DisorientLiDAR: Physical Attacks on LiDAR-based Localization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lao, Yizhen, Zhang, Yu, Wang, Ziting, Wang, Chengbo, Xue, Yifei, Shao, Wanpeng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908540973613056
author Lao, Yizhen
Zhang, Yu
Wang, Ziting
Wang, Chengbo
Xue, Yifei
Shao, Wanpeng
author_facet Lao, Yizhen
Zhang, Yu
Wang, Ziting
Wang, Chengbo
Xue, Yifei
Shao, Wanpeng
contents Deep learning models have been shown to be susceptible to adversarial attacks with visually imperceptible perturbations. Even this poses a serious security challenge for the localization of self-driving cars, there has been very little exploration of attack on it, as most of adversarial attacks have been applied to 3D perception. In this work, we propose a novel adversarial attack framework called DisorientLiDAR targeting LiDAR-based localization. By reverse-engineering localization models (e.g., feature extraction networks), adversaries can identify critical keypoints and strategically remove them, thereby disrupting LiDAR-based localization. Our proposal is first evaluated on three state-of-the-art point-cloud registration models (HRegNet, D3Feat, and GeoTransformer) using the KITTI dataset. Experimental results demonstrate that removing regions containing Top-K keypoints significantly degrades their registration accuracy. We further validate the attack's impact on the Autoware autonomous driving platform, where hiding merely a few critical regions induces noticeable localization drift. Finally, we extended our attacks to the physical world by hiding critical regions with near-infrared absorptive materials, thereby successfully replicate the attack effects observed in KITTI data. This step has been closer toward the realistic physical-world attack that demonstrate the veracity and generality of our proposal.
format Preprint
id arxiv_https___arxiv_org_abs_2509_12595
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DisorientLiDAR: Physical Attacks on LiDAR-based Localization
Lao, Yizhen
Zhang, Yu
Wang, Ziting
Wang, Chengbo
Xue, Yifei
Shao, Wanpeng
Computer Vision and Pattern Recognition
Artificial Intelligence
Deep learning models have been shown to be susceptible to adversarial attacks with visually imperceptible perturbations. Even this poses a serious security challenge for the localization of self-driving cars, there has been very little exploration of attack on it, as most of adversarial attacks have been applied to 3D perception. In this work, we propose a novel adversarial attack framework called DisorientLiDAR targeting LiDAR-based localization. By reverse-engineering localization models (e.g., feature extraction networks), adversaries can identify critical keypoints and strategically remove them, thereby disrupting LiDAR-based localization. Our proposal is first evaluated on three state-of-the-art point-cloud registration models (HRegNet, D3Feat, and GeoTransformer) using the KITTI dataset. Experimental results demonstrate that removing regions containing Top-K keypoints significantly degrades their registration accuracy. We further validate the attack's impact on the Autoware autonomous driving platform, where hiding merely a few critical regions induces noticeable localization drift. Finally, we extended our attacks to the physical world by hiding critical regions with near-infrared absorptive materials, thereby successfully replicate the attack effects observed in KITTI data. This step has been closer toward the realistic physical-world attack that demonstrate the veracity and generality of our proposal.
title DisorientLiDAR: Physical Attacks on LiDAR-based Localization
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2509.12595