Idaho National Lab Investigates Chinese LiDAR Security Vulnerabilities in Autonomous Vehicles

TL;DR
- Idaho National Laboratory is leading a U.S. government-backed security review of Chinese-made LiDAR sensors to assess potential cyber vulnerabilities, including risks of remote hacking, data exfiltration, and spoofing in connected and autonomous vehicles.
- The study comes as Chinese manufacturers like Hesai, RoboSense, and Livox dominate the global LiDAR market, raising concerns in Washington about national security and supply chain dependence for critical automotive technology.
- Unusually, the research is being partially funded by a consortium of U.S. automakers and autonomous driving companies who see securing the LiDAR supply chain as critical to the future of EVs and self-driving deployment.
LiDAR — Light Detection and Ranging — is the invisible eye that allows modern electric and autonomous vehicles to see the world in 3D. By firing millions of laser pulses per second, it builds a precise, real-time map of roads, pedestrians, and obstacles. As vehicles become more connected and more autonomous, LiDAR has shifted from a niche sensor to critical infrastructure. That shift is exactly why it is now at the center of a major national security review.
For years, the U.S. has relied heavily on Chinese-made LiDAR to power its next-generation fleets. Now, the government wants to know if that dependence has created a hidden vulnerability.
Why LiDAR Is Suddenly a National Security Issue
The concern is not just about where LiDAR is made, but what it could do. Unlike a simple camera, LiDAR sensors are sophisticated networked computers. They run firmware, connect to a vehicle's internal network, process vast amounts of geospatial data, and in many cases, receive over-the-air software updates from their manufacturer.
Security researchers and U.S. officials warn this creates several potential attack vectors. A compromised sensor could theoretically be used to exfiltrate highly detailed 3D mapping data of U.S. roads and infrastructure back to a foreign server. More alarmingly, vulnerabilities in firmware could allow a malicious actor to spoof or manipulate sensor data, causing a vehicle to misidentify an obstacle, ignore a pedestrian, or brake unexpectedly. Others have raised concerns about a potential kill-switch, where a fleet of vehicles could be disabled remotely through a backdoor in the sensor's software.
These fears have been amplified by the sheer market dominance of Chinese firms. Hesai Technology, RoboSense, and Livox together control well over 60% of the global automotive LiDAR market, with their low-cost sensors widely integrated into testing fleets, robotaxis, and even consumer EVs sold in the U.S. and Europe. In Washington, the situation echoes earlier debates over Chinese-made telecom equipment and drones, prompting calls from lawmakers and the Department of Commerce to treat LiDAR as a critical technology subject to stricter oversight.
Inside the Idaho National Laboratory Investigation
To move beyond speculation, the U.S. Department of Energy has tasked Idaho National Laboratory with conducting a deep technical teardown of Chinese-made LiDAR units. INL, one of the nation's leading centers for critical infrastructure and industrial control system cybersecurity, is uniquely positioned for the task. The lab has a long history of testing the cyber-resilience of everything from power grids to electric vehicle chargers.
According to details of the program, INL researchers are acquiring commercially available LiDAR sensors from leading Chinese vendors and subjecting them to rigorous hardware and software analysis. The testing includes reverse-engineering firmware to look for hardcoded credentials, undocumented communication protocols, or hidden remote access capabilities. Researchers are also analyzing network traffic to determine what data the sensors collect, where that data is sent, and whether it is encrypted. A key part of the review involves penetration testing to see if the sensors can be hacked to inject false data into a vehicle's perception system.
The goal is not to prove that a backdoor exists, but to provide a definitive, science-based risk assessment for federal policymakers. The findings are expected to inform upcoming decisions by the Department of Commerce's Bureau of Industry and Security and the Department of Transportation on whether to restrict or ban certain Chinese LiDAR systems from connected vehicles on U.S. roads, similar to recent rules proposed for Chinese connected-vehicle software and hardware.
Why Automakers Are Paying for the Research Themselves
Perhaps the most telling detail of the INL study is who is helping to fund it. Alongside federal support, the research is being co-funded by a private consortium of automakers and autonomous vehicle developers.
This unusual public-private funding model reflects a growing anxiety within the industry itself. For companies like Ford, General Motors, Stellantis, and autonomous players such as Waymo, Aurora, and Zoox, LiDAR supply chain security is no longer an abstract policy issue — it is a direct business risk. A government ban or security recall of a widely used sensor could disrupt production lines, delay robotaxi deployments, and force costly redesigns.
By funding independent testing at a trusted national lab, the industry hopes to get ahead of regulation. If the INL review finds the sensors are secure, it could help the industry argue against a blanket ban and push for a risk-based certification process instead. If vulnerabilities are found, the companies want to know early so they can pivot to alternative suppliers from the U.S., Europe, or Japan, including firms like Ouster, Luminar, and Innoviz.
In essence, the automakers are investing in clarity. They need a trusted, neutral verdict on whether the cost advantage of Chinese LiDAR is worth the potential cybersecurity and compliance risk.
What Happens Next for the AV Industry
The INL investigation is expected to conclude with a classified briefing for government agencies and an unclassified summary for industry partners later this year. Its conclusions could reshape the autonomous vehicle supply chain for the next decade.
If significant vulnerabilities are confirmed, the U.S. could move to add Chinese LiDAR to its covered technology list, effectively barring its use in new connected and autonomous vehicles sold domestically, and accelerating federal incentives to build a domestic LiDAR manufacturing base. If the sensors are found to be low-risk with proper mitigations, it could lead to new cybersecurity standards and testing requirements for all LiDAR, regardless of origin.
Either way, the era of treating LiDAR as a simple, plug-and-play component is over. As vehicles become rolling supercomputers, every sensor is now part of the nation's cybersecurity perimeter, and the INL review marks the first major step in securing it.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!