Physically Realizable Adversarial Examples for LiDAR Object Detection
James Tu, Mengye Ren, Sivabalan Manivasagam, Ming Liang, Bin Yang, Richard Du, Frank Cheng, Raquel Urtasun
Abstract
Modern autonomous driving systems rely heavily on deep learning models to process point cloud sensory data; meanwhile, deep models have been shown to be susceptible to adversarial attacks with visually imperceptible perturbations. Despite the fact that this poses a security concern for the self-driving industry, there has been very little exploration in terms of 3D perception, as most adversarial attacks have only been applied to 2D flat images. In this paper, we address this issue and present a method to generate universal 3D adversarial objects to fool LiDAR detectors. In particular, we demonstrate that placing an adversarial object on the rooftop of any target vehicle to hide the vehicle entirely from LiDAR detectors with a success rate of 80%. We report attack results on a suite of detectors using various input representation of point clouds. We also conduct a pilot study on adversarial defense using data augmentation. This is one step closer towards safer self-driving under unseen conditions from limited training data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ef57b25f-b33d-4ef8-a314-3113d110371aCited by top-tier papers62
- Robo3D: Towards Robust and Reliable 3D Perception against CorruptionsLingdong Kong, Youquan Liu, Xin Li, Runnan Chen et al.ICCV 2023 · 151 citations
- Shadows can be Dangerous: Stealthy and Effective Physical-world Adversarial Attack by Natural PhenomenonYiqi Zhong, Xianming Liu, Deming Zhai, Junjun Jiang et al.CVPR 2022 · 148 citations
- Generating Useful Accident-Prone Driving Scenarios via a Learned Traffic PriorDavis Rempe, Jonah Philion, Leonidas J. Guibas, Sanja Fidler et al.CVPR 2022 · 123 citations
- A Backdoor Attack against 3D Point Cloud ClassifiersZhen Xiang, David J. Miller, Siheng Chen, Xi Li et al.ICCV 2021 · 90 citations
- Shape-invariant 3D Adversarial Point CloudsQidong Huang, Xiaoyi Dong, Dongdong Chen, Hang Zhou et al.CVPR 2022 · 88 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- PointCloud Saliency MapsTianhang Zheng, Changyou Chen, Junsong Yuan, Bo Li et al.ICCV 2019 · 265 citations
Related papers
- Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous DrivingYan Zhang, Zihao Liu, Yi Zhu, Chenglin MiaoCCS 2025
- Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving?Yi Zhu, Chenglin Miao, Tianhang Zheng, Foad Hajiaghajani et al.CCS 2021 · 65 citations
- Fooling LiDAR Perception via Adversarial Trajectory PerturbationYiming Li, Congcong Wen, Felix Juefei-Xu, Chen FengICCV 2021 · 69 citations
- PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous VehicleZizhi Jin, Xiaoyu Ji, Yushi Cheng, Bo Yang et al.S&P 2023
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
