paper-with-me

홈 › Papers

SAJA: A State-Action Joint Attack Framework on Multi-Agent Deep Reinforcement Learning

2025-10-15 · Weiqi Guo, Guanjun Liu, Ziyuan Zhou arxiv

Multi-Agent Deep Reinforcement Learning (MADRL) has shown potential for cooperative and competitive tasks such as autonomous driving and strategic gaming. However, models trained by MADRL are vulnerable to adversarial perturbations on states and actions. Therefore, it is essential to investigate the robustness of MADRL models from an attack perspective. Existing studies focus on either state-only attacks or action-only attacks, but do not consider how to effectively joint them. Simply combining state and action perturbations such as randomly perturbing states and actions does not exploit their potential synergistic effects. In this paper, we propose the State-Action Joint Attack (SAJA) framework that has a good synergistic effects. SAJA consists of two important phases: (1) In the state attack phase, a multi-step gradient ascent method utilizes both the actor network and the critic network to compute an adversarial state, and (2) in the action attack phase, based on the perturbed state, a second gradient ascent uses the critic network to craft the final adversarial action. Additionally, a heuristic regularizer measuring the distance between the perturbed actions and the original clean ones is added into the loss function to enhance the effectiveness of the critic's guidance. We evaluate SAJA in the Multi-Agent Particle Environment (MPE), demonstrating that (1) it outperforms and is more stealthy than state-only or action-only attacks, and (2) existing state or action defense methods cannot defend its attacks.

📄 PDF Abstract BibTeX arXiv:2510.13262

Code (0)

등록된 구현이 없습니다.

Tasks

Reinforcement LearningAutonomous Driving

Similar Papers 제목 키워드 기반

A Study of Variable-Role-based Feature Enrichment in Neural Models of Code

2023-03-08 · Aftab Hussain, Md Rafiqul Islam Rabin, Bowen Xu, David Lo 외

Although deep neural models substantially reduce the overhead of feature engineering, the features readily available in the inputs might significantly impact training cost and the performance of the models. In this paper…

Feature Engineering

Joint Attribute and Model Generalization Learning for Privacy-Preserving Action Recognition

2023-09-21 · NeurIPS 2023 11

Privacy-Preserving Action Recognition (PPAR) aims to transform raw videos into anonymous ones to prevent privacy leakage while maintaining action clues, which is an increasingly important problem in intelligent vision ap…

SAJA at TRAC 2020 Shared Task: Transfer Learning for Aggressive Identification with XGBoost

2020-05-01 · LREC 2020 5 · Saja Tawalbeh, Mahmoud Hammad, Mohammad AL-Smadi

we have developed a system based on transfer learning technique depending on universal sentence encoder (USE) embedding that will be trained in our developed model using xgboost classifier to identify the aggressive text…

SentenceTransfer Learning

TLDR9+: A Large Scale Resource for Extreme Summarization of Social Media Posts

2021-10-04 · EMNLP (newsum) 2021 11 · Sajad Sotudeh, Hanieh Deilamsalehy, Franck Dernoncourt, Nazli Goharian

Recent models in developing summarization systems consist of millions of parameters and the model performance is highly dependent on the abundance of training data. While most existing summarization corpora contain data …

Extreme SummarizationSentence

Query Efficient Cross-Dataset Transferable Black-Box Attack on Action Recognition

2022-11-23 · Rohit Gupta, Naveed Akhtar, Gaurav Kumar Nayak, Ajmal Mian 외

Black-box adversarial attacks present a realistic threat to action recognition systems. Existing black-box attacks follow either a query-based approach where an attack is optimized by querying the target model, or a tran…

Action Recognition