提出三类共谋对抗攻击,提升隐蔽性与协同破坏力。
CAMA: Exploring Collusive Adversarial Attacks in c-MARL
- 设计统一框架CAMA,实现三类共谋攻击
- 实验证明三类攻击具叠加破坏效果
- 适合研究多智能体安全与防御的学者
合作式多智能体强化学习(c-MARL)已广泛应用于社交机器人、具身智能、无人机集群等场景。然而,现有对抗攻击多聚焦单个恶意智能体或白盒攻击,难以模拟真实威胁。本文首次提出三类共谋对抗攻击模式:集体恶意智能体、伪装恶意智能体和窃听恶意智能体,并设计统一框架CAMA实现策略级共谋攻击。理论分析从破坏性、隐蔽性和攻击成本三个维度验证有效性;技术上通过观测信息融合与攻击触发控制实现攻击。在四个SMAC II地图上进行多维度实验,结果表明三类攻击具有叠加协同效应,在长期运行中保持高隐蔽性与稳定性,显著增强破坏力。本工作填补了c-MARL中共谋对抗学习的研究空白。
原文摘要 · Abstract (English)
Cooperative multi-agent reinforcement learning (c-MARL) has been widely deployed in real-world applications, such as social robots, embodied intelligence, UAV swarms, etc. Nevertheless, many adversarial attacks still exist to threaten various c-MARL systems. At present, the studies mainly focus on single-adversary perturbation attacks and white-box adversarial attacks that manipulate agents' internal observations or actions. To address these limitations, we in this paper attempt to study collusive adversarial attacks through strategically organizing a set of malicious agents into three collusive attack modes: Collective Malicious Agents, Disguised Malicious Agents, and Spied Malicious Agents. Three novelties are involved: i) three collusive adversarial attacks are creatively proposed for the first time, and a unified framework CAMA for policy-level collusive attacks is designed; ii) the attack effectiveness is theoretically analyzed from the perspectives of disruptiveness, stealthiness, and attack cost; and iii) the three collusive adversarial attacks are technically realized through agent's observation information fusion, attack-trigger control. Finally, multi-facet experiments on four SMAC II maps are performed, and experimental results showcase the three collusive attacks have an additive adversarial synergy, strengthening attack outcome while maintaining high stealthiness and stability over long horizons. Our work fills the gap for collusive adversarial learning in c-MARL.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。