{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:YUYWCIA6ZJMFXQWSO4ZR2FYVBC","short_pith_number":"pith:YUYWCIA6","schema_version":"1.0","canonical_sha256":"c53161201eca585bc2d277331d171508bdd2b2f0718e21981b2181e99bff33df","source":{"kind":"arxiv","id":"2301.12595","version":1},"attestation_state":"computed","paper":{"title":"Adversarial Attacks on Adversarial Bandits","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Yuzhe Ma, Zhijin Zhou","submitted_at":"2023-01-30T00:51:39Z","abstract_excerpt":"We study a security threat to adversarial multi-armed bandits, in which an attacker perturbs the loss or reward signal to control the behavior of the victim bandit player. We show that the attacker is able to mislead any no-regret adversarial bandit algorithm into selecting a suboptimal target arm in every but sublinear (T-o(T)) number of rounds, while incurring only sublinear (o(T)) cumulative attack cost. This result implies critical security concern in real-world bandit-based systems, e.g., in online recommendation, an attacker might be able to hijack the recommender system and promote a de"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2301.12595","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2023-01-30T00:51:39Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"454b7a3ee2be1f769e5710cdab046763bb546b2d088c67dc5a4ed2da6fb0b610","abstract_canon_sha256":"d5a6e9adda3561bbd1365db756fbf836e718a6a0a6c64a46c317d5c9e95ae40e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:36:55.620154Z","signature_b64":"a6zdHf+tGOf2NaNtqQjuet4u07DI4O7SeLMJVteGJnUZkRosoW7KYU0eswAgYQnnY3wJ/O5CP34BgIuKCwh+AQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c53161201eca585bc2d277331d171508bdd2b2f0718e21981b2181e99bff33df","last_reissued_at":"2026-07-05T05:36:55.619667Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:36:55.619667Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Attacks on Adversarial Bandits","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Yuzhe Ma, Zhijin Zhou","submitted_at":"2023-01-30T00:51:39Z","abstract_excerpt":"We study a security threat to adversarial multi-armed bandits, in which an attacker perturbs the loss or reward signal to control the behavior of the victim bandit player. We show that the attacker is able to mislead any no-regret adversarial bandit algorithm into selecting a suboptimal target arm in every but sublinear (T-o(T)) number of rounds, while incurring only sublinear (o(T)) cumulative attack cost. This result implies critical security concern in real-world bandit-based systems, e.g., in online recommendation, an attacker might be able to hijack the recommender system and promote a de"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2301.12595","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2301.12595/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2301.12595","created_at":"2026-07-05T05:36:55.619726+00:00"},{"alias_kind":"arxiv_version","alias_value":"2301.12595v1","created_at":"2026-07-05T05:36:55.619726+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2301.12595","created_at":"2026-07-05T05:36:55.619726+00:00"},{"alias_kind":"pith_short_12","alias_value":"YUYWCIA6ZJMF","created_at":"2026-07-05T05:36:55.619726+00:00"},{"alias_kind":"pith_short_16","alias_value":"YUYWCIA6ZJMFXQWS","created_at":"2026-07-05T05:36:55.619726+00:00"},{"alias_kind":"pith_short_8","alias_value":"YUYWCIA6","created_at":"2026-07-05T05:36:55.619726+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2505.21938","citing_title":"Practical Adversarial Attacks on Stochastic Bandits via Fake Data Injection","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2605.02495","citing_title":"Efficient Preference Poisoning Attack on Offline RLHF","ref_index":2,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC","json":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC.json","graph_json":"https://pith.science/api/pith-number/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/graph.json","events_json":"https://pith.science/api/pith-number/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/events.json","paper":"https://pith.science/paper/YUYWCIA6"},"agent_actions":{"view_html":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC","download_json":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC.json","view_paper":"https://pith.science/paper/YUYWCIA6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2301.12595&json=true","fetch_graph":"https://pith.science/api/pith-number/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/graph.json","fetch_events":"https://pith.science/api/pith-number/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/action/storage_attestation","attest_author":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/action/author_attestation","sign_citation":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/action/citation_signature","submit_replication":"https://pith.science/pith/YUYWCIA6ZJMFXQWSO4ZR2FYVBC/action/replication_record"}},"created_at":"2026-07-05T05:36:55.619726+00:00","updated_at":"2026-07-05T05:36:55.619726+00:00"}