Everyday mirrors can hijack the eyes of a self-driving car. A collaboration led by the University of Luxembourg’s SnT center, with CISPA and several partners, demonstrated the effect on a full Autoware-based autonomous stack, where reflections produced phantom obstacles and hid genuine ones.
Two failure modes emerged from the analysis. In one, multi-path reflections cause the LiDAR to see objects that do not exist. In the other, deflected beams make real objects vanish from the point cloud. Both propagated through the full perception, planning, and control pipeline, ending in emergency braking and pile-up style collisions.
The team found that a mirror of 0.18 square meters, purchasable for under $60, could trigger high-confidence false detections, with phantoms classified as vehicles in 74 percent of trials. They also produced physics-informed models that predict artifact position, point count, and appearance odds from distance, angle, and mirror area, then folded those models into a CARLA-based injection framework for real-time simulation.
Specular reflections are absent from most current simulators, so validation pipelines can ship vehicles that never encountered mirror scenarios. The authors concede that defending against physically legitimate but geometrically deceptive inputs remains unsolved.
Glass storefronts, truck bodies, and building facades make such surfaces common in cities, adding urgency as automated driving pushes into dense urban environments. The paper was presented at VehicleSec ’26 this week.