PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR

Zizhi Jin

Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · Sensor Attacks

Overview

LiDAR (Light Detection and Ranging) systems are foundational technologies for autonomous vehicles, robotics, and various industrial applications, providing critical 3D perception of the environment. The accuracy and integrity of LiDAR data are paramount for ensuring system safety and reliability. This talk, "PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR," delves into novel attack vectors against these essential sensors, demonstrating how Electromagnetic Interference (EMI) can be leveraged to compromise LiDAR functionality in unprecedented ways. The research highlights significant vulnerabilities that extend beyond previously explored attack surfaces, emphasizing the urgent need for enhanced security measures in LiDAR design and deployment.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to Lidar security and system overview
  2. 2:00 PhantomLiDAR's four attack effects and core principles
  3. 4:00 Detailing the point interference attack mechanism
  4. 4:30 Understanding the point remover attack principles
  5. 5:40 How PhantomLiDAR can cause Lidar system shutdown
  6. 6:00 Forging controllable points into Lidar data
  7. 7:00 Demonstrating PhantomLiDAR's impact in real-world scenarios

PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR

Speakers: Zizhi Jin, Author (presented by Ian Jang)

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=WGO0uDlT-aQ

Overview

LiDAR (Light Detection and Ranging) systems are foundational technologies for autonomous vehicles, robotics, and various industrial applications, providing critical 3D perception of the environment. The accuracy and integrity of LiDAR data are paramount for ensuring system safety and reliability. This talk, "PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR," delves into novel attack vectors against these essential sensors, demonstrating how Electromagnetic Interference (EMI) can be leveraged to compromise LiDAR functionality in unprecedented ways. The research highlights significant vulnerabilities that extend beyond previously explored attack surfaces, emphasizing the urgent need for enhanced security measures in LiDAR design and deployment.

Presented by Ian Jang on behalf of the paper's author, Zizhi Jin, this work introduces "PhantomLiDAR," a comprehensive framework for injecting malicious signals into LiDAR systems. Unlike prior research predominantly focused on direct laser-based manipulation, PhantomLiDAR explores the susceptibility of various internal LiDAR modules to EMI, revealing both direct signal disruption and indirect exploitation of internal diagnostic mechanisms. The findings underscore a critical gap in current LiDAR security paradigms, challenging the assumption that these systems are robust against non-optical interference and paving the way for more reliable and secure LiDAR implementations in the future.

The significance of PhantomLiDAR lies in its systematic exploration of EMI as a cross-modality attack vector. By demonstrating four distinct attack effects—ranging from subtle point cloud corruption to complete system shutdown and the injection of phantom objects—the research exposes a broad spectrum of risks. This work is crucial for engineers, researchers, and policymakers involved in the development and regulation of autonomous systems, as it provides a detailed understanding of sophisticated threats that could lead to dangerous operational failures or misleading perceptions in safety-critical applications.

Background

▶ Watch: Introduction to Lidar security and system overview (0:00)

LiDAR technology operates on the principle of laser ranging and laser scanning to construct a detailed 3D representation of its surroundings, known as a point cloud. At its core, a LiDAR system emits laser pulses in various directions. When a pulse strikes an object, it reflects back as an echo. The distance to that point is precisely calculated based on the Time of Flight (ToF) principle—measuring the time taken for the laser pulse to travel to the object and return. By rapidly changing the laser's firing direction through scanning mechanisms, LiDAR can acquire millions of such points, forming a comprehensive 3D map.

A typical commercial LiDAR system is a complex integration of several key functional modules. These generally include an emitter responsible for generating and transmitting laser pulses, a receiver designed to detect and process the returning echo signals, a beam steering module that precisely controls the laser's direction for scanning the environment, and a main board which houses the central processing unit, signal processing logic, and various auxiliary circuits and sensors. Each of these modules plays a critical role in the overall operation and data integrity of the LiDAR system.

