Blackbox Attacks on Reinforcement Learning Agents Using Approximated Temporal Information
Blackbox Attacks on Reinforcement Learning Agents Using Approximated Temporal Information
复制标题
使用近似时间信息对强化学习代理进行黑盒攻击
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Ross Anderson
中科院分区:
文献类型:
--
作者:
Yiren Zhao;Ilia Shumailov;Han Cui;Xitong Gao;R. Mullins;Ross Anderson
Recent research on reinforcement learning (RL) has suggested that trained agents are vulnerable to maliciously-crafted adversarial samples. In this work, we show how such samples can be generalised from White-box and Grey-box attacks to a strong Black-box case, where the attacker has no knowledge of the agents, their training parameters or their training methods. We use sequence-to-sequence models to predict a single action or a sequence of future actions that a trained agent will make. First, we show that our approximation model, based on time-series information from the agent, consistently predicts RL agents’ future actions with high accuracy in a Black-box setup on a wide range of games and RL algorithms. Second, we find that although adversarial samples are transferable from the sequence-to-sequence model to our RL agents, they often outperform Random Gaussian Noise only marginally. Third, we propose a novel use for adversarial samples in Black-box attacks of RL agents: they can be used to trigger a trained agent to misbehave after a specific time delay. This potentially enables an attacker to use devices controlled by RL agents as time bombs.
影响因子:
12
作者:
Andrew Bagnell;March
通讯作者:
Andrew Bagnell;March
影响因子:
11.2
作者:
Pereira, Andre Luis S.;do Nascirnento, Diego M.;Rosa, Morsyleide de F.
通讯作者:
Rosa, Morsyleide de F.