{"id":"https://openalex.org/W3185519452","doi":"https://doi.org/10.23919/acc50511.2021.9483025","title":"Towards Optimal Attacks on Reinforcement Learning Policies","display_name":"Towards Optimal Attacks on Reinforcement Learning Policies","publication_year":2021,"publication_date":"2021-05-25","ids":{"openalex":"https://openalex.org/W3185519452","doi":"https://doi.org/10.23919/acc50511.2021.9483025","mag":"3185519452"},"language":"en","primary_location":{"id":"doi:10.23919/acc50511.2021.9483025","is_oa":false,"landing_page_url":"https://doi.org/10.23919/acc50511.2021.9483025","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 American Control Conference (ACC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101696896","display_name":"Alessio Russo","orcid":"https://orcid.org/0000-0001-9083-5260"},"institutions":[{"id":"https://openalex.org/I86987016","display_name":"KTH Royal Institute of Technology","ror":"https://ror.org/026vcq606","country_code":"SE","type":"education","lineage":["https://openalex.org/I86987016"]}],"countries":["SE"],"is_corresponding":true,"raw_author_name":"Alessio Russo","raw_affiliation_strings":["Division of Decision and Control Systems, KTH Royal Institute of Technology, Sweden"],"affiliations":[{"raw_affiliation_string":"Division of Decision and Control Systems, KTH Royal Institute of Technology, Sweden","institution_ids":["https://openalex.org/I86987016"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5025136069","display_name":"Alexandre Prouti\u00e8re","orcid":"https://orcid.org/0000-0002-4679-4673"},"institutions":[{"id":"https://openalex.org/I86987016","display_name":"KTH Royal Institute of Technology","ror":"https://ror.org/026vcq606","country_code":"SE","type":"education","lineage":["https://openalex.org/I86987016"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Alexandre Proutiere","raw_affiliation_strings":["Division of Decision and Control Systems, KTH Royal Institute of Technology, Sweden"],"affiliations":[{"raw_affiliation_string":"Division of Decision and Control Systems, KTH Royal Institute of Technology, Sweden","institution_ids":["https://openalex.org/I86987016"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5101696896"],"corresponding_institution_ids":["https://openalex.org/I86987016"],"apc_list":null,"apc_paid":null,"fwci":1.4957,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.85603099,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"4561","last_page":"4567"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.970300018787384,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10462","display_name":"Reinforcement Learning in Robotics","score":0.9362000226974487,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.9155117273330688},{"id":"https://openalex.org/keywords/markov-decision-process","display_name":"Markov decision process","score":0.7934212684631348},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7471923232078552},{"id":"https://openalex.org/keywords/partially-observable-markov-decision-process","display_name":"Partially observable Markov decision process","score":0.6724169850349426},{"id":"https://openalex.org/keywords/heuristics","display_name":"Heuristics","score":0.5922088027000427},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5264628529548645},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5158383250236511},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4134117066860199},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.39456266164779663},{"id":"https://openalex.org/keywords/markov-process","display_name":"Markov process","score":0.38974159955978394},{"id":"https://openalex.org/keywords/mathematical-optimization","display_name":"Mathematical optimization","score":0.34072208404541016},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3300231695175171},{"id":"https://openalex.org/keywords/markov-chain","display_name":"Markov chain","score":0.2499190866947174},{"id":"https://openalex.org/keywords/markov-model","display_name":"Markov model","score":0.19917991757392883},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.11804154515266418}],"concepts":[{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.9155117273330688},{"id":"https://openalex.org/C106189395","wikidata":"https://www.wikidata.org/wiki/Q176789","display_name":"Markov decision process","level":3,"score":0.7934212684631348},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7471923232078552},{"id":"https://openalex.org/C17098449","wikidata":"https://www.wikidata.org/wiki/Q176814","display_name":"Partially observable Markov decision process","level":4,"score":0.6724169850349426},{"id":"https://openalex.org/C127705205","wikidata":"https://www.wikidata.org/wiki/Q5748245","display_name":"Heuristics","level":2,"score":0.5922088027000427},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5264628529548645},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5158383250236511},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4134117066860199},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.39456266164779663},{"id":"https://openalex.org/C159886148","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov process","level":2,"score":0.38974159955978394},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.34072208404541016},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3300231695175171},{"id":"https://openalex.org/C98763669","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov chain","level":2,"score":0.2499190866947174},{"id":"https://openalex.org/C163836022","wikidata":"https://www.wikidata.org/wiki/Q6771326","display_name":"Markov