用集成防御提升自动驾驶DRL模型抗攻击能力
Advancing Robustness in Deep Reinforcement Learning with an Ensemble Defense Approach
- 设计集成防御架构,融合多种防御策略
- 对抗攻击下奖励提升213%,碰撞率降82%
- 特别适合自动驾驶等高安全场景
深度强化学习(DRL)已在机器人、医疗、能源优化和自动驾驶等领域展现应用潜力。然而,当面对对抗攻击时,DRL模型的鲁棒性仍存疑。尽管已有防御方法如对抗训练和知识蒸馏可增强模型韧性,但在自动驾驶场景中整合多种防御机制的研究仍存在显著空白。本文提出一种新型集成防御架构,以缓解自动驾驶中的对抗攻击问题。评估结果表明,该架构显著提升了DRL模型的鲁棒性:在高速公路与汇入车道场景下,相较于基线模型,在FGSM攻击下平均奖励从5.87提升至18.38(增长超213%),平均碰撞率从0.50降至0.09(下降82%),优于所有单一防御策略。
原文摘要 · Abstract (English)
Recent advancements in Deep Reinforcement Learning (DRL) have demonstrated its applicability across various domains, including robotics, healthcare, energy optimization, and autonomous driving. However, a critical question remains: How robust are DRL models when exposed to adversarial attacks? While existing defense mechanisms such as adversarial training and distillation enhance the resilience of DRL models, there remains a significant research gap regarding the integration of multiple defenses in autonomous driving scenarios specifically. This paper addresses this gap by proposing a novel ensemble-based defense architecture to mitigate adversarial attacks in autonomous driving. Our evaluation demonstrates that the proposed architecture significantly enhances the robustness of DRL models. Compared to the baseline under FGSM attacks, our ensemble method improves the mean reward from 5.87 to 18.38 (over 213% increase) and reduces the mean collision rate from 0.50 to 0.09 (an 82% decrease) in the highway scenario and merge scenario, outperforming all standalone defense strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。