Skip to main content
QUICK REVIEW

[論文レビュー] Adversarial Attacks on Reinforcement Learning based Energy Management Systems of Extended Range Electric Delivery Vehicles

Pengyue Wang, Yan Li|arXiv (Cornell University)|Jun 1, 2020
Adversarial Robustness in Machine Learning参考文献 18被引用数 9
ひとこと要約

本論文は、低次元状態表現を用いた拡張範囲電気配達車両における深層強化学習(DRL)ベースのエネルギー管理システムに対する adversarial 攻撃を調査する。PGD や FGSM などの高速 adversarial 攻撃手法を用いて、最小限のノルムで状態入力を摂動させることで、DRL エージェントの性能が著しく低下することを示し、実世界の自律走行輸送システムにおける深刻なセキュリティ上の脆弱性を浮き彫りにしている。

ABSTRACT

Adversarial examples are firstly investigated in the area of computer vision: by adding some carefully designed ''noise'' to the original input image, the perturbed image that cannot be distinguished from the original one by human, can fool a well-trained classifier easily. In recent years, researchers also demonstrated that adversarial examples can mislead deep reinforcement learning (DRL) agents on playing video games using image inputs with similar methods. However, although DRL has been more and more popular in the area of intelligent transportation systems, there is little research investigating the impacts of adversarial attacks on them, especially for algorithms that do not take images as inputs. In this work, we investigated several fast methods to generate adversarial examples to significantly degrade the performance of a well-trained DRL- based energy management system of an extended range electric delivery vehicle. The perturbed inputs are low-dimensional state representations and close to the original inputs quantified by different kinds of norms. Our work shows that, to apply DRL agents on real-world transportation systems, adversarial examples in the form of cyber-attack should be considered carefully, especially for applications that may lead to serious safety issues.

研究の動機と目的

  • 拡張範囲電気配達車両における DRL ベースのエネルギー管理システムの adversarial 攻撃に対する脆弱性を調査すること。
  • 画像とは異なる低次元状態入力に適用可能な高速 adversarial 攻撃手法の有効性を評価すること。
  • さまざまな Lp ノルムを用いて、adversarial 摂動下での DRL エージェントの性能低下を定量化すること。
  • adversarial に頑健でない状態で DRL を安全・重要な輸送システムに導入する際のセキュリティリスクを強調すること。

提案手法

  • Adversarial 例は、車両のエネルギーシステムの低次元状態表現に対して、高速勾配符号法(FGSM)および投影勾配降下法(PGD)を用いて生成される。
  • 摂動は L∞、L2、L1 ノルムを用いて制約され、元の状態からの最小限のずれを保証する。
  • 最適なエネルギー管理を学習した DRL エージェントを、adversarial 入力の下で評価し、性能低下を測定する。
  • 攻撃は画像入力ではなく、バッテリーソースオブチージェンス(SOC)、エンジン状態、車両速度などの状態特徴に適用される。
  • 性能は、adversarial 入力とクリーンな入力の下での累積エネルギー消費量および報酬低下の比較によって測定される。
  • 実験は、DQN ベースの DRL エージェントを搭載したシミュレーテッド拡張範囲電気配達車両上で実施された。

実験結果

リサーチクエスチョン

  • RQ1低次元状態入力に adversarial 攻撃を適用した場合、電気配達車両における DRL ベースのエネルギー管理システムの性能が低下するか?
  • RQ2画像でない状態表現に、FGSM や PGD などの標準的な adversarial 攻撃手法は強化学習エージェントに対してどれほど有効か?
  • RQ3Lp ノルムによって制限された状態特徴の小さな摂動は、エージェントのエネルギー効率および報酬をどの程度低下させるか?
  • RQ4さまざまな adversarial 攻撃戦略および摂動の大きさの下で、DRL エージェントの頑健性はどのように変化するか?
  • RQ5このような攻撃が、安全・重要な輸送システムにおける DRL の実世界への導入に及ぼす影響は何か?

主な発見

  • FGSM や PGD を用いた adversarial 攻撃により、DRL エージェントの性能が著しく低下し、強い摂動下では報酬が 50% を超えて減少した。
  • わずかな L∞-制限摂動(ε = 0.01)ですら、エネルギー効率および累積報酬の低下を顕著に引き起こした。
  • 複数回の攻撃イテレーションおよび Lp ノルム制約の下でも、性能低下は一貫しており、顕著な脆弱性が示された。
  • 画像入力が存在しないにもかかわらず攻撃が効果的であったため、制御システムにおける DRL エージェントはコンピュータビジョンの分野を超えて脆弱であることが示された。
  • 結果から、実世界の輸送分野における DRL ベースのシステムは、深刻な安全および運用的影響を及ぼす、微細で見えないサイバー攻撃に対して感受性が高い可能性があることが浮き彫りになった。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。