model","level":3,"score":0.19917991757392883},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.11804154515266418},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.23919/acc50511.2021.9483025","is_oa":false,"landing_page_url":"https://doi.org/10.23919/acc50511.2021.9483025","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 American Control Conference (ACC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.7799999713897705,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G8600725529","display_name":null,"funder_award_id":"RIT17-0046","funder_id":"https://openalex.org/F4320320940","funder_display_name":"Stiftelsen f\u00f6r\u00a0Strategisk Forskning"}],"funders":[{"id":"https://openalex.org/F4320320940","display_name":"Stiftelsen f\u00f6r\u00a0Strategisk Forskning","ror":"https://ror.org/044wr7g58"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W52153049","https://openalex.org/W1541084404","https://openalex.org/W1757796397","https://openalex.org/W1771410628","https://openalex.org/W1945616565","https://openalex.org/W2011418219","https://openalex.org/W2105078254","https://openalex.org/W2121092017","https://openalex.org/W2150468603","https://openalex.org/W2155007355","https://openalex.org/W2165150801","https://openalex.org/W2257979135","https://openalex.org/W2586751528","https://openalex.org/W2602963933","https://openalex.org/W2616841723","https://openalex.org/W2766447205","https://openalex.org/W2773525213","https://openalex.org/W2941205169","https://openalex.org/W2949103145","https://openalex.org/W2962755762","https://openalex.org/W2962927323","https://openalex.org/W2962938178","https://openalex.org/W2963207607","https://openalex.org/W2963864421","https://openalex.org/W2964043796","https://openalex.org/W2964108292","https://openalex.org/W2964161785","https://openalex.org/W2964725706","https://openalex.org/W2998401161","https://openalex.org/W3098237412","https://openalex.org/W3103780890","https://openalex.org/W4298325485","https://openalex.org/W4298857966","https://openalex.org/W4302570325","https://openalex.org/W6637967152","https://openalex.org/W6638018090","https://openalex.org/W6640425456","https://openalex.org/W6677939520","https://openalex.org/W6682849425","https://openalex.org/W6684205842","https://openalex.org/W6684921986","https://openalex.org/W6692846177","https://openalex.org/W6733049761","https://openalex.org/W6735677848","https://openalex.org/W6737897983","https://openalex.org/W6747027214","https://openalex.org/W6766410358","https://openalex.org/W6780559895"],"related_works":["https://openalex.org/W2096013579","https://openalex.org/W52153049","https://openalex.org/W1760611253","https://openalex.org/W1515117609","https://openalex.org/W1589140671","https://openalex.org/W4323315247","https://openalex.org/W2294884454","https://openalex.org/W3169161914","https://openalex.org/W4321379664","https://openalex.org/W2211790881"],"abstract_inverted_index":{"Control":[0],"policies,":[1,176],"trained":[2,128],"using":[3,33,129,204,216,224],"Deep":[4],"Reinforcement":[5,130,217],"Learning,":[6],"have":[7,30],"been":[8,31],"recently":[9],"shown":[10],"to":[11,14,21,43,67,88,94,103,143,158,172,179,221,229],"be":[12,127,202],"vulnerable":[13],"adversarial":[15,38],"attacks":[16,26,101,125,141,153,173],"introducing":[17],"even":[18],"minimal":[19],"perturbations":[20],"the":[22,54,69,75,78,84,89,117,120,137,149,159,162,180,190,194,199],"policy":[23,76,118,163],"input.":[24],"The":[25],"proposed":[27],"so":[28],"far":[29],"designed":[32],"heuristics,":[34],"based":[35],"on":[36,61],"existing":[37,144],"example":[39],"crafting":[40],"techniques":[41],"used":[42],"dupe":[44],"classifiers":[45],"in":[46],"supervised":[47],"learning.":[48],"In":[49],"contrast,":[50],"this":[51],"paper":[52],"investigates":[53],"problem":[55],"of":[56,139,152,161],"devising":[57],"optimal":[58,100,124],"attacks,":[59,114],"depending":[60],"a":[62,91,96,105,205],"well-defined":[63],"attacker's":[64],"objective,":[65],"e.g.,":[66],"minimize":[68],"main":[70,191],"agent":[71,192],"average":[72],"reward.":[73],"When":[74],"and":[77,154],"system":[79,121,195],"dynamics,":[80],"as":[81,83,95],"well":[82],"rewards,":[85],"are":[86,168,182],"known":[87],"attacker,":[90],"scenario":[92],"referred":[93],"white-box":[97],"attack,":[98],"designing":[99],"amounts":[102],"solving":[104],"Markov":[106,208],"Decision":[107,209],"Process.":[108],"For":[109],"what":[110],"we":[111,186],"call":[112],"black-box":[113],"where":[115],"neither":[116],"nor":[119],"is":[122],"known,":[123],"can":[126,201],"Learning.":[131],"We":[132,146,213],"present":[133],"numerical":[134],"experiments":[135],"demonstrating":[136],"efficiency":[138],"our":[140],"compared":[142],"attacks.":[145],"further":[147],"quantify":[148],"potential":[150],"impact":[151],"establish":[155],"its":[156],"connection":[157],"smoothness":[160],"under":[164],"attack.":[165],"Smooth":[166],"policies":[167],"naturally":[169],"less":[170],"prone":[171],"(e.g.":[174,223],"Lipschitz":[175],"with":[177],"respect":[178],"state,":[181],"more":[183,230],"resilient).":[184],"Finally,":[185],"show":[187],"that":[188,215],"from":[189],"perspective,":[193],"uncertainties":[196],"induced":[197],"by":[198],"attack":[200],"modelled":[203],"Partially":[206],"Observable":[207],"Process":[210],"(POMDP)":[211],"framework.":[212],"demonstrate":[214],"Learning":[218],"methods":[219],"tailored":[220],"POMDP":[222],"Recurrent":[225],"Neural":[226],"Networks)":[227],"leads":[228],"resilient":[231],"policies.":[232]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
