Lune

USENIX Security2025

Invisible but Detected: Physical Adversarial Shadow Attack and Defense on LiDAR Object Detection

Ryunosuke Kobayashi, Kazuki Nomoto, Yuna Tanaka, Go Tsuruoka, Tatsuya Mori

2025年份

摘要

This paper introduces "Shadow Hack," the first adversarial attack exploiting naturally occurring object shadows in LiDAR point clouds to target object detection models in autonomous vehicles. Shadow Hack manipulates these shadows, which implicitly influence object detection even though they are not included in output results. To create "Adversarial Shadows," we use materials that are difficult for LiDAR to measure accurately. We optimize the position and size of these shadows to maximize misclassification by point cloud-based object recognition models. Our evaluation is conducted on object detection models trained with the KITTI dataset, and the attack effectiveness is demonstrated within this setting. In simulations, Shadow Hack achieves a 100% attack success rate at distances between 11 m and 21 m across multiple models. Our physical world experiments validate these findings, demonstrating up to 100% success rate at 10 m against PointPillars and 98% against SECOND-IoU, using mirror sheets that achieve nearly 100% point cloud removal rate at distances from 1 to 14 meters. We also propose "BBValidator," a defense mechanism achieving a 100% success rate while maintaining high object detection accuracy. All data and code in this study are available at https://zenodo.org/records/14719074 . Annotated as "Car" despite the lack of point clouds.