{"id":"https://openalex.org/W3163651025","doi":"https://doi.org/10.1109/isr50024.2021.9419509","title":"Adversarial Black-Box Attacks on Vision-based Deep Reinforcement Learning Agents","display_name":"Adversarial Black-Box Attacks on Vision-based Deep Reinforcement Learning Agents","publication_year":2021,"publication_date":"2021-03-04","ids":{"openalex":"https://openalex.org/W3163651025","doi":"https://doi.org/10.1109/isr50024.2021.9419509","mag":"3163651025"},"language":"en","primary_location":{"id":"doi:10.1109/isr50024.2021.9419509","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isr50024.2021.9419509","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Conference on Intelligence and Safety for Robotics (ISR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5020895774","display_name":"Atanas Tanev","orcid":null},"institutions":[{"id":"https://openalex.org/I143379178","display_name":"FZI Research Center for Information Technology","ror":"https://ror.org/04kdh6x72","country_code":"DE","type":"nonprofit","lineage":["https://openalex.org/I143379178"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Atanas Tanev","raw_affiliation_strings":["FZI Research Center for Information Technology, Karslruhe, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"FZI Research Center for Information Technology, Karslruhe, Germany","institution_ids":["https://openalex.org/I143379178"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028458518","display_name":"Svetlana Pavlitskaya","orcid":null},"institutions":[{"id":"https://openalex.org/I143379178","display_name":"FZI Research Center for Information Technology","ror":"https://ror.org/04kdh6x72","country_code":"DE","type":"nonprofit","lineage":["https://openalex.org/I143379178"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Svetlana Pavlitskaya","raw_affiliation_strings":["FZI Research Center for Information Technology, Karslruhe, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"FZI Research Center for Information Technology, Karslruhe, Germany","institution_ids":["https://openalex.org/I143379178"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079287881","display_name":"Joan Sigloch","orcid":null},"institutions":[{"id":"https://openalex.org/I102335020","display_name":"Karlsruhe Institute of Technology","ror":"https://ror.org/04t3en479","country_code":"DE","type":"education","lineage":["https://openalex.org/I102335020","https://openalex.org/I1305996414"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Joan Sigloch","raw_affiliation_strings":["Karlsruhe Institute of Technology (KIT), Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Karlsruhe Institute of Technology (KIT), Germany","institution_ids":["https://openalex.org/I102335020"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072884786","display_name":"Arne Roennau","orcid":"https://orcid.org/0000-0002-6090-607X"},"institutions":[{"id":"https://openalex.org/I143379178","display_name":"FZI Research Center for Information Technology","ror":"https://ror.org/04kdh6x72","country_code":"DE","type":"nonprofit","lineage":["https://openalex.org/I143379178"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Arne Roennau","raw_affiliation_strings":["FZI Research Center for Information Technology, Karslruhe, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"FZI Research Center for Information Technology, Karslruhe, Germany","institution_ids":["https://openalex.org/I143379178"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004964717","display_name":"Ruediger Dillmann","orcid":"https://orcid.org/0000-0002-2049-8219"},"institutions":[{"id":"https://openalex.org/I102335020","display_name":"Karlsruhe Institute of Technology","ror":"https://ror.org/04t3en479","country_code":"DE","type":"education","lineage":["https://openalex.org/I102335020","https://openalex.org/I1305996414"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Ruediger Dillmann","raw_affiliation_strings":["Karlsruhe Institute of Technology (KIT), Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Karlsruhe Institute of Technology (KIT), Germany","institution_ids":["https://openalex.org/I102335020"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060028048","display_name":"J. Marius Z\u00f6llner","orcid":"https://orcid.org/0000-0001-6190-7202"},"institutions":[{"id":"https://openalex.org/I102335020","display_name":"Karlsruhe Institute of Technology","ror":"https://ror.org/04t3en479","country_code":"DE","type":"education","lineage":["https://openalex.org/I102335020","https://openalex.org/I1305996414"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"J. Marius Zollner","raw_affiliation_strings":["Karlsruhe Institute of Technology (KIT), Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Karlsruhe Institute of Technology (KIT), Germany","institution_ids":["https://openalex.org/I102335020"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.1399,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.53626813,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":"abs 1712 