{"id":"https://openalex.org/W2959364614","doi":"https://doi.org/10.1145/3319535.3339815","title":"Adversarial Sensor Attack on LiDAR-based Perception in Autonomous Driving","display_name":"Adversarial Sensor Attack on LiDAR-based Perception in Autonomous Driving","publication_year":2019,"publication_date":"2019-11-06","ids":{"openalex":"https://openalex.org/W2959364614","doi":"https://doi.org/10.1145/3319535.3339815","mag":"2959364614"},"language":"en","primary_location":{"id":"doi:10.1145/3319535.3339815","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3339815","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3339815","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3339815","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Yulong Cao","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yulong Cao","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Chaowei Xiao","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chaowei Xiao","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Benjamin Cyr","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Benjamin Cyr","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Yimeng Zhou","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yimeng Zhou","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Won Park","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Won Park","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Sara Rampazzi","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sara Rampazzi","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Qi Alfred Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I204250578","display_name":"University of California, Irvine","ror":"https://ror.org/04gyf1771","country_code":"US","type":"education","lineage":["https://openalex.org/I204250578"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qi Alfred Chen","raw_affiliation_strings":["University of California, Irvine, Irvine, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California, Irvine, Irvine, CA, USA","institution_ids":["https://openalex.org/I204250578"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Kevin Fu","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kevin Fu","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]},{"author_position":"last","author":{"id":null,"display_name":"Z. Morley Mao","orcid":null},"institutions":[{"id":"https://openalex.org/I27837315","display_name":"University of Michigan","ror":"https://ror.org/00jmfr291","country_code":"US","type":"education","lineage":["https://openalex.org/I27837315"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Z. Morley Mao","raw_affiliation_strings":["University of Michigan, Ann Arbor, MI, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Michigan, Ann Arbor, MI, USA","institution_ids":["https://openalex.org/I27837315"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":9,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I27837315"],"apc_list":null,"apc_paid":null,"fwci":23.799,"has_fulltext":true,"cited_by_count":429,"citation_normalized_percentile":{"value":0.99582988,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"2267","last_page":"2281"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9810000061988831,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9670000076293945,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/spoofing-attack","display_name":"Spoofing attack","score":0.7595000267028809},{"id":"https://openalex.org/keywords/perception","display_name":"Perception","score":0.5410000085830688},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.45559999346733093},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.44839999079704285},{"id":"https://openalex.org/keywords/situation-awareness","display_name":"Situation awareness","score":0.4108000099658966},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.35010001063346863},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.3474999964237213},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.3325999975204468}],"concepts":[{"id":"https://openalex.org/C167900197","wikidata":"https://www.wikidata.org/wiki/Q11081100","display_name":"Spoofing attack","level":2,"score":0.7595000267028809},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6467999815940857},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.5410000085830688},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.48669999837875366},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.45559999346733093},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.44839999079704285},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.44440001249313354},{"id":"https://openalex.org/C145804949","wikidata":"https://www.wikidata.org/wiki/Q478123","display_name":"Situation awareness","level":2,"score":0.4108000099658966},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.35010001063346863},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.3474999964237213},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.3325999975204468},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.3319999873638153},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.32010000944137573},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.31200000643730164},{"id":"https://openalex.org/C87833898","wikidata":"https://www.wikidata.org/wiki/Q1060280","display_name":"Advanced