针对多智能体通信设计精准攻击,找到最脆弱的发送者、消息和时间点。
Finding the Weakest Link: Adversarial Attack against Multi-Agent Communications
- 利用雅可比梯度定位最易受攻击的通信节点和时机。
- 在30个场景中半数以上攻击成功率与影响显著提升。
- 适合研究多智能体系统安全或对抗性测试的读者。
多智能体系统依赖通信进行信息共享与协同行动,这使其面临攻击风险。本文研究针对多智能体强化学习训练系统的单目标通信扰动攻击,提出基于雅可比矩阵梯度的方法,识别出最易受攻击的消息、智能体及时间步,并最大化攻击影响。通过引入两种新的对抗性损失函数,在攻击成功率与影响之间实现权衡,生成更有效的扰动。在导航任务中的PredatorPrey和TrafficJunction环境里,对两种不同通信机制进行实证评估。结果表明,所提消息选择方法在几乎所有测试场景中达到甚至超过随机选择的效果;受害者选择、消息选择、时间选择及损失函数改进,在30个测试场景中提升了半数以上攻击的有效性。
原文摘要 · Abstract (English)
Multi-agent systems rely on communication for information sharing and action coordination, which exposes a vulnerability to attacks. We investigate single-victim communication perturbation attacks against Multi-Agent Reinforcement Learning-trained systems and propose methods that use gradient information from the Jacobian to identify which messages, agent, and timesteps are most susceptible to attack and have the greatest impact on the system. We enhance these methods with two proposed adversarial loss functions that trade-off attack success for attack impact which also create more effective perturbations. We empirically demonstrate the effectiveness of our methods against two different multi-agent communication methods in navigation, PredatorPrey, and TrafficJunction environments. Our results show that our novel message selection method achieves a similar or greater impact than random message selection across almost all tested scenarios. Our victim selection, message selection, tempo, and loss functions improve attack effectiveness in half of the thirty scenarios we tested.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。