Black-box Targeted Reward Poisoning Attack Against Online Deep Reinforcement Learning
2023 Β· Yinglun Xu, Gagandeep Singh
Abstract
We propose the first black-box targeted attack against online deep reinforcement learning through reward poisoning during training time. Our attack is applicable to general environments with unknown dynamics learned by unknown algorithms and requires limited attack budgets and computational resources. We leverage a general framework and find conditions to ensure efficient attack under a general assumption of the learning algorithms. We show that our attack is optimal in our framework under the conditions. We experimentally verify that with limited budgets, our attack efficiently leads the learning agent to various target policies under a diverse set of popular DRL environments and state-of-the-art learners.
Authors
(none)
Tags
Stats
Related papers
- Efficient Reward Poisoning Attacks On Online Deep Reinforcement Learning (2022)0.00
- Online Poisoning Attack Against Reinforcement Learning Under Black-box Environments (2024)0.00
- Reward Poisoning In Reinforcement Learning: Attacks Against Unknown Learners In Unknown Environments (2021)0.00
- Universal Black-box Reward Poisoning Attack Against Offline Reinforcement Learning (2024)0.00
- Policy Teaching In Reinforcement Learning Via Environment Poisoning Attacks (2020)0.00
- Vulnerability-aware Poisoning Mechanism For Online RL With Unknown Dynamics (2020)0.00
- Reward Poisoning Attacks On Offline Multi-agent Reinforcement Learning (2022)0.00
- Execute Order 66: Targeted Data Poisoning For Reinforcement Learning (2022)0.00