GhostLite: data minimization with applications to real-time LiDAR attacks
File(s) GhostLite camera ready.pdf (1.94 MB)
Accepted version
Author(s)
Capraru, Richard
Lupu, Emil
Wang, Jian-Gang
Hee Soong, Boon
Type
Conference Paper
Abstract
LiDAR-based object detection plays a crucial role
in autonomous driving, yet remains vulnerable to ghost object attacks, where adversarially crafted point clouds trigger false detections. Traditional attack methods often require a large number of points and substantial computational resources, making them inapplicable in real-world scenarios. Although prior research has explored reducing the number of required attack points, real-world feasibility remains a challenge due to the high computational cost and attack generation time. While
LiDAR object detection can be compromised given enough
adversarially crafted points, we believe there are some critical points, which we call reduced attack budget, which are sufficient to attack the detector. Motivated by this consideration, we propose a novel geometric- and heuristic-based approach capable of generating effective ghost object attacks by leveraging the target’s contour characteristics. By strategically selecting a minimal set of adversarial points, as few as 20 points, our approach maintains high detection confidence, reduces attack
execution time and attack budget by up to 4 and 73 times,
respectively, in this paper. Our method has been verified on both simulated and real-world datasets (KITTI). The experimental results demonstrate that our optimized attack significantly reduces computational overhead and consequently improves the attack’s real-time feasibility.
in autonomous driving, yet remains vulnerable to ghost object attacks, where adversarially crafted point clouds trigger false detections. Traditional attack methods often require a large number of points and substantial computational resources, making them inapplicable in real-world scenarios. Although prior research has explored reducing the number of required attack points, real-world feasibility remains a challenge due to the high computational cost and attack generation time. While
LiDAR object detection can be compromised given enough
adversarially crafted points, we believe there are some critical points, which we call reduced attack budget, which are sufficient to attack the detector. Motivated by this consideration, we propose a novel geometric- and heuristic-based approach capable of generating effective ghost object attacks by leveraging the target’s contour characteristics. By strategically selecting a minimal set of adversarial points, as few as 20 points, our approach maintains high detection confidence, reduces attack
execution time and attack budget by up to 4 and 73 times,
respectively, in this paper. Our method has been verified on both simulated and real-world datasets (KITTI). The experimental results demonstrate that our optimized attack significantly reduces computational overhead and consequently improves the attack’s real-time feasibility.
Date Issued
2026-01-06
Date Acceptance
2025-06-01
Citation
2025 IEEE 102nd Vehicular Technology Conference (VTC2025-Fall), 2026
ISBN
979-8-3315-0321-5
ISSN
1090-3038
Publisher
IEEE
Journal / Book Title
2025 IEEE 102nd Vehicular Technology Conference (VTC2025-Fall)
Copyright Statement
Copyright © ©2025 IEEE. This is the author’s accepted manuscript made available under a CC-BY licence in accordance with Imperial’s Research Publications Open Access policy (www.imperial.ac.uk/oa-policy)
License URL
Source
VTC2025-Fall
Place of Publication
Chengdu, China
Publication Status
Published
Start Date
2025-10-19
Finish Date
2025-10-22
Coverage Spatial
Chengdu, China
Date Publish Online
2026-01-06