driver assistance systems","level":2,"score":0.3070000112056732},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.30140000581741333},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.29440000653266907},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.2840999960899353},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.2770000100135803},{"id":"https://openalex.org/C137836250","wikidata":"https://www.wikidata.org/wiki/Q984063","display_name":"Optimization problem","level":2,"score":0.2759000062942505},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.27549999952316284},{"id":"https://openalex.org/C51399673","wikidata":"https://www.wikidata.org/wiki/Q504027","display_name":"Lidar","level":2,"score":0.26649999618530273},{"id":"https://openalex.org/C3017944768","wikidata":"https://www.wikidata.org/wiki/Q1450463","display_name":"Poison control","level":2,"score":0.25949999690055847},{"id":"https://openalex.org/C14036430","wikidata":"https://www.wikidata.org/wiki/Q3736076","display_name":"Function (biology)","level":2,"score":0.2556999921798706}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3319535.3339815","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3339815","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3339815","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:1907.06826","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1907.06826","pdf_url":"https://arxiv.org/pdf/1907.06826","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"doi:10.1145/3319535.3339815","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3339815","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3339815","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G8230704229","display_name":null,"funder_award_id":"CNS-1544678, ONR N00014-18-1-2020","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":6,"referenced_works":["https://openalex.org/W185142374","https://openalex.org/W2116520617","https://openalex.org/W2949789602","https://openalex.org/W2963564844","https://openalex.org/W2963857521","https://openalex.org/W6713134421"],"related_works":[],"abstract_inverted_index":{"In":[0,46],"Autonomous":[1],"Vehicles":[2],"(AVs),":[3],"one":[4],"fundamental":[5],"pillar":[6],"is":[7,72,109],"perception,which":[8],"leverages":[9],"sensors":[10],"like":[11],"cameras":[12],"and":[13,17,86,148,157,173,180,209,219,230],"LiDARs":[14],"(Light":[15],"Detection":[16],"Ranging)":[18],"to":[19,25,38,48,95,111,116,134,189,196],"understand":[20,197],"the":[21,41,61,83,88,96,117,126,131,136,153,158,163,169,185,198,202,226],"driving":[22,204],"environment.":[23],"Due":[24],"its":[26,40],"direct":[27],"impact":[28,200],"on":[29,53],"road":[30,217],"safety,":[31],"multiple":[32],"prior":[33,49],"efforts":[34],"have":[35],"been":[36],"made":[37],"study":[39,64,195],"security":[42,63],"of":[43,65,98,128,166],"perception":[44,67],"systems.":[45],"contrast":[47],"work":[50,58],"that":[51,104,177,214],"concentrates":[52],"camera-based":[54],"perception,":[55],"in":[56,68],"this":[57,113,142],"we":[59,123,207],"perform":[60],"first":[62],"LiDAR-based":[66],"AV":[69,203,227],"settings,":[70],"which":[71,183],"highly":[73],"important":[74],"but":[75],"unexplored.":[76],"We":[77,102,140],"consider":[78],"LiDAR":[79,107],"spoofing":[80,92,108],"attacks":[81],"as":[82,91,144],"threat":[84],"model":[85,233],"set":[87],"attack":[89,133,186,199,212],"goal":[90,114],"obstacles":[93],"close":[94],"front":[97],"a":[99,193],"victim":[100],"AV.":[101],"find":[103],"blindly":[105],"applying":[106],"insufficient":[110],"achieve":[112],"due":[115],"machine":[118,137,231],"learning-based":[119],"object":[120],"detection":[121],"process.Thus,":[122],"then":[124],"explore":[125],"possibility":[127],"strategically":[129],"controlling":[130],"spoofed":[132],"fool":[135],"learning":[138,232],"model.":[139],"formulate":[141],"task":[143],"an":[145,175],"optimization":[146,172,179],"problem":[147,170],"design":[149,174],"modeling":[150],"methods":[151],"for":[152],"input":[154],"perturbation":[155],"function":[156],"objective":[159],"function.We":[160],"also":[161,221],"identify":[162],"inherent":[164],"limitations":[165],"directly":[167],"solving":[168],"using":[171],"algorithm":[176],"combines":[178],"global":[181],"sampling,":[182],"improves":[184],"success":[187],"rates":[188],"around":[190],"75%.":[191],"As":[192],"case":[194],"at":[201,225],"decision":[205],"level,":[206],"construct":[208],"evaluate":[210],"two":[211],"scenarios":[213],"may":[215],"damage":[216],"safety":[218],"mobility.We":[220],"discuss":[222],"defense":[223],"directions":[224],"system,":[228],"sensor,":[229],"levels.":[234]},"counts_by_year":[{"year":2026,"cited_by_count":17},{"year":2025,"cited_by_count":82},{"year":2024,"cited_by_count":84},{"year":2023,"cited_by_count":82},{"year":2022,"cited_by_count":63},{"year":2021,"cited_by_count":73},{"year":2020,"cited_by_count":27},{"year":2019,"cited_by_count":1}],"updated_date":"2026-05-31T08:46:17.908082","created_date":"2019-07-23T00:00:00"}