9665","issue":null,"first_page":"177","last_page":"181"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9236999750137329,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8798635005950928},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.8213626742362976},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7677187323570251},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6758437752723694},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6470963954925537},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.6249878406524658},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5698526501655579},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.47247669100761414},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4102437198162079},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.3962543308734894},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.3741946816444397}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8798635005950928},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.8213626742362976},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7677187323570251},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6758437752723694},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6470963954925537},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.6249878406524658},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5698526501655579},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.47247669100761414},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4102437198162079},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3962543308734894},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3741946816444397},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isr50024.2021.9419509","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isr50024.2021.9419509","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Conference on Intelligence and Safety for Robotics (ISR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":35,"referenced_works":["https://openalex.org/W1659842140","https://openalex.org/W1757796397","https://openalex.org/W2155007355","https://openalex.org/W2586751528","https://openalex.org/W2604394466","https://openalex.org/W2616841723","https://openalex.org/W2736601468","https://openalex.org/W2781726626","https://openalex.org/W2789008106","https://openalex.org/W2890054895","https://openalex.org/W2908314380","https://openalex.org/W2911506106","https://openalex.org/W2941205169","https://openalex.org/W2947234734","https://openalex.org/W2949103145","https://openalex.org/W2962748759","https://openalex.org/W2962793652","https://openalex.org/W2962927323","https://openalex.org/W2964161785","https://openalex.org/W2990747716","https://openalex.org/W3115741658","https://openalex.org/W4293872189","https://openalex.org/W4298857966","https://openalex.org/W6637967152","https://openalex.org/W6682849425","https://openalex.org/W6733049761","https://openalex.org/W6737897983","https://openalex.org/W6741002519","https://openalex.org/W6747473740","https://openalex.org/W6748599296","https://openalex.org/W6751839145","https://openalex.org/W6754363872","https://openalex.org/W6758269446","https://openalex.org/W6763011915","https://openalex.org/W6787872340"],"related_works":["https://openalex.org/W3048732067","https://openalex.org/W4383468834","https://openalex.org/W2900159906","https://openalex.org/W4384648009","https://openalex.org/W4283221438","https://openalex.org/W4287828318","https://openalex.org/W2406556600","https://openalex.org/W4380352238","https://openalex.org/W2950183588","https://openalex.org/W4293054861"],"abstract_inverted_index":{"Deep":[0],"reinforcement":[1],"learning":[2],"(DRL)":[3],"has":[4],"had":[5],"a":[6],"profound":[7],"impact":[8],"in":[9,16,87,142],"the":[10,22,44,55,100,107,119,122,143,146],"field":[11],"of":[12,26,57,102,118,133],"robotic":[13,28],"learning,":[14],"especially":[15],"vision-based":[17,50],"end-to-end":[18],"applications.":[19],"To":[20],"ensure":[21],"robustness":[23],"and":[24,80,129,140],"stability":[25],"such":[27],"systems,":[29],"their":[30,74],"vulnerability":[31],"to":[32,62,93,135],"possible":[33],"adversarial":[34,58,103,111,151],"attacks":[35,83,152],"must":[36],"be":[37,94],"explored.":[38],"In":[39],"this":[40],"paper":[41],"we":[42],"demonstrate":[43],"first":[45],"realistic":[46,150],"black-box":[47],"attack":[48],"on":[49,68,153],"DRL":[51,85,124,154],"systems":[52,86,125],"by":[53],"adopting":[54],"concept":[56],"patches.":[59],"Agents":[60],"trained":[61],"perform":[63],"object":[64],"grasping":[65],"based":[66],"only":[67],"visual":[69],"input":[70],"are":[71,89,126],"manipulated":[72],"through":[73],"observation":[75],"space.":[76],"Different":[77],"patch":[78,104],"sizes":[79],"positions":[81],"for":[82,148],"targeting":[84],"simulation":[88,144],"evaluated,":[90],"which":[91],"prove":[92],"decisive":[95],"factors":[96],"that":[97,109],"greatly":[98],"influence":[99],"effectiveness":[101],"attacks.":[105],"Despite":[106],"fact":[108],"evaluated":[110],"patches":[112],"take":[113],"up":[114,134],"less":[115],"than":[116],"2%":[117],"images":[120],"observed,":[121],"attacked":[123],"heavily":[127],"affected":[128],"show":[130],"performance":[131],"drop":[132],"99":[136],"%.":[137],"Our":[138],"experiments":[139],"results":[141],"pave":[145],"way":[147],"more":[149],"agents.":[155]},"counts_by_year":[{"year":2021,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
