Pith. sign in

REVIEW 1 cited by

Black-Box Targeted Reward Poisoning Attack Against Online Deep Reinforcement Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2305.10681 v1 pith:6HXSIU2X submitted 2023-05-18 cs.LG cs.CR

classification cs.LGcs.CR
keywords attacklearninggeneralunderalgorithmsblack-boxbudgetsconditions
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We propose the first black-box targeted attack against online deep reinforcement learning through reward poisoning during training time. Our attack is applicable to general environments with unknown dynamics learned by unknown algorithms and requires limited attack budgets and computational resources. We leverage a general framework and find conditions to ensure efficient attack under a general assumption of the learning algorithms. We show that our attack is optimal in our framework under the conditions. We experimentally verify that with limited budgets, our attack efficiently leads the learning agent to various target policies under a diverse set of popular DRL environments and state-of-the-art learners.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Online Poisoning Attack Against Reinforcement Learning under Black-box Environments

    cs.LG 2024-12 conditional novelty 6.0 of 10

    An online attacker knowing only which states are reachable can poison rewards and transitions to make a Q-learning agent follow a target policy in a maze.

Pith tools