Historically, research into LiDAR security has primarily focused on laser-based attacks. These studies often considered the receiver as the primary attack surface, attempting to manipulate the laser ranging process by injecting spoofing laser pulses or blinding the sensor with high-intensity light. While effective in certain scenarios, these attacks typically require line-of-sight and precise optical alignment, limiting their practical applicability. More recently, some works began to investigate the potential for Electromagnetic Interference (EMI) to compromise LiDAR. However, these initial explorations often lacked a systematic analysis of the entire LiDAR system, leaving many internal modules and their vulnerabilities unexplored. This created a significant research gap: the comprehensive assessment of how EMI could impact the full spectrum of LiDAR components and functions, and whether such interference could exploit the system's internal diagnostic mechanisms. PhantomLiDAR seeks to fill this gap by dissecting the LiDAR system's architecture and systematically identifying and exploiting new attack surfaces through EMI.

Key Findings

▶ Watch: Detailing the point interference attack mechanism (4:00)

The PhantomLiDAR research unveils a groundbreaking understanding of LiDAR vulnerabilities, fundamentally shifting the perspective on how these critical sensors can be compromised. The key findings are multifaceted, introducing novel attack surfaces, diverse attack effects, and robust attack capabilities.

Firstly, the research systematically identified new attack surfaces within commercial LiDAR systems that were previously unexamined. Beyond the conventional focus on the optical receiver, PhantomLiDAR demonstrates successful exploitation of the laser receiving analog circuit (within the receiver module), monitor sensors on the main board (e.g., temperature sensors), and the optical encoder in the beam steering module. This expansion of attack surfaces reveals that LiDAR's complexity, rather than solely its optical nature, introduces a broader range of vulnerabilities.

Secondly, PhantomLiDAR categorizes and demonstrates four distinct types of attack effects, showcasing the versatility and severity of EMI-based compromise:

  1. Point Interference: Introducing errors in the measured distances, thereby corrupting the accuracy and integrity of the generated point cloud. This can lead to misinterpretations of the environment.
  2. Point Remover: Causing legitimate objects or environmental features to appear significantly farther away or to disappear entirely from the point cloud. This can create dangerous "blind spots" for autonomous systems.
  3. LiDAR Power Off: Forcing the entire LiDAR system to shut down and cease operation, effectively rendering the autonomous system blind to its surroundings.
  4. Point Injection: Injecting controllable, false points into the point cloud, creating "phantom" objects that do not exist in the real world. This can mislead navigation and object detection systems.

Thirdly, the research identifies and leverages two fundamental attack principles:

  1. Direct Attack: This principle involves directly interfering with the analog electrical signals within the LiDAR's receiving module. By manipulating these signals, the attack directly disrupts the laser ranging process, leading to immediate corruption of the point cloud.
  2. Indirect Attack: This more sophisticated principle involves inducing errors in the LiDAR's auxiliary circuits (e.g., sensors monitoring internal temperature or rotational speed). These induced errors then exploit the LiDAR's Fault Detection and Diagnostic (FDD) mechanisms. Designed for safety, these FDD systems, when triggered by manipulated sensor readings, can inadvertently cause severe operational issues such as point removal or even system shutdown, turning a safety feature into an attack vector.

Finally, the evaluation of PhantomLiDAR demonstrates strong attackability. The attacks exhibit long effective distances and low location/aiming requirements compared to traditional laser-based attacks, making them more practical and difficult to detect. The ability to inject complex spoofing patterns, such as entire walls or pedestrians, into the point cloud highlights the potential for highly deceptive and dangerous manipulations. Furthermore, the study revealed that different commercial LiDAR modules exhibit distinct vulnerabilities when subjected to EMI fuzzing, providing crucial insights for future, more robust LiDAR designs. Importantly, the research also offered a glimmer of hope for defense, indicating that sensor fusion (combining LiDAR data with other sensor inputs like cameras or radar) can effectively mitigate certain types of point interference, suggesting a path towards more resilient perception systems.

Technical Deep Dive

▶ Watch: Understanding the point remover attack principles (4:30)

The technical prowess of PhantomLiDAR lies in its detailed understanding of LiDAR's internal architecture and the nuanced ways in which electromagnetic interference can manipulate its sensitive electronic and optical components. The researchers systematically dissected the LiDAR system into its four core modules—the emitter, receiver, beam steering module, and main board—to identify and target specific vulnerabilities.

