Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles

To enable safe and reliable decision-making, autonomous vehicles (AVs) feed\nsensor data to perception algorithms to understand the environment. Sensor\nfusion with multi-frame tracking is becoming increasingly popular for detecting\n3D objects. Thus, in this work, we perform an analysis of camera-LiDAR fusion,\nin the AV context, under LiDAR spoofing attacks. Recently, LiDAR-only\nperception was shown vulnerable to LiDAR spoofing attacks; however, we\ndemonstrate these attacks are not capable of disrupting camera-LiDAR fusion. We\nthen define a novel, context-aware attack: frustum attack, and show that out of\n8 widely used perception algorithms - across 3 architectures of LiDAR-only and\n3 architectures of camera-LiDAR fusion - all are significantly vulnerable to\nthe frustum attack. In addition, we demonstrate that the frustum attack is\nstealthy to existing defenses against LiDAR spoofing as it preserves\nconsistencies between camera and LiDAR semantics. Finally, we show that the\nfrustum attack can be exercised consistently over time to form stealthy\nlongitudinal attack sequences, compromising the tracking module and creating\nadverse outcomes on end-to-end AV control.\n

Paper

References (45)

Scroll for more · 33 remaining

Similar papers

© 2026 NYSGPT2525 LLC