{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:HAV22UYRN4KIILGKLSOQGRQQOY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a93b4d6ace5a99c500440cb0e7a411cd65e7d46369020629d3504e4caedb5f18","cross_cats_sorted":["cs.AI","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-25T15:23:19Z","title_canon_sha256":"17fd1a4bb0ee0b5f9d1445bb830d0e57455885be4bf7144b6a8f22807244f708"},"schema_version":"1.0","source":{"id":"1905.10615","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1905.10615","created_at":"2026-07-05T02:07:25Z"},{"alias_kind":"arxiv_version","alias_value":"1905.10615v3","created_at":"2026-07-05T02:07:25Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.10615","created_at":"2026-07-05T02:07:25Z"},{"alias_kind":"pith_short_12","alias_value":"HAV22UYRN4KI","created_at":"2026-07-05T02:07:25Z"},{"alias_kind":"pith_short_16","alias_value":"HAV22UYRN4KIILGK","created_at":"2026-07-05T02:07:25Z"},{"alias_kind":"pith_short_8","alias_value":"HAV22UYR","created_at":"2026-07-05T02:07:25Z"}],"graph_snapshots":[{"event_id":"sha256:941a8a4febca6c04de91681bc882d282e7ace7333bb389d282f3513f4fae6109","target":"graph","created_at":"2026-07-05T02:07:25Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/1905.10615/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Deep reinforcement learning (RL) policies are known to be vulnerable to adversarial perturbations to their observations, similar to adversarial examples for classifiers. However, an attacker is not usually able to directly modify another agent's observations. This might lead one to wonder: is it possible to attack an RL agent simply by choosing an adversarial policy acting in a multi-agent environment so as to create natural observations that are adversarial? We demonstrate the existence of adversarial policies in zero-sum games between simulated humanoid robots with proprioceptive observation","authors_text":"Adam Gleave, Cody Wild, Michael Dennis, Neel Kant, Sergey Levine, Stuart Russell","cross_cats":["cs.AI","cs.CR","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-25T15:23:19Z","title":"Adversarial Policies: Attacking Deep Reinforcement Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.10615","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d3a342563c314be3cd6b6e0e377afe4f341fee9958aae216674598b814197c8c","target":"record","created_at":"2026-07-05T02:07:25Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a93b4d6ace5a99c500440cb0e7a411cd65e7d46369020629d3504e4caedb5f18","cross_cats_sorted":["cs.AI","cs.CR","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-25T15:23:19Z","title_canon_sha256":"17fd1a4bb0ee0b5f9d1445bb830d0e57455885be4bf7144b6a8f22807244f708"},"schema_version":"1.0","source":{"id":"1905.10615","kind":"arxiv","version":3}},"canonical_sha256":"382bad53116f14842cca5c9d03461076054429c093ab72b1e2d91046b39fb8e1","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"382bad53116f14842cca5c9d03461076054429c093ab72b1e2d91046b39fb8e1","first_computed_at":"2026-07-05T02:07:25.878041Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T02:07:25.878041Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Uyrf+IW2y35L4+3HCo1VEBY3QP3NURDPBPB6HnopI00MG/fq4IajhRMeai46kACBDjXyRIj3EqamK2D/0faADw==","signature_status":"signed_v1","signed_at":"2026-07-05T02:07:25.878525Z","signed_message":"canonical_sha256_bytes"},"source_id":"1905.10615","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d3a342563c314be3cd6b6e0e377afe4f341fee9958aae216674598b814197c8c","sha256:941a8a4febca6c04de91681bc882d282e7ace7333bb389d282f3513f4fae6109"],"state_sha256":"10883047c645215c1ca8454e10265bb9aeba1d6de86ea7cd4a9b0efd69fc74b0"}