ACADIA: Efficient and Robust Adversarial Attacks Against Deep Reinforcement Learning

被引:3
|
作者
Ali, Haider [1 ]
Al Ameedi, Mohannad [1 ]
Swami, Ananthram [2 ]
Ning, Rui [3 ]
Li, Jiang [4 ]
Wu, Hongyi [5 ]
Cho, Jin-Hee [1 ]
机构
[1] Virginia Tech, Comp Sci, Blacksburg, VA 24061 USA
[2] Army Res Lab, Adelphi, MD USA
[3] Old Dominion Univ, Comp Sci, Norfolk, VA 23529 USA
[4] Old Dominion Univ, Elect Engn, Norfolk, VA 23529 USA
[5] Univ Arizona, Elect & Comp Engn, Tucson, AZ 85721 USA
基金
美国国家科学基金会;
关键词
Deep reinforcement learning; adversarial attacks; Deep-Q learning Network; Proximal Policy Optimization;
D O I
10.1109/CNS56114.2022.9947234
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Existing adversarial algorithms for Deep Reinforcement Learning (DRL) have largely focused on identifying an optimal time to attack a DRL agent. However, little work has been explored in injecting efficient adversarial perturbations in DRL environments. We propose a suite of novel DRL adversarial attacks, called ACADIA, representing AttaCks Against Deep reInforcement leArning. ACADIA provides a set of efficient and robust perturbation-based adversarial attacks to disturb the DRL agent's decision-making based on novel combinations of techniques utilizing momentum, ADAM optimizer (i.e., Root Mean Square Propagation, or RMSProp), and initial randomization. These kinds of DRL attacks with novel integration of such techniques have not been studied in the existing Deep Neural Networks (DNNs) and DRL research. We consider two well-known DRL algorithms, Deep-Q Learning Network (DQN) and Proximal Policy Optimization (PPO), under Atari games and MuJoCo where both targeted and non-targeted attacks are considered with or without the state-of-the-art defenses in DRL (i.e., RADIAL and ATLA). Our results demonstrate that the proposed ACADIA outperforms existing gradient-based counterparts under a wide range of experimental settings. ACADIA is nine times faster than the state-of-the-art Carlini & Wagner (CW) method with better performance under defenses of DRL.
引用
收藏
页码:1 / 9
页数:9
相关论文
共 50 条
  • [1] Stealthy and Efficient Adversarial Attacks against Deep Reinforcement Learning
    Sun, Jianwen
    Zhang, Tianwei
    Xie, Xiaofei
    Ma, Lei
    Zheng, Yan
    Chen, Kangjie
    Liu, Yang
    [J]. THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 5883 - 5891
  • [2] Robust Deep Reinforcement Learning with Adversarial Attacks Extended Abstract
    Pattanaik, Anay
    Tang, Zhenyi
    Liu, Shuijing
    Bommannan, Gautham
    Chowdhary, Girish
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS AND MULTIAGENT SYSTEMS (AAMAS' 18), 2018, : 2040 - 2042
  • [3] Deep Reinforcement Adversarial Learning Against Botnet Evasion Attacks
    Apruzzese, Giovanni
    Andreolini, Mauro
    Marchetti, Mirco
    Venturi, Andrea
    Colajanni, Michele
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (04): : 1975 - 1987
  • [4] Robust Deep Reinforcement Learning against Adversarial Perturbations on State Observations
    Zhang, Huan
    Chen, Hongge
    Xiao, Chaowei
    Li, Bo
    Liu, Mingyan
    Boning, Duane
    Hsieh, Cho-Jui
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [5] Enhanced Adversarial Strategically-Timed Attacks Against Deep Reinforcement Learning
    Yang, Chao-Han Huck
    Qi, Jun
    Chen, Pin-Yu
    Ouyang, Yi
    Hung, I-Te Danny
    Lee, Chin-Hui
    Ma, Xiaoli
    [J]. ICASSP, IEEE International Conference on Acoustics, Speech and Signal Processing - Proceedings, 2020, 2020-May : 3407 - 3411
  • [6] Instance-based defense against adversarial attacks in Deep Reinforcement Learning
    Garcia, Javier
    Sagredo, Ismael
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 107
  • [7] Forming Adversarial Example Attacks Against Deep Neural Networks With Reinforcement Learning
    Akers, Matthew
    Barton, Armon
    [J]. COMPUTER, 2024, 57 (01) : 88 - 99
  • [8] Defense Strategies Against Adversarial Jamming Attacks via Deep Reinforcement Learning
    Wang, Feng
    Zhong, Chen
    Gursoy, M. Cenk
    Velipasalar, Senem
    [J]. 2020 54TH ANNUAL CONFERENCE ON INFORMATION SCIENCES AND SYSTEMS (CISS), 2020, : 336 - 341
  • [9] ENHANCED ADVERSARIAL STRATEGICALLY-TIMED ATTACKS AGAINST DEEP REINFORCEMENT LEARNING
    Yang, Chao-Han Huck
    Qi, Jun
    Chen, Pin-Yu
    Ouyang, Yi
    Hung, I-Te Danny
    Lee, Chin-Hui
    Ma, Xiaoli
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 3407 - 3411
  • [10] Robust Deep Reinforcement Learning Based Network Slicing under Adversarial Jamming Attacks
    Wang, Feng
    Gursoy, M. Cenk
    Velipasalar, Senem
    Sagduyu, Yalin E.
    [J]. 2022 IEEE 33RD ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS (IEEE PIMRC), 2022, : 752 - 757