Vehicle-to-everything systems promise to let cars share what their sensors see, but a VehicleSec 2026 lightning talk argues that collaboration itself is becoming an attack surface.
Qingzhao Zhang of the University of Arizona presented the talk, which examines how cooperative perception systems expand the ground an attacker can stand on. In collaborative perception, connected vehicles fuse camera, radar, and LiDAR data from nearby cars to see beyond line of sight. The benefit is real: vehicles gain awareness of hazards hidden around corners. The risk is that the shared data pipeline becomes a single point of deception.
Prior research in this area has shown that an attacker who compromises one participant, or injects spoofed perception messages into the exchange, can poison what an entire group of vehicles believes about the road ahead. Detections from a trusted-looking peer can override a vehicle’s own observations, and fabricated objects, phantom braking events, or masked obstacles can propagate through the network before any single car can verify them.
Zhang’s talk mapped why these threats evolve as cooperative systems move from research to deployment, and why the integrity of shared sensor data needs the same attention as the encryption protecting the channel.
Standard V2X security today focuses on authenticating senders. The harder problem is authenticating what a sender claims to have seen, and that question becomes critical as automakers begin shipping cooperative perception features.