arrow
Return

Clustering-based attack detection for adversarial reinforcement learning

delete2024-02-06
delete1
delete
OA
AI
R
Rubén Majadas *
J
Javier García
F
Fernando Fernández
DOI:10.1007/s10489-024-05275-7delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Detecting malicious attacks presents a major challenge in the field of reinforcement learning (RL), as such attacks can force the victim to perform abnormal actions, with potentially severe consequences. To mitigate these risks, current research focuses on the enhancement of RL algorithms with efficient detection mechanisms, especially for real-world applications. Adversarial attacks have the potential to alter the environmental dynamics of a Markov Decision Process (MDP) perceived by an RL agent. Leveraging these changes in dynamics, we propose a novel approach to detect attacks. Our contribution can be summarized in two main aspects. Firstly, we propose a novel formalization of the attack detection problem that entails analyzing modifications made by attacks to the transition and reward dynamics within the environment. This problem can be framed as a context change detection problem, where the goal is to identify the transition from a free-of-attack situation to an under-attack scenario. To solve this problem, we propose a groundbreaking model-free clustering-based countermeasure. This approach consists of two essential steps: first, partitioning the transition space into clusters, and then using this partitioning to identify changes in environmental dynamics caused by adversarial attacks. To assess the efficiency of our detection method, we performed experiments on four established RL domains (grid-world, mountain car, carpole, and acrobot) and subjected them to four advanced attack types. Uniform, Strategically-timed, Q-value, and Multi-objective. Our study proves that our technique has a high potential for perturbation detection, even in scenarios where attackers employ more sophisticated strategies.
Keywords:
Adversarial reinforcement learning
Adversarial attacks
Change-point detection
Clustering applications

Journal

Applied Intelligence cover
Applied Intelligence
IF:
3.5
Papers:
7.6K
Citations:
1.7W

Organization

U
Universidad Carlos III de Madrid
Scholars:
5.5K
Papers: 5.7K
Citations: 4.5K
U
Universidade de Santiago de Compostela
Scholars:
1.5W
Papers: 1.3W
Citations: 1.4W
Cited Papers

Cited Papers

Distributed Services Attestation in IoT
err2018-11-30
err0
PREAI
errMauro Conti; Edlira Dushku; Luigi V. Mancini
errShare
errSave
Copper-doped silica cuprous sulfate (CDSCS) as a highly efficient and new heterogeneous nano catalyst for [3+2] Huisgen cycloaddition
err2012-09-01
err0
PREAI
errMohammad Navid Soltani Rad; Somayeh Behrouz; Mohammad Mahdi Doroodmand; Abdollah Movahediyan
errShare
errSave
Structure and dynamics in the three crystal phases of 1,1′,2,2′-tetrachloroferrocene
err1983-01-01
err0
PREAI
errMervyn F. Daniel; Alan J. Leadbetter; Mahommed A. Mazid; Jennifer Piper
errShare
errSave
Organometallic sol/gel chemistry of metal sulfides
err1990-05-01
err0
PREAI
errT.A. Guiton; C.L. Czekaj; C.G. Pantano
errShare
errSave
researcher View more