Query-based Targeted Action-Space Adversarial Policies on Deep Reinforcement Learning Agents

Advances in computing resources have resulted in the increasing complexity of\ncyber-physical systems (CPS). As the complexity of CPS evolved, the focus has\nshifted from traditional control methods to deep reinforcement learning-based\n(DRL) methods for control of these systems. This is due to the difficulty of\nobtaining accurate models of complex CPS for traditional control. However, to\nsecurely deploy DRL in production, it is essential to examine the weaknesses of\nDRL-based controllers (policies) towards malicious attacks from all angles. In\nthis work, we investigate targeted attacks in the action-space domain, also\ncommonly known as actuation attacks in CPS literature, which perturbs the\noutputs of a controller. We show that a query-based black-box attack model that\ngenerates optimal perturbations with respect to an adversarial goal can be\nformulated as another reinforcement learning problem. Thus, such an adversarial\npolicy can be trained using conventional DRL methods. Experimental results\nshowed that adversarial policies that only observe the nominal policy's output\ngenerate stronger attacks than adversarial policies that observe the nominal\npolicy's input and output. Further analysis reveals that nominal policies whose\noutputs are frequently at the boundaries of the action space are naturally more\nrobust towards adversarial policies. Lastly, we propose the use of adversarial\ntraining with transfer learning to induce robust behaviors into the nominal\npolicy, which decreases the rate of successful targeted attacks by 50%.\n

Paper

References (51)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC