Query-based Targeted Action-Space Adversarial Policies on Deep Reinforcement Learning Agents

被引:10
|
作者
Lee, Xian Yeow [1 ]
Esfandiari, Yasaman [1 ]
Tan, Kai Liang [1 ]
Sarkar, Soumik [1 ]
机构
[1] Iowa State Univ, Dept Mech Engn, Ames, IA 50011 USA
来源
ICCPS'21: PROCEEDINGS OF THE 2021 ACM/IEEE 12TH INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (WITH CPS-IOT WEEK 2021) | 2021年
关键词
Deep Reinforcement Learning; Adversarial Attacks; Black-box Attacks; Adversarial Policies; Adversarial Training;
D O I
10.1145/3450267.3450537
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advances in computing resources have resulted in the increasing complexity of cyber-physical systems (CPS). As the complexity of CPS evolved, the focus has shifted to deep reinforcement learning-based (DRL) methods for control of these systems. This is in part due to: 1) difficulty of obtaining accurate models of complex CPS for traditional control 2) DRL algorithms' capability of learning control policies from data which can be adapted and scaled to real, complex CPS. To securely deploy DRL in production, it is essential to examine the weaknesses of DRL-based controllers (policies) towards malicious attacks from all angles. This work investigates targeted attacks in the action-space domain (actuation attacks), which perturbs the outputs of a controller. We show that a black-box attack model that generates perturbations with respect to an adversarial goal can be formulated as another reinforcement learning problem. Thus, an adversarial policy can be trained using conventional DRL methods. Experimental results showed that adversarial policies which only observe the nominal policy's output generate stronger attacks than adversarial policies that observe the nominal policy's input and output. Further analysis revealed that nominal policies whose outputs are frequently at the boundaries of the action space are naturally more robust towards adversarial policies. Lastly, we propose the use of adversarial training with transfer learning to induce robust behaviors into the nominal policy, which decreases the rate of successful targeted attacks by approximately 50%.
引用
收藏
页码:87 / 97
页数:11
相关论文
共 50 条
  • [31] Impedance Control of Space Manipulator Based on Deep Reinforcement Learning
    Sun, Yu
    Cao, Heyang
    Ma, Rui
    Wang, Guan
    Ma, Guangcheng
    Xia, Hongwei
    2022 41ST CHINESE CONTROL CONFERENCE (CCC), 2022, : 3609 - 3614
  • [32] Visual Explanation With Action Query Transformer in Deep Reinforcement Learning and Visual Feedback via Augmented Reality
    Itaya, Hidenori
    Yin, Wantao
    Hirakawa, Tsubasa
    Yamashita, Takayoshi
    Fujiyoshi, Hironobu
    Sugiura, Komei
    IEEE ACCESS, 2025, 13 : 56338 - 56354
  • [33] Adversarial Attacks and Defense in Deep Reinforcement Learning (DRL)-Based Traffic Signal Controllers
    Haydari, Ammar
    Zhang, Michael
    Chuah, Chen-Nee
    IEEE OPEN JOURNAL OF INTELLIGENT TRANSPORTATION SYSTEMS, 2021, 2 : 402 - 416
  • [34] A Further Exploration of Deep Multi-Agent Reinforcement Learning with Hybrid Action Space
    Hua, Hongzhi
    Zhao, Ruiwei
    Wen, Guixuan
    Wu, Kaigui
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2023, PT VI, 2023, 14259 : 1 - 12
  • [35] Goal-Oriented Obstacle Avoidance with Deep Reinforcement Learning in Continuous Action Space
    Cimurs, Reinis
    Lee, Jin Han
    Suh, Il Hong
    ELECTRONICS, 2020, 9 (03)
  • [36] Robust Deep Reinforcement Learning Based Network Slicing under Adversarial Jamming Attacks
    Wang, Feng
    Gursoy, M. Cenk
    Velipasalar, Senem
    Sagduyu, Yalin E.
    2022 IEEE 33RD ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS (IEEE PIMRC), 2022, : 752 - 757
  • [37] Reinforcement and deep reinforcement learning-based solutions for machine maintenance planning, scheduling policies, and optimization
    Ogunfowora, Oluwaseyi
    Najjaran, Homayoun
    JOURNAL OF MANUFACTURING SYSTEMS, 2023, 70 : 244 - 263
  • [38] Deep Adversarial Reinforcement Learning Method to Generate Control Policies Robust Against Worst-Case Value Predictions
    Ohashi, Kohei
    Nakanishi, Kosuke
    Yasui, Yuji
    Ishii, Shin
    IEEE ACCESS, 2023, 11 : 100798 - 100809
  • [39] Robust Adversarial Attacks Detection Based on Explainable Deep Reinforcement Learning for UAV Guidance and Planning
    Hickling T.
    Aouf N.
    Spencer P.
    IEEE Transactions on Intelligent Vehicles, 2023, 8 (10): : 4381 - 4394
  • [40] Deep Reinforcement Learning Based Mobility Load Balancing Under Multiple Behavior Policies
    Xu, Yue
    Xu, Wenjun
    Wang, Zhi
    Lin, Jiaru
    Cui, Shuguang
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,