arXiv:2603.11365cs.RO2026-03

用动态点云干扰骗过激光雷达定位,还能自检防骗。

D-SLAMSpoof: An Environment-Agnostic LiDAR Spoofing Attack using Dynamic Point Cloud Injection

  • 设计动态点云模式,骗过复杂环境中的激光雷达定位
  • 在城市和室内场景中攻击成功率显著提升
  • 仅用惯性传感器就能发现并抵御此类攻击

本文提出Dynamic SLAMSpoof(D-SLAMSpoof),一种针对激光雷达SLAM的新型欺骗攻击,可在特征丰富的现实环境(如城市和室内)中有效运作。该攻击通过外部激光干扰向激光雷达扫描注入虚假测量数据,结合基于扫描匹配原理的空间形状与时间协调的动态注入模式,显著提升了攻击成功率。传统方法在复杂环境中常失效,而D-SLAMSpoof克服了这一瓶颈。此外,我们提出一种实用防御方案ISD-SLAM,仅依赖自动驾驶系统普遍配备的惯性死推信号,可准确检测包括D-SLAMSpoof在内的激光雷达欺骗攻击,并有效缓解由此引发的位置漂移。研究揭示了激光雷达SLAM固有的安全漏洞,首次实现了仅使用标准车载传感器的实用防御,为提升自主系统安全性与可靠性提供了关键洞见。

原文摘要 · Abstract (English)

In this work, we introduce Dynamic SLAMSpoof (D-SLAMSpoof), a novel attack that compromises LiDAR SLAM even in feature-rich environments. The attack leverages LiDAR spoofing, which injects spurious measurements into LiDAR scans through external laser interference. By designing both spatial injection shapes and temporally coordinated dynamic injection patterns guided by scan-matching principles, D-SLAMSpoof significantly improves attack success rates in real-world, feature-rich environments such as urban areas and indoor spaces, where conventional LiDAR spoofing methods often fail. Furthermore, we propose a practical defense method, ISD-SLAM, that relies solely on inertial dead reckoning signals commonly available in autonomous systems. We demonstrate that ISD-SLAM accurately detects LiDAR spoofing attacks, including D-SLAMSpoof, and effectively mitigates the resulting position drift. Our findings expose inherent vulnerabilities in LiDAR-based SLAM and introduce the first practical defense against LiDAR-based SLAM spoofing using only standard onboard sensors, providing critical insights for improving the security and reliability of autonomous systems.

激光雷达安全欺骗攻击自动驾驶

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。