Vulnerability of Deep Reinforcement Learning to Policy Induction Attacks
Explore this paper's citation graph
Summary
This work establishes that reinforcement learning techniques based on Deep Q-Networks are also vulnerable to adversarial input perturbations, and presents a novel class of attacks based on this vulnerability that enable policy manipulation and induction in the learning process of DQNs.
- Type
- preprint
- Published
- 2017-01-16
- Cited by
- 312
- References
- 23
- Access
- Open access
- OpenAlex
- https://openalex.org/W2572659264
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:1562290
Keywords
Adversarial system, Reinforcement learning, Transferability, Computer science, Vulnerability (computing)
References
- Introduction to Reinforcement Learning
- Reinforcement learning is direct adaptive optimal control
- Intriguing properties of neural networks
- Playing Atari with Deep Reinforcement Learning
- Learning deep control policies for autonomous aerial vehicles with MPC-guided policy search
- A survey of inverse reinforcement learning techniques
- A Comprehensive Survey of Multiagent Reinforcement Learning
- Application and network performance of Amazon elastic compute cloud instances
- Human-level control through deep reinforcement learning
- An approach to tune fuzzy controllers based on reinforcement learning for autonomous vehicle control
- Gradient Descent for General Reinforcement Learning
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks
- The Limitations of Deep Learning in Adversarial Settings
- Beginning Game Development with Python and Pygame: From Novice to Professional
- TensorFlow: Large-Scale Machine Learning on Heterogeneous Distributed Systems
- Practical Black-Box Attacks against Deep Learning Systems using Adversarial Examples
- Towards Evaluating the Robustness of Neural Networks
- Defensive Distillation is Not Robust to Adversarial Examples
- Deep reinforcement learning for robotic manipulation with asynchronous off-policy updates
- Practical Black-Box Attacks against Machine Learning
Cited by
- SoK: Security and Privacy in Machine Learning
- Adversarial Attacks on Neural Network Policies
- The Space of Transferable Adversarial Examples
- Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong
- Certified Defenses for Data Poisoning Attacks
- Models and Framework for Adversarial Attacks on Complex Adaptive Systems
- How intelligent are convolutional neural networks?
- Detecting Adversarial Attacks on Neural Network Policies with Visual Foresight
- Adversarially Robust Policy Learning: Active construction of physically-plausible perturbations
- Whatever Does Not Kill Deep Reinforcement Learning, Makes It Stronger
- Audio Adversarial Examples: Targeted Attacks on Speech-to-Text
- Generalizable Data-Free Objective for Crafting Universal Adversarial Perturbations
- Adversary A3C for Robust Reinforcement Learning
- Verifying Controllers Against Adversarial Examples with Bayesian Optimization
- R3Net: Random Weights, Rectifier Linear Units and Robustness for Artificial Neural Network
- Built-in Vulnerabilities to Imperceptible Adversarial Perturbations
- A Survey of Adversarial Machine Learning in Cyber Warfare
- Explainable Learning: Implicit Generative Modelling during Training for Adversarial Robustness
- Security and Privacy Issues in Deep Learning
- Reinforcement Learning for Autonomous Defence in Software-Defined Networking