The emitter is responsible for generating and sending out laser pulses. While not a direct target in most PhantomLiDAR attacks, its interaction with the receiver and beam steering module is crucial. The receiver is arguably the most critical component for signal integrity, converting the returning optical echo into electrical signals that can be processed to determine distance. It typically contains highly sensitive analog circuitry designed to detect faint laser reflections. The beam steering module dictates the direction of the laser pulses, often employing motors and precise angular sensors like optical encoders to ensure accurate scanning. Finally, the main board acts as the central hub, performing signal processing, data aggregation, and housing various auxiliary circuits, including monitor sensors (e.g., temperature sensors) that oversee the system's operational health.

PhantomLiDAR leverages two primary attack principles:

  1. Direct Attack: This principle targets the sensitive analog circuit within the receiver module. LiDAR echoes are extremely weak analog signals that are amplified and processed to determine the precise time of arrival. By injecting a carefully crafted EMI signal, particularly a sinusoidal wave, this external interference can mix with the genuine echo signal. This mixing introduces subtle but critical variations in the detected "pick time" of the echo pulse. Since distance is derived directly from the ToF, even minor fluctuations in pick time translate into significant distance errors, leading to point interference where the point cloud becomes distorted and inaccurate. For point injection, the direct attack is more sophisticated. The researchers designed the attack signal using Amplitude Modulation (AM). Here, a carrier signal (a high-frequency sinusoidal wave) is modulated by a baseband signal consisting of fine-grained pulses. This amplitude-modulated sine wave can effectively forge an artificial echo signal that mimics a legitimate return pulse. When this forged echo is detected by the receiver, it is processed as if a real object reflected a laser pulse, resulting in the injection of controllable, false points into the point cloud. Furthermore, a high-amplitude sinusoidal EMI signal can be used for direct point remover attacks. By saturating the receiving circuit, this intense interference overwhelms the sensor's dynamic range, making it impossible to detect legitimate echo pulses, causing objects to disappear from the point cloud.
  1. Indirect Attack: This principle exploits the LiDAR's inherent Fault Detection and Diagnostic (FDD) mechanisms. These FDD systems are designed as safety features, continuously monitoring the operational parameters of the LiDAR (e.g., temperature, rotational speed, power draw) to ensure safe and reliable performance. If these parameters deviate significantly from their normal ranges, the FDD mechanism triggers protective actions, which can range from flagging invalid data to shutting down the system. PhantomLiDAR weaponizes these safety mechanisms.
  • For point remover attacks via indirect means, the attack targets monitoring sensors on the main board, such as the temperature sensor. By injecting EMI, the researchers induced dramatic and rapid fluctuations in the reported temperature readings. For instance, the transcript mentions temperature fluctuating dramatically when EMI is on, while stable at 14°C when off. The FDD system, interpreting these erratic temperature readings as a critical malfunction or an unsafe operating condition, then deems some or all incoming point cloud data as invalid, effectively "removing" points.
  • The LiDAR power off attack similarly leverages an indirect approach, targeting the optical encoder within the beam steering module. Optical encoders are crucial for precisely measuring the rotational speed and angular position of the laser scanner. EMI injected into this module can disrupt the encoder's readings, causing it to report an abnormally low or erratic rotation speed. As shown in the figures, the rotational speed drops significantly when the attack is active. The FDD mechanism, perceiving a critical failure in the scanning mechanism (e.g., the motor stalling or moving erratically), intervenes to prevent further damage or unsafe operation by cutting off power to the entire LiDAR system, leading to a complete shutdown.

The careful design of EMI signals, ranging from simple sinusoids for direct interference to sophisticated amplitude-modulated signals for injection, highlights the attackers' understanding of both the analog signal processing chain and the digital diagnostic logic within modern LiDAR systems. This cross-modality aspect—where electrical interference directly impacts optical ranging and indirectly manipulates software-driven safety protocols—is a central theme of the PhantomLiDAR research.

