A roadside AI now picks the exact moment and method to fake out a self-driving car's LiDAR - and it wins every time in simulation.
Researchers built TACTIC, a framework that pairs a roadside sensor rig with a multimodal large language model to plan physical LiDAR attacks on the fly. The system never touches the target vehicle's own sensors. Instead it watches traffic from the roadside, uses an MLLM to turn that view plus local measurements into a live map of who is near whom, and picks between two tricks: making a lead vehicle appear farther away than it is, or spoofing a phantom obstacle to trigger emergency braking. In 280 randomized CARLA simulation runs, the full system scored a 100% collision rate, compared with 35% for a fixed attack pattern, 60% for random selection, and 75% for a simpler LLM limited to picking a mode with default settings.
The gap matters because most published LiDAR attacks assume a static scene and a single pre-tuned trick. TACTIC's results suggest that assumption understates the real risk: feeding the model both camera images and physical measurements beat either input alone (100% versus 65% and 75%), and reworking the pipeline to replan asynchronously cut the system's reaction time to traffic changes from 7.4 seconds to 2.0 seconds, fast enough to keep up with real driving.
Worth noting what this is not: it is a simulated demonstration against a gray-box target, run with an attacker-controlled roadside sensor setup, not a confirmed attack on production self-driving cars. Still, it is a clear signal that LiDAR defenses tested only against fixed, context-blind attacks are being tested against the wrong adversary.