Breaking the Shield: Systematic Security Analysis on Pulse Fingerprinting LiDAR Systems for Autonomous Driving
Yuki Hayakawa, Takami Sato, Ryo Suzuki, Kazuma Ikeda, Ozora Sako, Rokuto Nagata, Ryo Yoshida, Qi Alfred Chen, Kentaro Yoshioka · IEEE Sensors Journal · 2025
LiDAR sensors play a crucial role in autonomous driving (AD) systems because of their high-definition 3D sensing capabilities. While LiDAR spoofing attacks that project fake ranging signals pose a critical security threat, new-generation (new-gen) LiDARs have introduced pulse fingerprinting (PF), an authentication mechanism that distinguishes reflected signals from external interference. Although PF offers a promising defense against spoofing attacks, its security implications remain unexplored. This paper presents the first comprehensive security evaluation of PF features. While current PF-equipped LiDARs use the time difference of pulse pairs as authentication to counter conventional spoofing attacks, we demonstrate their vulnerability to periodic malicious laser pulses through two novel attacks: High-Frequency Removal (HFR) and Adaptive HFR (A-HFR). The basic HFR attack employs high-frequency laser pulses, while A-HFR incorporates weak synchronization and selective range limiting to prevent laser overheating, achieving spoofing frequencies 25 times higher than HFR. Our evaluation of three commercial LiDARs with PF reveals their vulnerability to these attacks, with over 96% of the point cloud data vanishing within the attack target area. Through attack simulations against Autoware using real attack data, we show that successful attacks in over 90% of frames invariably lead to accidents, highlighting significant limitations in current PF implementations. We conclude by proposing enhanced security measures for both AD systems and PF mechanisms.