用可动镜面反射攻击激光雷达定位,无需信号注入即可造成严重定位偏差。
MirrorDrift: Actuated Mirror-Based Attacks on LiDAR SLAM
- 通过可动平面镜产生虚假点云,干扰扫描匹配
- 实测最高导致6.03米定位误差,仿真提升6.1倍误差
- 对主流防御机制有效的新型物理攻击,适合安全研究者
激光雷达同步定位与建图(LiDAR SLAM)虽精度高,但易受点云污染影响,因扫描匹配依赖几何一致性。以往物理攻击多依赖外部信号注入进行激光欺骗,需精确掌握传感器时序,且日益被现代防御机制如时序混淆和注入拒绝所抑制。本文提出一种无需信号注入的替代方案——利用镜面反射,实现名为MirrorDrift的攻击。该攻击通过控制平面镜的位置、角度和运动,生成鬼影点云,系统性地偏移扫描匹配对应关系。仿真结果显示,相较于随机放置,其平均位姿误差(APE)提升6.1倍,使三种SLAM系统平均APE恶化至2.29-3.31米。在配备先进抗干扰机制的现代激光雷达上进行真实实验,最大定位误差达6.03米。据我们所知,这是首个成功针对生产级安全激光雷达的定向攻击。
原文摘要 · Abstract (English)
LiDAR SLAM provides high-accuracy localization but is fragile to point-cloud corruption because scan matching assumes geometric consistency. Prior physical attacks on LiDAR SLAM largely rely on LiDAR spoofing via external signal injection, which requires sensor-specific timing knowledge and is increasingly mitigated by modern defense mechanisms such as timing obfuscation and injection rejection. In this work, we show that specular reflection offers an injection-free alternative and demonstrate an attack, MirrorDrift, that uses an actuated planar mirror to cause ghost points in LiDAR scans and systematically bias scan-matching correspondences. MirrorDrift optimizes mirror placement, alignment, and actuation. In simulation, it increases the average pose error (APE) by 6.1x over random placement, degrading three SLAM systems to 2.29-3.31 m mean APE. In real-world experiments on a modern LiDAR with state-of-the-art interference mitigation, it induces localization errors of up to 6.03 m. To the best of our knowledge, this is the first successful SLAM-targeted attack against production-grade secure LiDARs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。