Could some rebel make things like fake road bumps that lidars can't pick up, but humans can?

Protecting AI against spoofing attacks is a pretty active area of research right now.

Protecting neural networks from adversarial attacks, i think you mean. Protecting good A.I. from spoofing attacks is exactly the same as protecting human drivers from spoofing attacks.

Or the other way around - trick the lidar into thinking a road bump is there when there is no bump.

