Adversarial Manipulation of Learning in Linear-Quadratic Zero-Sum Differential Games via Cost Poisoning

Adversarial Manipulation of Learning in Linear-Quadratic Zero-Sum Differential Games via Cost Poisoning
复制标题

DOI:
10.1109/cns59707.2023.10288942
复制
发表时间:
2023-10
期刊:
2023 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Son Tung Do;Gabrielle Ebbrecht;Juntao Chen
Son Tung Do;Gabrielle Ebbrecht;Juntao Chen
中科院分区:
其他
文献类型:
--
作者:
Son Tung Do;Gabrielle Ebbrecht;Juntao Chen

文献摘要

相似文献

重要的是要研究对游戏的攻击,以深入了解控制系统漏洞,并更好地了解对手如何优化其恶意行为以逃避检测。学习游戏容易受到许多攻击,包括误导算法从不准确的数据中学习的欺骗性攻击。研究了一个线性二次(LQ)零和微分博弈中的策略中毒攻击,在这个博弈中,两个玩家从批量数据中学习他们的控制策略。作为一个对手,我们设计恶意的政策,以操纵成本测量的数据之前,玩家开始学习过程的目的是展示脆弱性的成本中毒攻击及其对受损系统的影响。中毒策略被制定为一个优化问题,其中包括一个约束的偏离原始批次数据的手段,以避免检测。我们利用案例研究,包括追捕-逃避游戏,进一步证明攻击的可行性和影响。
It is important to study attacks on games to gain insights into control system vulnerabilities and better understand how adversaries may optimize their malicious behavior to evade detection. Learning games are susceptible to a number of attacks, including deceptive attacks that misguide an algorithm to learn from inaccurate data. This work investigates policy poisoning attacks in a linear-quadratic (LQ) zero-sum differential game in which two players learn their control policies from batch data. Acting as an adversary, we design malicious policies to manipulate cost measurements in the data before players begin the learning process with the aim of demonstrating vulnerabilities to cost-poisoning attacks and their effects on compromised systems. The poisoning strategy is formulated as an optimization problem that includes a constraint on deviations from original batch data as a means to avoid detection. We leverage case studies, including a pursuit-evasion game, to further evidence attack feasibility and impacts.