A microscopic prism-patterned film can shift how vehicle cameras and LiDAR perceive road lanes, potentially triggering dangerous steering decisions and exposing a critical weakness in autonomous driving safety systems.

Researchers at the Technical University of Munich (TUM), Germany, have demonstrated how a thin optical film can manipulate the perception systems of autonomous vehicles without making lane markings or surrounding objects disappear. The attack can shift their apparent positions, potentially causing a vehicle to steer into oncoming traffic.
The findings, presented at the 2026 USENIX Symposium on Vehicle Security and Privacy, highlight a cybersecurity risk in the optical sensors used by autonomous driving and advanced driver-assistance systems (ADAS). Unlike attacks that make objects difficult to detect, this technique allows vehicles to continue recognising lanes and obstacles while misjudging where they are.
Optical Film Shifts Sensor Perspective
The researchers used a polycarbonate film containing microscopic, asymmetrical linear prism structures. When placed over an optical sensor, the film bends incoming light by 20 degrees, shifting the sensor’s field of view.
This manipulation affects cameras and light detection and ranging (LiDAR) systems, which perform complementary roles in environmental perception. Cameras interpret visual information such as road markings, traffic signs and other road users, while LiDAR measures distances to construct a three-dimensional representation of the surroundings.
By redirecting incoming light, the film changes the apparent positions of detected objects and lanes. The vehicle’s perception software may therefore process incorrect spatial information even when its object-detection algorithms continue reporting high confidence.
According to the researchers, a positional displacement exceeding one metre can lead to incorrect driving decisions, including unintended movement into the opposite lane. This makes the attack particularly concerning because conventional checks based on whether an object has been detected may fail to identify the underlying problem.
Digital Twins Help Test Attacks
The team is investigating vulnerabilities across vehicle cameras, LiDAR sensors and their associated data-processing pipelines. Before testing attacks on physical vehicles, researchers use digital twins—virtual replicas of vehicles and their surroundings—to examine potential failures under controlled conditions. The experiments are also being evaluated in controlled environments using TUM’s EDGAR autonomous research vehicle.
The researchers are exploring mechanisms to detect and mitigate sensor manipulation. Potential safeguards include identifying physical anomalies in sensor signals and checking whether different perception outputs remain consistent with one another.
Future autonomous vehicles could use such checks to recognise compromised sensors, warn occupants or safely pull over before continuing becomes dangerous. These safeguards will become increasingly important as vehicles rely more heavily on automated perception and operate in situations where remote human intervention may not be available.





