Adversarial Manipulation of Learning in Linear-Quadratic Zero-Sum Differential Games via Cost Poisoning
Adversarial Manipulation of Learning in Linear-Quadratic Zero-Sum Differential Games via Cost Poisoning
复制标题
DOI:
10.1109/cns59707.2023.10288942
复制
发表时间:
2023-10
期刊:
影响因子:
--
通讯作者:
Son Tung Do;Gabrielle Ebbrecht;Juntao Chen
中科院分区:
文献类型:
--
作者:
Son Tung Do;Gabrielle Ebbrecht;Juntao Chen
It is important to study attacks on games to gain insights into control system vulnerabilities and better understand how adversaries may optimize their malicious behavior to evade detection. Learning games are susceptible to a number of attacks, including deceptive attacks that misguide an algorithm to learn from inaccurate data. This work investigates policy poisoning attacks in a linear-quadratic (LQ) zero-sum differential game in which two players learn their control policies from batch data. Acting as an adversary, we design malicious policies to manipulate cost measurements in the data before players begin the learning process with the aim of demonstrating vulnerabilities to cost-poisoning attacks and their effects on compromised systems. The poisoning strategy is formulated as an optimization problem that includes a constraint on deviations from original batch data as a means to avoid detection. We leverage case studies, including a pursuit-evasion game, to further evidence attack feasibility and impacts.