arXiv:2502.13641cs.RO2025-02ICRA被引 5

首次实现针对自动驾驶定位系统的实用化激光欺骗攻击,可致位置误差超4.2米。

SLAMSpoof: Practical LiDAR Spoofing Attacks on Localization Systems Guided by Scan Matching Vulnerability Analysis

  • 基于扫描匹配漏洞评分定位有效攻击点
  • 真实车辆实验中使三类算法误差均超4.2米
  • 揭示高危漏洞,适合安全研究者参考

精准定位是实现全自动驾驶服务的关键。此类服务高度依赖地图信息以降低对车道形状、交通灯和标志识别的不确定性,而厘米级定位精度目前仅可通过激光雷达(LiDAR)实现。然而,激光雷达易受恶意激光欺骗攻击,可篡改其测量结果。一旦定位被破坏,可能导致车辆偏离道路或无视交通灯。为评估此类攻击的真实危害,本文提出SLAMSpoof,首个针对自动驾驶定位系统的实用化激光欺骗攻击。该方法通过扫描匹配漏洞评分(SMVS)定位有效攻击点,实车实验验证其在真实场景下对三种主流激光雷达定位算法均引发≥4.2米的位置误差(超过典型车道宽度)。研究还讨论了潜在防御方案,代码已开源。

原文摘要 · Abstract (English)

Accurate localization is essential for enabling modern full self-driving services. These services heavily rely on map-based traffic information to reduce uncertainties in recognizing lane shapes, traffic light locations, and traffic signs. Achieving this level of reliance on map information requires centimeter-level localization accuracy, which is currently only achievable with LiDAR sensors. However, LiDAR is known to be vulnerable to spoofing attacks that emit malicious lasers against LiDAR to overwrite its measurements. Once localization is compromised, the attack could lead the victim off roads or make them ignore traffic lights. Motivated by these serious safety implications, we design SLAMSpoof, the first practical LiDAR spoofing attack on localization systems for self-driving to assess the actual attack significance on autonomous vehicles. SLAMSpoof can effectively find the effective attack location based on our scan matching vulnerability score (SMVS), a point-wise metric representing the potential vulnerability to spoofing attacks. To evaluate the effectiveness of the attack, we conduct real-world experiments on ground vehicles and confirm its high capability in real-world scenarios, inducing position errors of $\geq$4.2 meters (more than typical lane width) for all 3 popular LiDAR-based localization algorithms. We finally discuss the potential countermeasures of this attack. Code is available at https://github.com/Keio-CSG/slamspoof

激光雷达欺骗攻击定位安全自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。