Research Project

Comprehensive Robustness Analysis of LiDAR-based 3D Object Detection in Autonomous Driving

ECCV 2026
3D Object Detection LiDAR Perception Adversarial Robustness Autonomous Driving Safety-Critical AI
1Institute for Technologies and Management of Digital Transformation (TMDT), University of Wuppertal, Germany
2IKB Faculty of Science, University of British Columbia, Canada
*Work done during a Research Internship at TMDT, University of Wuppertal funded by the DAAD RISE program.

Video Presentation

Adversarial Attack Comparison on 3D LiDAR Point Cloud

Bird's-Eye-View (BEV) Detection Comparison: A subtle adversarial coordinate perturbation leads to severe prediction degradation (missed true positives and phantom bounding boxes), exposing fundamental vulnerabilities in state-of-the-art 3D object detectors.

Abstract

Recent advancements in LiDAR-only 3D object detection have demonstrated improved detection accuracy over benchmark datasets. However, the adversarial robustness of these models remains untested. Very few adversarial robustness studies exist for LiDAR-only 3D object detection and unfortunately, even they are limited to legacy models. Moreover, there is a systemic gap in the existing evaluation frameworks that rely simply on mAP ignoring other structural and predictive factors. To fill this gap, we propose a holistic framework that evaluates adversarial robustness using two structural factors (point cloud density and point cloud localization) and three predictive factors (misclassification, localization error, distance from ego). Using this framework, we perform an empirical study and critical analysis on recent and legacy state-of-theart models using adversarial attacks specifically designed for LiDAR based models. Our key finding is that high-capacity, voxel-based detectors are more susceptible to structured coordinate perturbations than pillar-based detectors. Additionally, non-anchor-based detectors demonstrate poor adversarial robustness, which necessitates rethinking model training techniques. Overall, our results demonstrate that recent models are as vulnerable to adversarial attacks as their predecessors. Therefore, we argue that there is a need to improve the evaluation benchmarks for 3D object detection that not only reward architectural modifications for improving detection accuracy, but also evaluate whether the design choices improve adversarial robustness.

Key Contributions & Core Findings

Multi-Factor Robustness Framework
Moves beyond simple mean Average Precision (mAP) by evaluating structural factors (point density and localization) alongside predictive factors (misclassification, bounding box error, and distance from the ego vehicle).
Voxel vs. Pillar Architectures
High-capacity, voxel-based detectors (e.g., CenterPoint, FocalFormer3D) exhibit substantially higher vulnerability to structured coordinate perturbations compared to pillar-based detectors.
Anchor-Free Detector Fragility
Non-anchor-based detectors demonstrate severe susceptibility to adversarial point attacks, highlighting an urgent need for robustness-oriented training paradigms.
PC Density as a double-edged sword
Contrary to the intuition that higher point cloud density bolsters model resilience, our findings establish that point density and adversarial robustness are largely orthogonal.

Pipeline Architecture & Methodology

Adversarial Robustness Evaluation Pipeline Methodology

Methodology Overview: End-to-end framework for evaluating adversarial robustness in LiDAR-based 3D object detection across structural and predictive multi-factor metrics, diverse attack suites, and detection architectures. The robustness factors are represented in boxes.

Benchmark Results (Attack Success Rate)

Note: Higher Attack Success Rate (ASR %) indicates greater vulnerability to the adversarial attack. Values in bold represent highest vulnerability per attack column.

nuScenes Benchmark

Model LiDAttack Non-E2E IoU-S Attack Variants
Attachment Perturbation Detachment
CenterPoint 0.81% 48.60% 23.30% 88.46% 43.26%
FocalFormer3D 5.77% 59.30% 50.33% 97.86% 68.30%
PillarNeSt 0.60% 35.22% 50.29% 53.15% 45.27%
PointPillars 0.95% 49.32% 75.70% 40.83% 38.20%

Waymo Open Dataset Benchmark

Model LiDAttack Non-E2E IoU-S Attack Variants
Attachment Perturbation Detachment
CenterPoint 0.00% 71.49% 33.50% 71.49% 74.36%
FocalFormer3D 2.44% 93.25% 25.28% 93.25% 33.12%
PillarNeSt 3.02% 43.57% 39.13% 43.57% 23.73%
PointPillars 2.65% 19.17% 65.05% 19.17% 33.00%

Qualitative Visualizations

Visual comparisons between clean LiDAR point clouds and adversarial perturbations generated across our benchmark:

Point Cloud BEV Depth
Bird's-Eye-View (BEV) Depth Map: Visualizing spatial depth distribution across LiDAR return points in the scene.
Adversarial vs Clean Comparison
Clean vs. Adversarially Perturbed Point Cloud: Demonstrating how targeted point additions/shifts mislead 3D bounding box estimation.
Object-Level Crop
Zoomed Object View: Fine-grained crop around a target vehicle showing perturbed point clusters.

BibTeX Citation

@misc{chandorkar2026comprehensiverobustnessanalysislidarbased, title={Comprehensive Robustness Analysis of LiDAR-based 3D Object Detection in Autonomous Driving}, author={Adwait Chandorkar and Kai Krink and Yerdana Maulenbay and Hasan Tercan and Tobias Meisen}, year={2026}, eprint={2607.02074}, archivePrefix={arXiv}, primaryClass={cs.CV}, url={https://arxiv.org/abs/2607.02074}, }