun, S. Liu, and J. Jia, “3DSSD: Point-based 3D Single Stage Object Detector,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2020, pp. 11 040–11 048.
- S. Shi, C. Guo, L. Jiang, Z. Wang, J. Shi, X. Wang, and H. Li, “PV-RCNN: Point-Voxel Feature Set Abstraction for 3D Object Detection,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2020, pp. 10 529–10 538.
- A. Geiger, P. Lenz, and R. Urtasun, “Are we ready for Autonomous Driving? The KITTI Vision Benchmark Suite,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2012.
- P. Sun, H. Kretzschmar, X. Dotiwalla, A. Chouard, V. Patnaik, P. Tsui, J. Guo, Y. Zhou, Y. Chai, B. Caine, V. Vasudevan, W. Han, J. Ngiam, H. Zhao, A. Timofeev, S. Ettinger, M. Krivokon, A. Gao, A. Joshi, Y. Zhang, J. Shlens, Z. Chen, and D. Anguelov, “Scalability in Perception for Autonomous Driving: Waymo Open Dataset,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2020.
- H. Caesar, V. Bankiti, A. H. Lang, S. Vora, V. E. Liong, Q. Xu, A. Krishnan, Y. Pan, G. Baldan, and O. Beijbom, “nuScenes: A Multimodal Dataset for Autonomous Driving,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2020.
- R. Kesten, M. Usman, J. Houston, T. Pandya, K. Nadhamuni, A. Ferreira, M. Yuan, B. Low, A. Jain, P. Ondruska, S. Omari, S. Shah, A. Kulkarni, A. Kazakova, C. Tao, L. Platinsky, W. Jiang, and V. Shet, “Level 5 Perception Dataset,” https://level-5.global/level5/data/, 2019.
- “Baidu Apollo,” https://github.com/ApolloAuto/apollo.
- M. Contributors, “MMDetection3D: OpenMMLab Next-Generation Platform for Feneral 3D Object Detection,” https://github.com/open-mmlab/mmdetection3d, 2020.
- “OpenPCDet: An Open-source Toolbox for 3D Object Detection from Point Clouds,” https://github.com/open-mmlab/OpenPCDet, 2020.
- “Alpha Prime,” https://velodynelidar.com/products/alpha-prime/.
- “Leddar Pixell,” https://leddarsensor.com/solutions/leddar-pixell/.
- “Intel RealSense LiDAR Camera L515 Datasheet,” https://dev.intelrealsense.com/docs/lidar-camera-l515-datasheet.
- “Livox Horizon User Manual,” https://www.livoxtech.com/3296f540ecf5458a8829e01cf429798e/assets/horizon/Livox%20Horizon%20user%20manual%20v1.0.pdf.
- “EOSRAM Radial T1 3/4, SPL PL90_3,” https://www.osram.com/ecat/com/en/class_pim_web_catalog_103489/prd_pim_device_2220019/.
- J. Shen, N. Wang, Z. Wan, Y. Luo, T. Sato, Z. Hu, X. Zhang, S. Guo, Z. Zhong, K. Li, Z. Zhao, C. Qiao, and Q. A. Chen, “SoK: On the Semantic AI Security in Autonomous Driving,” arXiv preprint arXiv:2203.05314, 2022.
- “Our Project Website,” https://sites.google.com/view/cav-sec/new-gen-lidar-sec.
- Z. Jin, J. Xiaoyu, Y. Cheng, B. Yang, C. Yan, and W. Xu, “PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous Vehicle,” in IEEE Symposium on Security and Privacy (SP), 2023, pp. 710–727.
- Y. Jia, Y. Lu, J. Shen, Q. A. Chen, H. Chen, Z. Zhong, and T. Wei, “Fooling Detection Alone is Not Enough: Adversarial Attack Against Multiple Object Tracking,” in International Conference on Learning Representations (ICLR), 2020.
- “LGSVL Simulator,” https://github.com/lgsvl/simulator/.
- “AEye Automotive,” https://www.aeye.ai/solutions/automotive/.
- “Luminar Iris,” https://www.luminartech.com/iris/.
- “Si PIN photodiode S6775,” https://www.hamamatsu.com/us/en/product/optical-sensors/photodiodes/si-photodiodes/S6775.html.
- “TL082 LINEAR INTEGRATED CIRCUIT,” http://www.unisonic.com.tw/datasheet/TL082.pdf.
- “81160A Pulse Function Arbitrary Noise Generator,” https://www.keysight.com/us/en/product/81160A/81160a-pulse-function-arbitrary-noise-generator.html.
- “EPC9126/EPC9126HC Lidar Demo Boards ,” https://epc-co.com/epc/Products/DemoBoards/EPC9126.aspx.
- “AFG310 and AFG320 User Manual,” https://www.tek.com/en/afg310-manual/afg310-and-afg320-user-manual.
- “LiDAR for Automotive and Industrial Applications 2021,” https://www.i-micronews.com/products/lidar-for-automotive-and-industrial-applications-2021/.
- Y. Zhou and O. Tuzel, “VoxelNet: End-to-End Learning for Point Cloud based 3D Object Detection,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2018, pp. 4490–4499.
- S. Kato, S. Tokunaga, Y. Maruyama, S. Maeda, M. Hirabayashi, Y. Kitsukawa, A. Monrroy, T. Ando, Y. Fujii, and T. Azumi, “Autoware On Board: Enabling Autonomous Vehicles with Embedded Systems,” in ICCPS’18. IEEE Press, 2018, pp. 287–296.
- S. Shi, X. Wang, and H. Li, “PointRCNN: 3D Object Proposal Generation and Detection from Point Cloud,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2019, pp. 770–779.
- R. Girshick, “Fast R-CNN,” in CVPR, 2015, pp. 1440–1448.
- C. R. Qi, L. Yi, H. Su, and L. J. Guibas, “PointNet++: Deep Hierarchical Feature Learning on Point Sets in a Metric Space,” Advances in Neural Information Processing Systems (NeurIPS), vol. 30, 2017.
- W. Liu, D. Anguelov, D. Erhan, C. Szegedy, S. Reed, C.-Y. Fu, and A. C. Berg, “SSD: Single Shot Multibox Detector,” in European Conference on Computer Vision (ECCV). Springer, 2016, pp. 21–37.
- Y. Chen, S. Liu, X. Shen, and J. Jia, “Fast Point R-CNN,” in Conference on Computer Vision and Pattern Recognition (CVPR), 2019.
- Takami Sato (16 papers)
- Yuki Hayakawa (2 papers)
- Ryo Suzuki (61 papers)
- Yohsuke Shiiki (1 paper)
- Kentaro Yoshioka (14 papers)
- Qi Alfred Chen (37 papers)