Technology

A U.S. National Lab Is Investigating Whether Chinese-Made Lidar Sensors Are a Security Risk

Martin HollowayPublished 6d ago6 min readBased on 1 source
Reading level
A U.S. National Lab Is Investigating Whether Chinese-Made Lidar Sensors Are a Security Risk
Photo by Abhishek Navlakha on Pexels

Idaho National Laboratory, a U.S. Department of Energy facility, is investigating whether Chinese-made lidar sensors could pose security vulnerabilities if widely deployed on American vehicles. The review is funded by a company or group of companies in the electric and autonomous vehicle industries, according to two people familiar with the effort who were granted anonymity to discuss it (TechCrunch).

Lidar, which stands for Light Detection and Ranging, uses pulsed laser beams to build detailed three-dimensional maps of a vehicle's surroundings in real time. It is a core sensor in most autonomous driving systems, feeding data into the software that makes driving decisions.

INL declined to comment. A spokesperson told TechCrunch in June and again in July that "this isn't a project that we're at liberty to discuss with reporters." Representatives for Rivian, General Motors, Ford, Kodiak, Lucid Motors, Nuro, and Uber told TechCrunch they were not aware of the review. Nvidia, Zoox, and Aurora did not respond to questions about whether they are involved. The two Chinese lidar suppliers most commonly named in the U.S. market, Hesai and RoboSense, did not respond to multiple requests for comment.

According to the two sources, the laboratory's effort is focused more narrowly on cybersecurity risks than on broader supply chain concerns, and may ultimately be aimed at giving Chinese-made lidar a clean bill of health in that domain. If the review concludes that the sensors are cybersecure, the finding could undercut legislative efforts to ban them. Conversely, it could surface specific vulnerabilities that accelerate those bans. The dual possibility makes the lab's eventual findings consequential regardless of which way they cut.

The review is underway as lawmakers craft multiple bills to ban Chinese lidar from American roads. Senator Tammy Baldwin (D-WI) is spearheading the Securing Infrastructure from Adversaries Act with Senator Ted Budd (R-NC). Baldwin told TechCrunch her primary concern is Chinese lidar being used for military or industrial espionage. Congressman John Moolenaar (R-MI), co-sponsoring separate legislation aimed at banning the sensors, told CNBC he is concerned that "back doors" could transmit information back to Chinese Communist interests.

The policy push and the lab review are running on parallel tracks but with potentially different endpoints. Legislation treats Chinese lidar as a category-level risk: the country of origin is the disqualifying factor, regardless of what a technical assessment finds. INL's review, by contrast, appears to be examining whether specific, demonstrable cybersecurity vulnerabilities exist in the hardware and software of these sensors. If the two efforts reach conflicting conclusions, the tension between a geopolitical risk framework and an evidence-based security assessment will be sharp.

Omer Keilaf, CEO and co-founder of Israeli lidar company Innoviz, said he was not aware of the INL review until TechCrunch asked him about it. Keilaf did frame the broader risk landscape. China's government, he noted, has deemed lidar a strategically important technology, which creates basic supply chain risk for automakers building autonomous driving systems on a Chinese supply chain. He also described a specific cybersecurity scenario: Chinese lidar sensors could be disabled en masse, disrupting vehicles in motion and disabling parked ones.

Keilaf's concern about mass disabling points to the kind of failure mode that matters most for fleet operators. A single compromised sensor is a contained incident. Coordinated disablement across a fleet of autonomous vehicles, whether in motion or parked, is a different class of event, and it maps onto threat models that cybersecurity professionals in the automotive sector have been building for several years. The question the INL review appears designed to answer is whether that threat model is theoretical or demonstrable in current hardware.

Lidar occupies a privileged position in the autonomous vehicle stack. The sensor generates high-resolution, three-dimensional point clouds of the vehicle's surroundings in real time, feeding perception pipelines that make driving decisions. If a lidar unit can be externally manipulated, whether to feed false data into the perception stack or to disable the sensor outright, the integrity of the entire autonomous driving system is in question. The attack surface is not just the sensor itself but its integration into the vehicle's compute architecture: data paths, firmware update mechanisms, and communication protocols between the lidar and the central processing unit.

The review also lands in a policy environment where the U.S. has already moved against Chinese technology in adjacent sectors. The pattern is familiar: telecom infrastructure, semiconductors, and connected vehicle components have each gone through cycles of scrutiny, restriction, and in some cases outright bans. Lidar is now moving through that same arc, with the INL review adding a technical assessment layer to what has so far been primarily a legislative and geopolitical conversation.

For the automakers and AV companies that may be funding the review, the calculus is practical. Chinese lidar units, particularly from Hesai and RoboSense, have competed aggressively on price and performance, and a number of U.S. and European automakers have integrated them into development programs and production plans. A clean cybersecurity bill of health from a DOE national laboratory would provide cover for continued use. A finding of serious vulnerabilities would force a supply chain pivot that, depending on the timeline, could delay production programs.

The absence of comment from so many parties, INL included, makes it difficult to assess the review's scope, timeline, or methodology. What is known is that a U.S. national laboratory with deep cybersecurity expertise is examining a specific technology category that Congress is simultaneously moving to ban, and that the effort is being paid for by industry participants with a direct commercial stake in the outcome. Those two facts, standing alone, are enough to make the eventual findings one of the more consequential technical assessments in the autonomous vehicle space.