{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:6HXSIU2XNDDAHKTHHVWYOO46UJ","short_pith_number":"pith:6HXSIU2X","schema_version":"1.0","canonical_sha256":"f1ef24535768c603aa673d6d873b9ea26436910b5932abc26402bf3992510f91","source":{"kind":"arxiv","id":"2305.10681","version":1},"attestation_state":"computed","paper":{"title":"Black-Box Targeted Reward Poisoning Attack Against Online Deep Reinforcement Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Gagandeep Singh, Yinglun Xu","submitted_at":"2023-05-18T03:37:29Z","abstract_excerpt":"We propose the first black-box targeted attack against online deep reinforcement learning through reward poisoning during training time. Our attack is applicable to general environments with unknown dynamics learned by unknown algorithms and requires limited attack budgets and computational resources. We leverage a general framework and find conditions to ensure efficient attack under a general assumption of the learning algorithms. We show that our attack is optimal in our framework under the conditions. We experimentally verify that with limited budgets, our attack efficiently leads the lear"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2305.10681","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-05-18T03:37:29Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"7cabff1d39c98413225a8a15eedf625a1013d829bcbe7b8d69db201a15daa8ed","abstract_canon_sha256":"eac3bfeb47c9fcb20551ea6502324732d956aa509b2074c79aafc362a82b5ea3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:11:25.325730Z","signature_b64":"ZY8LhGWruxmvvdqDNu4K5fa2+5PZgE4iiTtghhhfQHQoc373zCSPREZ7Uj42IcJGzmk9Rk9bwRehZNSVkQC/BQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f1ef24535768c603aa673d6d873b9ea26436910b5932abc26402bf3992510f91","last_reissued_at":"2026-07-05T06:11:25.325285Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:11:25.325285Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Black-Box Targeted Reward Poisoning Attack Against Online Deep Reinforcement Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Gagandeep Singh, Yinglun Xu","submitted_at":"2023-05-18T03:37:29Z","abstract_excerpt":"We propose the first black-box targeted attack against online deep reinforcement learning through reward poisoning during training time. Our attack is applicable to general environments with unknown dynamics learned by unknown algorithms and requires limited attack budgets and computational resources. We leverage a general framework and find conditions to ensure efficient attack under a general assumption of the learning algorithms. We show that our attack is optimal in our framework under the conditions. We experimentally verify that with limited budgets, our attack efficiently leads the lear"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2305.10681","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2305.10681/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2305.10681","created_at":"2026-07-05T06:11:25.325350+00:00"},{"alias_kind":"arxiv_version","alias_value":"2305.10681v1","created_at":"2026-07-05T06:11:25.325350+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.10681","created_at":"2026-07-05T06:11:25.325350+00:00"},{"alias_kind":"pith_short_12","alias_value":"6HXSIU2XNDDA","created_at":"2026-07-05T06:11:25.325350+00:00"},{"alias_kind":"pith_short_16","alias_value":"6HXSIU2XNDDAHKTH","created_at":"2026-07-05T06:11:25.325350+00:00"},{"alias_kind":"pith_short_8","alias_value":"6HXSIU2X","created_at":"2026-07-05T06:11:25.325350+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.20037","citing_title":"When Critics Disagree: Adaptive Reward Poisoning Attacks in RIS-Aided Wireless Control System","ref_index":26,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ","json":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ.json","graph_json":"https://pith.science/api/pith-number/6HXSIU2XNDDAHKTHHVWYOO46UJ/graph.json","events_json":"https://pith.science/api/pith-number/6HXSIU2XNDDAHKTHHVWYOO46UJ/events.json","paper":"https://pith.science/paper/6HXSIU2X"},"agent_actions":{"view_html":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ","download_json":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ.json","view_paper":"https://pith.science/paper/6HXSIU2X","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2305.10681&json=true","fetch_graph":"https://pith.science/api/pith-number/6HXSIU2XNDDAHKTHHVWYOO46UJ/graph.json","fetch_events":"https://pith.science/api/pith-number/6HXSIU2XNDDAHKTHHVWYOO46UJ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ/action/storage_attestation","attest_author":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ/action/author_attestation","sign_citation":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ/action/citation_signature","submit_replication":"https://pith.science/pith/6HXSIU2XNDDAHKTHHVWYOO46UJ/action/replication_record"}},"created_at":"2026-07-05T06:11:25.325350+00:00","updated_at":"2026-07-05T06:11:25.325350+00:00"}