Query-based Targeted Action-Space Adversarial Policies on Deep Reinforcement Learning Agents

被引:10
|
作者
Lee, Xian Yeow [1 ]
Esfandiari, Yasaman [1 ]
Tan, Kai Liang [1 ]
Sarkar, Soumik [1 ]
机构
[1] Iowa State Univ, Dept Mech Engn, Ames, IA 50011 USA
来源
ICCPS'21: PROCEEDINGS OF THE 2021 ACM/IEEE 12TH INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (WITH CPS-IOT WEEK 2021) | 2021年
关键词
Deep Reinforcement Learning; Adversarial Attacks; Black-box Attacks; Adversarial Policies; Adversarial Training;
D O I
10.1145/3450267.3450537
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advances in computing resources have resulted in the increasing complexity of cyber-physical systems (CPS). As the complexity of CPS evolved, the focus has shifted to deep reinforcement learning-based (DRL) methods for control of these systems. This is in part due to: 1) difficulty of obtaining accurate models of complex CPS for traditional control 2) DRL algorithms' capability of learning control policies from data which can be adapted and scaled to real, complex CPS. To securely deploy DRL in production, it is essential to examine the weaknesses of DRL-based controllers (policies) towards malicious attacks from all angles. This work investigates targeted attacks in the action-space domain (actuation attacks), which perturbs the outputs of a controller. We show that a black-box attack model that generates perturbations with respect to an adversarial goal can be formulated as another reinforcement learning problem. Thus, an adversarial policy can be trained using conventional DRL methods. Experimental results showed that adversarial policies which only observe the nominal policy's output generate stronger attacks than adversarial policies that observe the nominal policy's input and output. Further analysis revealed that nominal policies whose outputs are frequently at the boundaries of the action space are naturally more robust towards adversarial policies. Lastly, we propose the use of adversarial training with transfer learning to induce robust behaviors into the nominal policy, which decreases the rate of successful targeted attacks by approximately 50%.
引用
收藏
页码:87 / 97
页数:11
相关论文
共 50 条
  • [41] Deep reinforcement learning based planning method in state space for lunar rovers
    Gao, Ai
    Lu, Siyao
    Xu, Rui
    Li, Zhaoyu
    Wang, Bang
    Zhu, Shengying
    Gao, Yuhui
    Pan, Bo
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 127
  • [42] Hawkeye: Change-targeted Testing for Android Apps based on Deep Reinforcement Learning
    Peng, Chao
    Lv, Zhengwei
    Fu, Jiarong
    Liang, Jiayuan
    Zhang, Zhao
    Rajan, Ajitha
    Yang, Ping
    2024 ACM/IEEE 44TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: SOFTWARE ENGINEERING IN PRACTICE, ICSE-SEIP 2024, 2024, : 298 - 308
  • [43] Deep Reinforcement Learning-Based Routing for Space-Terrestrial Networks
    Tsai, Kai-Chu
    Yao, Ting-Jui
    Huang, Pin-Hao
    Huang, Cheng-Sen
    Han, Zhu
    Wang, Li-Chun
    2022 IEEE 96TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2022-FALL), 2022,
  • [44] Pursuit-evasion with Decentralized Robotic Swarm in Continuous State Space and Action Space via Deep Reinforcement Learning
    Singh, Gurpreet
    Lofaro, Daniel M.
    Sofge, Donald
    ICAART: PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AGENTS AND ARTIFICIAL INTELLIGENCE, VOL 1, 2020, : 226 - 233
  • [45] A Federated Learning and Deep Reinforcement Learning-Based Method with Two Types of Agents for Computation Offload
    Liu, Song
    Yang, Shiyuan
    Zhang, Hanze
    Wu, Weiguo
    SENSORS, 2023, 23 (04)
  • [46] ATS-O2A: A state-based adversarial attack strategy on deep reinforcement learning
    Li, Xiangjuan
    Li, Yang
    Feng, Zhaowen
    Wang, Zhaoxuan
    Pan, Quan
    COMPUTERS & SECURITY, 2023, 129
  • [47] Adversarial Attacks on Deep Reinforcement Learning-based Traffic Signal Control Systems with Colluding Vehicles
    Qu, Ao
    Tang, Yihong
    Ma, Wei
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2023, 14 (06)
  • [48] RADEAN: A Resource Allocation Model Based on Deep Reinforcement Learning and Generative Adversarial Networks in Edge Computing
    Yu, Zhaoyang
    Zhao, Sinong
    Su, Tongtong
    Liu, Wenwen
    Liu, Xiaoguang
    Wang, Gang
    Wang, Zehua
    Leung, Victor C. M.
    MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES, MOBIQUITOUS 2023, PT I, 2024, 593 : 257 - 277
  • [49] Efficient adversarial attacks detection for deep reinforcement learning-based autonomous planetary landing GNC
    Wang, Ziwei
    Aouf, Nabil
    ACTA ASTRONAUTICA, 2024, 224 : 37 - 47
  • [50] Hierarchical decision algorithm for air combat with hybrid action based on deep reinforcement learning
    Li, Zuolong
    Zhu, Jihong
    Kuang, Minchi
    Zhang, Jie
    Ren, Jie
    Hangkong Xuebao/Acta Aeronautica et Astronautica Sinica, 2024, 45 (17):