用数字孪生和历史参数防御自动驾驶强化学习中的恶意攻击
Securing Autonomous Vehicle Systems via Twin-Aware Federated Reinforcement Learning

- 引入数字孪生与历史模型参数,筛选良性数据聚合
- 理论证明在攻击下仍能保证算法收敛
- 适合关注自动驾驶安全的系统设计者
联邦强化学习(FRL)在无需共享原始数据的前提下实现多智能体协同学习,提升动态交通环境中决策的隐私性与可扩展性。然而,中毒攻击严重威胁FRL系统的安全性和可靠性,尤其在对安全性要求极高的自动驾驶场景中,此类漏洞尚未被充分研究。攻击者可通过微调恶意系统参数,破坏全局控制模型,引发潜在风险。为此,我们提出 extsc{SecA}(Secure Aggregation with poisoning-prevention and historical reinforcement),一种面向安全关键驾驶场景的防御框架。该方法结合数字孪生进行回放式学习,利用历史聚合模型参数与选定中心梯度,确保仅良性数据被纳入聚合,有效抑制恶意代理的影响。理论上, extsc{SecA} 在存在中毒攻击时仍能保证收敛性能。通过构建模拟真实高速环境的数字孪生系统,我们在对抗条件下验证了该框架在自动驾驶车辆控制中的有效性。
原文摘要 · Abstract (English)
Federated reinforcement learning (FRL) is crucial for enabling collaborative learning across multiple agents without sharing raw data, thereby enhancing privacy and scalability in the decision-making process within dynamic vehicular environments. However, poisoning attacks pose a significant threat to the security and reliability of FRL-based systems, particularly in safety-critical autonomous driving, where this vulnerability remains largely unexplored. These attacks can compromise the global control model by subtly injecting malicious system parameters, leading to potential hazards. To counter these challenges, we present \alg (\underline{Sec}ure \underline{A}ggregation with \underline{p}oisoning-\underline{p}revention and historical reinforcement) as a defensive framework aimed at enhancing the robustness of FRL systems designed for safety-critical driving scenarios. \alg strategically integrates digital twins for rehearsal-based learning and leverages historical aggregated model parameters along with a selected central gradient to ensure that only benign data is aggregated, effectively mitigating the influence of malicious agents. Theoretical guarantees are provided for the convergence performance of \alg in the presence of poisoning attacks. We also validate the effectiveness of \alg using developed digital twins that model realistic highway environments to evaluate the control of autonomous vehicles under adversarial conditions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。