EMI-LiDAR: Uncovering Vulnerabilities of LiDAR Sensors in Autonomous Driving Setting using Electromagnetic Interference

EMI-LiDAR: Uncovering Vulnerabilities of LiDAR Sensors in Autonomous Driving Setting using Electromagnetic Interference
复制标题

DOI:
10.1145/3558482.3590192
复制
发表时间:
2023-05
期刊:
Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
通讯作者:
Sri Hrushikesh Varma Bhupathiraju;Jennifer Sheldon;L. A. Bauer;Vincent Bindschaedler;Takeshi Sugawara;Sara Rampazzi
Sri Hrushikesh Varma Bhupathiraju;Jennifer Sheldon;L. A. Bauer;Vincent Bindschaedler;Takeshi Sugawara;Sara Rampazzi
中科院分区:
其他
文献类型:
--
作者:
Sri Hrushikesh Varma Bhupathiraju;Jennifer Sheldon;L. A. Bauer;Vincent Bindschaedler;Takeshi Sugawara;Sara Rampazzi

文献摘要

相似文献

使用基于激光雷达的物体检测系统的自动驾驶车辆 (AV) 正在迅速改进,并成为一种日益可行的交通方式。虽然这些检测系统能够有效感知周围环境,但它们很容易受到激光攻击,从而导致障碍物错误分类或移除。然而,这些激光攻击执行起来具有挑战性,需要精确的瞄准和准确性。我们的研究揭示了故意电磁干扰 (IEMI) 形式的新威胁,它会影响构成现代激光雷达的飞行时间 (TOF) 电路。我们证明,这些漏洞可以被利用来迫使 AV 感知系统误检测、错误分类对象以及感知不存在的障碍物。我们评估了三个 AV 感知模块(PointPillars、PointRCNN 和 Apollo)中的漏洞,并展示了分类率如何降至 50% 以下。我们还分析了 IEMI 注入对两种融合模型(AVOD 和 Frustum-ConvNet)以及现实场景的影响。最后,我们讨论了潜在的对策并提出了两种检测信号注入的策略。
Autonomous Vehicles (AVs) using LiDAR-based object detection systems are rapidly improving and becoming an increasingly viable method of transportation. While effective at perceiving the surrounding environment, these detection systems are shown to be vulnerable to attacks using lasers which can cause obstacle misclassifications or removal. These laser attacks, however, are challenging to perform, requiring precise aiming and accuracy. Our research exposes a new threat in the form of Intentional Electro-Magnetic-Interference (IEMI), which affects the time-of-flight (TOF) circuits that make up modern LiDARs. We show that these vulnerabilities can be exploited to force the AV Perception system to misdetect, misclassify objects, and perceive non-existent obstacles. We evaluate the vulnerability in three AV perception modules (PointPillars, PointRCNN, and Apollo) and show how the classification rate drops below 50%. We also analyze the impact of the IEMI injection on two fusion models (AVOD and Frustum-ConvNet) and in real-world scenarios. Finally, we discuss potential countermeasures and propose two strategies to detect signal injection.