Keio University · Computing and Sensing Group

LiDAR spoofing: raw captures of injection and removal attacks

Packet captures (.pcap) from the physical experiments behind our LiDAR spoofing papers, each paired with a video. Every capture comes with a bird’s-eye rendering made from the pcap itself; where the original VeloView screen recording or a camera view exists, it is shown alongside.

Benign capture Attack capture Camera view of the scene CPI = Chosen Pattern Injection · PRA = Physical Removal Attack (synchronized) · HFR = High-Frequency Removal · A-HFR = adaptive HFR

Using the captures

  • Each download is a zip holding one unmodified pcap, exactly as recorded (VeloView, PandarView or Wireshark) on UDP port 2368. The SHA-256 shown is that of the pcap inside.
  • Open Velodyne captures in VeloView (or velodyne_decoder, ROS velodyne_pointcloud) and Hesai captures in PandarView or the Hesai LiDAR SDK. AT128 needs its angle-correction file, which is attached to the NDSS 2025 release. The LiDAR model and return mode below are read from the packets themselves.
  • Bird’s-eye renderings are top-down views, 0.1 s per frame (one 600 rpm revolution), coloured by height. In dual-return captures only the first return of each pair is drawn. AT128 renderings ignore its fine per-channel angle offsets (under about 0.5°).
  • Recorded videos are VeloView screen recordings made during the experiments; some were matched to their capture by timestamp.
  • “Removal check” (Hesai captures): share of 0.1 s frames with an azimuth gap of at least 8° where the scene normally returns points, and the longest run of such frames. Benign captures score 0 %. Attack runs in which the attack did not take effect are not published.

Experimental setup (NDSS 2024)

Indoor spoofing setup with laser spoofer aimed at the LiDAR
Indoor setup
Outdoor spoofing setup in a parking lot
Outdoor setup
Vehicle-removal setup with a parked car in front of the LiDAR
Vehicle removal (HFR)