I Can See the Light: Attacks on Autonomous Vehicles Using Invisible Lights
Wei Wang, Yao Yao, Xin Liu, Xiang Li, Pei Hao, Ting Zhu
Abstract
The camera is one of the most important sensors for an autonomous vehicle (AV) to perform Environment Perception and Simultaneous Localization and Mapping (SLAM). To secure the camera, current autonomous vehicles not only utilize the data gathered from multiple sensors (e.g., Camera, Ultrasonic Sensor, Radar, or LiDAR) for environment perception and SLAM but also require the human driver to always realize the driving situation, which can effectively defend against previous attack approaches (i.e., creating visible fake objects or introducing perturbations to the camera by using advanced deep learning techniques). Different from their work, in this paper, we in-depth investigate the features of Infrared light and introduce a new security challenge called I-Can-See-the-Light- Attack (ICSL Attack) that can alter environment perception results and introduce SLAM errors to the AV. Specifically, we found that the invisible infrared lights (IR light) can successfully trigger the image sensor while human eyes cannot perceive IR lights. Moreover, the IR light appears magenta color in the camera, which triggers different pixels from the ambient visible light and can be selected as key points during the AV's SLAM process. By leveraging these features, we explore to i) generate invisible traffic lights, ii) create fake invisible objects, iii) ruin the in-car user experience, and iv) introduce SLAM errors to the AV. We implement the ICSL Attack by using off-the-shelf IR light sources and conduct an extensive evaluation on Tesla Model 3 and an enterprise-level autonomous driving platform under various environments and settings. We demonstrate the effectiveness of the ICSL Attack and prove that current autonomous vehicle companies have not yet considered the ICSL Attack, which introduces severe security issues. To secure the AV, by exploring unique features of the IR light, we propose a software-based detection module to defend against the ICSL Attack.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6daf1148-e237-41e6-8db3-f107cbe233f3Cited by top-tier papers8
- Does Physical Adversarial Example Really Matter to Autonomous Driving? Towards System-Level Effect of Adversarial Object Evasion AttackNingfei Wang, Yunpeng Luo, Takami Sato, Kaidi Xu et al.ICCV 2023 · 65 citations
- AE-Morpher: Improve Physical Robustness of Adversarial Objects against LiDAR-based Detectors via Object ReconstructionShenchen Zhu, Yue Zhao, Kai Chen, Bo Wang et al.USENIX Security 2024 · 13 citations
- Physical Hijacking Attacks against Object TrackersRaymond Muller, Yanmao Man, Z. Berkay Celik, Ming Li et al.CCS 2022 · 12 citations
- Adversary is on the Road: Attacks on Visual SLAM using Unnoticeable Adversarial PatchBaodong Chen, Wei Wang, Pascal Sikorski, Ting ZhuUSENIX Security 2024 · 8 citations
- mmSpoof: Resilient Spoofing of Automotive Millimeter-wave Radars using Reflect ArrayRohith Reddy Vennam, Ish Kumar Jain, Kshitiz Bansal, Joshua Orozco et al.S&P 2023
Related papers
- Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign PerceptionTakami Sato, Sri Hrushikesh Varma Bhupathiraju, Michael Clifford, Takeshi Sugawara et al.NDSS 2024
- Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted PerturbationsPengfei Jing, Qiyi Tang, Yuefeng Du, Lei Xue et al.USENIX Security 2021 · 79 citations
- Targeted Physical Evasion Attacks in the Near-Infrared DomainPascal Zimmer, Simon Lachnit, Alexander Jan Zielinski, Ghassan KarameNDSS 2026
- Fooling Thermal Infrared Pedestrian Detectors in Real World Using Small BulbsXiaopei Zhu, Xiao Li, Jianmin Li, Zheyao Wang et al.AAAI 2021 · 108 citations
- Infrared Adversarial Car StickersXiaopei Zhu, Yuqiu Liu, Zhanhao Hu, Jianmin Li et al.CVPR 2024 · 2 citations