Demo / Proof of Concept

▶ Watch: Forging controllable points into Lidar data (6:00)

To validate the PhantomLiDAR attacks, the researchers conducted extensive real-world experiments, meticulously evaluating the efficacy and characteristics of each attack effect across various commercial LiDAR systems. The experimental setup was designed to be practical and reproducible, typically comprising a signal generator (to create the specific EMI waveforms), a power amplifier (to boost the signal strength), and an antenna (to broadcast the EMI towards the target LiDAR).

The initial phase involved testing five different commercial LiDAR modules. By fuzzing these systems with a range of EMI signals, the researchers discovered that different LiDAR models exhibited distinct vulnerabilities, underscoring the lack of standardized EMI hardening and the diverse engineering approaches among manufacturers. This finding suggests that a "one-size-fits-all" defense may not be sufficient, and future designs must explicitly consider EMI resilience.

For point interference, the attacks were quantified by measuring the induced distance errors. The experiments successfully demonstrated that PhantomLiDAR could induce significant errors, specifically over 10 cm in the reported distances. Such errors, while seemingly small, can be catastrophic for autonomous navigation, where precise object localization is paramount. Further, the research explored the impact of this interference on 3D object detection models. While point interference could indeed destabilize these models, an important observation was that sensor fusion—the integration of data from multiple sensor types (e.g., LiDAR, camera, radar)—could effectively mitigate the impact of point interference. This provides a crucial guidance for developing more robust defense strategies.

Regarding point remover attacks, the experiments revealed impressive practical characteristics. The attacks demonstrated long attack distances and low location requirements, meaning the attacker did not need to be in close proximity or require precise aiming. This contrasts sharply with laser-based attacks, which typically demand precise optical alignment and closer range. The ability to induce point removal from a distance with minimal aiming makes this attack particularly insidious and difficult to detect or counter preemptively.

The most visually striking demonstration involved point injection. The researchers successfully injected spoofing point clouds with different patterns, including realistic shapes such as a wall or a pedestrian. This capability highlights the potential for highly deceptive attacks, where autonomous systems could perceive non-existent obstacles or vulnerable road users, leading to dangerous evasive maneuvers or false positives. The precision and control over the injected patterns underscore the sophistication of the amplitude modulation technique employed.

Finally, the team conducted a compelling real-world experiment with a moving vehicle. The objective was to compromise the victim's LiDAR system while in motion and demonstrate that the LiDAR-based 3D object detection model would become unstable, ultimately failing to detect a legitimate target object. While the full video of this experiment is referred to on their website, this demonstration illustrates the critical real-world implications of PhantomLiDAR attacks, confirming their potential to disrupt the perception stack of autonomous systems and compromise safety. The practical success of these varied demonstrations firmly establishes PhantomLiDAR as a potent and versatile threat to LiDAR integrity.

Defensive Implications

▶ Watch: Demonstrating PhantomLiDAR's impact in real-world scenarios (7:00)

The findings from the PhantomLiDAR research present a clear call to action for enhancing the security and resilience of LiDAR systems. The demonstrated vulnerabilities necessitate a multi-layered defensive strategy that addresses both the direct effects of EMI and the indirect exploitation of internal diagnostic mechanisms.

Foremost, physical shielding and electromagnetic hardening are critical. The analog circuits within the receiver, the monitoring sensors on the main board, and the optical encoders in the beam steering module are all susceptible to EMI. LiDAR manufacturers must integrate robust electromagnetic shielding into the physical design of these components and the overall system enclosure. This includes using shielded cables, employing Faraday cages for sensitive electronics, and selecting components with inherent EMI immunity. Testing and certification against a wider range of EMI frequencies and intensities, beyond current standards, will be crucial.

