PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 17, 20250 citationsOpen Access

Policy Disruption in Reinforcement Learning:Adversarial Attack with Large Language Models and Critical State Identification

View Full Paper
JJJunyong JiangBTBuwei TianCXChenxing Xu

Key Points

  • Proposed a novel adversarial attack method that generates tailored rewards using large language models, leading to suboptimal actions.
  • Demonstrated effectiveness through experimental results across various environments, outperforming previous methods.
  • Developed a critical state identification algorithm to find vulnerable states in the target agent, leading to significant performance degradation.
  • Challenges existing reinforcement learning strategies by addressing the practical limitations of modifying environments or policies.

Abstract

Reinforcement learning (RL) has achieved remarkable success in fields like robotics and autonomous driving, but adversarial attacks designed to mislead RL systems remain challenging. Existing approaches often rely on modifying the environment or policy, limiting their practicality. This paper proposes an adversarial attack method in which existing agents in the environment guide the target policy to output suboptimal actions without altering the environment. We propose a reward iteration optimization framework that leverages large language models (LLMs) to generate adversarial rewards explicitly tailored to the vulnerabilities of the target agent, thereby enhancing the effectiveness of inducing the target agent toward suboptimal decision-making. Additionally, a critical state identification algorithm is designed to pinpoint the target agent's most vulnerable states, where suboptimal behavior from the victim leads to significant degradation in overall performance. Experimental results in diverse environments demonstrate the superiority of our method over existing approaches.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Jiang et al. (2025) studied this question.

synapsesocial.com/papers/68f19f20de32064e504ddf38https://doi.org/10.48550/arxiv.2507.18113
Ask AI
Helpful
Bookmark
Share
View Full Paper