Pith. sign in

REVIEW 1 cited by

Reward Poisoning Attacks on Offline Multi-Agent Reinforcement Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2206.01888 v4 pith:ESJIFUTX submitted 2022-06-04 cs.LG cs.AIcs.CRcs.GT

classification cs.LGcs.AIcs.CRcs.GT
keywords agentsattackattacksattackerdatasetmarlofflinelearning
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

In offline multi-agent reinforcement learning (MARL), agents estimate policies from a given dataset. We study reward-poisoning attacks in this setting where an exogenous attacker modifies the rewards in the dataset before the agents see the dataset. The attacker wants to guide each agent into a nefarious target policy while minimizing the $L^p$ norm of the reward modification. Unlike attacks on single-agent RL, we show that the attacker can install the target policy as a Markov Perfect Dominant Strategy Equilibrium (MPDSE), which rational agents are guaranteed to follow. This attack can be significantly cheaper than separate single-agent attacks. We show that the attack works on various MARL agents including uncertainty-aware learners, and we exhibit linear programs to efficiently solve the attack problem. We also study the relationship between the structure of the datasets and the minimal attack cost. Our work paves the way for studying defense in offline MARL.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Provably Efficient Action-Manipulation Attack Against Continuous Reinforcement Learning

    cs.LG 2024-11 reject novelty 7.0 of 10

    LCBT is a trajectory-only tree-search attack that claims to steer continuous-action RL agents to target policies with sublinear attack cost, but the proof of the claim has a serious importance-sampling flaw.

Pith tools