Secondly, the reliance on and exploitation of Fault Detection and Diagnostic (FDD) mechanisms highlight a need for increased robustness in these safety-critical systems. While FDD is essential, it must be designed to differentiate between genuine component failures and manipulated sensor readings. This could involve:

  • Redundant Sensing: Using multiple, diverse sensors to cross-verify critical parameters (e.g., two temperature sensors, or a temperature sensor and a thermal camera).
  • Anomaly Detection: Implementing intelligent algorithms that can detect unusual patterns in sensor data that might indicate an attack rather than a physical fault (e.g., sudden, dramatic, and localized temperature fluctuations that defy physical possibility).
  • Consistency Checks: Validating sensor readings against physical models or expected operational ranges. For instance, if an optical encoder reports zero rotation speed while other sensors indicate the vehicle is moving, this inconsistency should trigger a more sophisticated diagnostic process than an immediate shutdown.

Thirdly, the research explicitly validates the importance of sensor fusion as a robust mitigation strategy. The observation that sensor fusion can effectively mitigate point interference underscores the value of integrating LiDAR data with inputs from other modalities such, as cameras, radar, and ultrasonic sensors. An autonomous system should not solely rely on a single sensor type for critical decision-making. If LiDAR data appears corrupted or injects phantom objects, other sensors can provide corroborating or contradictory evidence, allowing the system to identify and potentially filter out malicious data, or at least enter a safe operational state.

Finally, the discovery of distinct vulnerabilities across different commercial LiDAR models offers a vital insight for future design. Manufacturers should move towards a security-by-design approach, incorporating EMI resilience and attack-aware FDD mechanisms from the ground up. This involves thorough threat modeling that considers cross-modality attacks and adopting best practices from other safety-critical industries for electromagnetic compatibility (EMC) and cybersecurity. Post-processing algorithms could also be developed to identify and filter out anomalous points in the point cloud that might indicate injection or removal, based on spatial and temporal consistency with surrounding data or other sensor inputs. These defensive measures, collectively, can significantly improve the reliability and trustworthiness of LiDAR systems against sophisticated EMI attacks like PhantomLiDAR.

Key Takeaways

  • LiDAR systems, critical for autonomous vehicles and robotics, are highly vulnerable to Electromagnetic Interference (EMI) attacks, extending beyond traditional laser-based threats.
  • PhantomLiDAR identifies novel attack surfaces within LiDAR, including the receiver's analog circuits, main board monitoring sensors, and beam steering optical encoders, showcasing a broader attack vector than previously understood.
  • Attacks can be executed through two primary principles: direct interference with analog signals for immediate data corruption, and indirect exploitation of the LiDAR's Fault Detection and Diagnostic (FDD) mechanisms.
  • Four distinct and impactful attack effects are demonstrated: point interference, point remover, LiDAR power off, and point injection (including realistic spoofing of objects like walls or pedestrians).
  • These EMI attacks exhibit strong practical capabilities, characterized by long attack distances and low aiming requirements, making them more feasible and challenging to detect in real-world scenarios.
  • Sensor fusion with other modalities (e.g., cameras, radar) emerges as a crucial defense strategy to mitigate certain EMI-induced point cloud corruptions, emphasizing the need for multi-modal redundancy in autonomous systems.

About the Speaker(s)

The research paper "PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR" was authored by Zizhi Jin. Due to unforeseen circumstances, Zizhi Jin was unable to present the paper at the NDSS Symposium. The presentation was instead delivered by Ian Jang, who represented the research team. Zizhi Jin's work focuses on the security and reliability of LiDAR systems, exploring novel attack vectors and vulnerabilities that challenge existing assumptions about sensor robustness, particularly in the context of critical applications like autonomous driving and robotics.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Systematic EMI attack framework against LiDAR that expands the attack surface beyond the optical layer — hitting analog receive circuits, temperature monitor sensors, and optical encoders — and weaponizes the FDD safety stack itself. Solid novelty, real hardware validation across five commercial units, and the indirect FDD exploitation angle is the kind of counterintuitive finding that makes security people uncomfortable in the right way.

Heather Calloway (CISO) — WEAK

Technically credible research on a real attack surface, but it stops exactly where a security leader needs it to start. The work demonstrates the vulnerability; it does not address who owns the risk, what the regulatory exposure looks like, or what an operator or policymaker is supposed to do with this Monday morning.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025