arXiv:2505.21938cs.LGcs.AI2025-05被引 2

通过注入有限伪造数据,攻击随机多臂老虎机算法。

Practical Adversarial Attacks on Stochastic Bandits via Fake Data Injection

  • 限定数量且有界地注入虚假反馈数据,模拟真实攻击场景。
  • 理论证明可几乎每轮诱导算法选目标臂,攻击成本仅亚线性增长。
  • 适用于评估实际系统中带权算法的鲁棒性,尤其关注安全设计者。

针对随机多臂老虎机的对抗攻击传统上依赖不切实际的假设,如每轮奖励操控和无界扰动,限制了其在现实系统中的适用性。本文提出更贴近现实的威胁模型——伪造数据注入:攻击者只能向学习者的历史中注入有限数量、有界的虚假反馈样本,模拟合法交互。我们设计了有效的攻击策略,显式处理奖励值幅度约束与注入时间频率约束。理论分析表明,此类攻击可使一类带权算法在几乎所有轮次中选择目标臂,同时攻击成本仅为亚线性。在合成及真实数据集上的实验验证了策略的有效性,揭示了随机多臂老虎机算法在实际对抗场景下的脆弱性。

原文摘要 · Abstract (English)

Adversarial attacks on stochastic bandits have traditionally relied on some unrealistic assumptions, such as per-round reward manipulation and unbounded perturbations, limiting their relevance to real-world systems. We propose a more practical threat model, Fake Data Injection, which reflects realistic adversarial constraints: the attacker can inject only a limited number of bounded fake feedback samples into the learner's history, simulating legitimate interactions. We design effective attack strategies under this model, explicitly addressing both magnitude constraints (on reward values) and temporal constraints (on when and how often data can be injected). Our theoretical analysis shows that these attacks can mislead a class of bandit algorithms into selecting a target arm in nearly all rounds while incurring only sublinear attack cost. Experiments on synthetic and real-world datasets validate the effectiveness of our strategies, revealing vulnerabilities in stochastic bandit algorithms under practical adversarial scenarios.

对抗攻击多臂老虎机数据注入强化学习安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。