paper-with-me

홈 › Papers

Online Poisoning Attack Against Reinforcement Learning under Black-box Environments

2024-12-01 · Jianhui Li, Bokang Zhang, Junfeng Wu

This paper proposes an online environment poisoning algorithm tailored for reinforcement learning agents operating in a black-box setting, where an adversary deliberately manipulates training data to lead the agent toward a mischievous policy. In contrast to prior studies that primarily investigate white-box settings, we focus on a scenario characterized by \textit{unknown} environment dynamics to the attacker and a \textit{flexible} reinforcement learning algorithm employed by the targeted agent. We first propose an attack scheme that is capable of poisoning the reward functions and state transitions. The poisoning task is formalized as a constrained optimization problem, following the framework of \cite{ma2019policy}. Given the transition probabilities are unknown to the attacker in a black-box environment, we apply a stochastic gradient descent algorithm, where the exact gradients are approximated using sample-based estimates. A penalty-based method along with a bilevel reformulation is then employed to transform the problem into an unconstrained counterpart and to circumvent the double-sampling issue. The algorithm's effectiveness is validated through a maze environment.

📄 PDF Abstract BibTeX arXiv:2412.00797

Code (0)

등록된 구현이 없습니다.

Tasks

reinforcement-learningReinforcement Learning

Methods 이 논문이 사용한 방법론

Focus 설명 없음

Similar Papers 제목 키워드 기반

Black-Box Targeted Reward Poisoning Attack Against Online Deep Reinforcement Learning

2023-05-18 · Yinglun Xu, Gagandeep Singh

We propose the first black-box targeted attack against online deep reinforcement learning through reward poisoning during training time. Our attack is applicable to general environments with unknown dynamics learned by u…

Deep Reinforcement Learningreinforcement-learning

Efficient Adversarial Attacks on Online Multi-agent Reinforcement Learning

2023-07-15 · NeurIPS 2023 11

Due to the broad range of applications of multi-agent reinforcement learning (MARL), understanding the effects of adversarial attacks against MARL model is essential for the safe applications of this model. Motivated by …

Multi-agent Reinforcement Learningreinforcement-learningReinforcement Learning

Provably Efficient Black-Box Action Poisoning Attacks Against Reinforcement Learning

2021-10-09 · NeurIPS 2021 12 · Guanlin Liu, Lifeng Lai

Due to the broad range of applications of reinforcement learning (RL), understanding the effects of adversarial attacks against RL model is essential for the safe applications of this model. Prior theoretical works on ad…

reinforcement-learningReinforcement LearningReinforcement Learning (RL)

Practical Data Poisoning Attack against Next-Item Recommendation

2020-04-07 · Hengtong Zhang, Yaliang Li, Bolin Ding, Jing Gao

Online recommendation systems make use of a variety of information sources to provide users the items that users are potentially interested in. However, due to the openness of the online platform, recommendation systems …

Data PoisoningRecommendation SystemsReinforcement Learning

Lethean Attack: An Online Data Poisoning Technique

2020-11-24 · Eyal Perry

Data poisoning is an adversarial scenario where an attacker feeds a specially crafted sequence of samples to an online model in order to subvert learning. We introduce Lethean Attack, a novel data poisoning technique tha…

Data Poisoning