Stealthy Black-Box Attack With Dynamic Threshold Against MARL-Based Traffic Signal Control System

被引:0
|
作者
Ren, Yan [1 ]
Zhang, Heng [1 ,2 ]
Du, Linkang [3 ]
Zhang, Zhikun [4 ]
Zhang, Jian [2 ]
Li, Hongran [2 ]
机构
[1] Jiangsu Ocean Univ, Coll Elect Engn, Lianyungang 222000, Peoples R China
[2] Jiangsu Ocean Univ, Coll Comp Engn, Lianyungang 222000, Peoples R China
[3] Zhejiang Univ, Coll Control Sci & Engn, Hangzhou 310000, Peoples R China
[4] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310000, Peoples R China
基金
中国国家自然科学基金;
关键词
Training; Perturbation methods; Heuristic algorithms; Closed box; Optimization; Control systems; Vehicle dynamics; Adversarial attack; deep reinforcement learning (DRL); defense; security; traffic signal control; ROBUSTNESS;
D O I
10.1109/TII.2024.3413356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Multiagent reinforcement learning (MARL) promises outstanding performance for multiintersection traffic signal control systems (TSCS), enabling intelligent administration of cities. However, the vulnerability of MARL algorithms to adversarial attacks has raised concerns about the security of TSCS. In this article, we explore the robustness of MARL-based TSCS against adversarial attacks, propose a black-box multiobject attack strategy, and assign an attack budget to ensure stealthiness. We design a dynamic threshold-based selection of critical states to minimize the cumulative reward with a limited number of attacks. In addition, we present a lightweight agnostic dynamic threshold-based defense mechanism by enhancing the worst-case performance of the policy. We formulate it as a min-max optimization problem, i.e., minimizing the quantity of training sample alterations while maximizing the cumulative discount reward of policy against the perturbed states. Extensive experiments on simulation of urban mobility (SUMO) demonstrate that the proposed attack policy can significantly reduce the performance of TSCS.
引用
收藏
页码:12021 / 12031
页数:11
相关论文
共 23 条
  • [1] Promoting or Hindering: Stealthy Black-Box Attacks Against DRL-Based Traffic Signal Control
    Ren, Yan
    Zhang, Heng
    Cao, Xianghui
    Yang, Chaoqun
    Zhang, Jian
    Li, Hongran
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (04): : 5816 - 5825
  • [2] Model Inversion Attack against a Face Recognition System in a Black-Box Setting
    Yoshimura, Shunsuke
    Nakamura, Kazuaki
    Nitta, Naoko
    Babaguchi, Noboru
    2021 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2021, : 1800 - 1807
  • [3] Black-box Stealthy Frequency Spectrum Attack on LSTM-based Power Load Forecasting In An Energy Management System with Islanded Microgrid
    Nazeri, Amirhossein
    Biroon, Roghieh A.
    Pisu, Pierluigi
    2023 NORTH AMERICAN POWER SYMPOSIUM, NAPS, 2023,
  • [4] Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection
    Liang, Siyuan
    Wu, Baoyuan
    Fan, Yanbo
    Wei, Xingxing
    Cao, Xiaochun
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7677 - 7687
  • [5] Query-based black-box attack against medical image segmentation model
    Li, Siyuan
    Huang, Guangji
    Xu, Xing
    Lu, Huimin
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 133 : 331 - 337
  • [6] A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors
    LYU Haoran
    TAN Yu'an
    XUE Yuan
    WANG Yajie
    XUE Jingfeng
    Chinese Journal of Electronics, 2021, 30 (03) : 406 - 412
  • [7] A CMA-ES-Based Adversarial Attack Against Black-Box Object Detectors
    Lyu Haoran
    Tan Yu'an
    Xue Yuan
    Wang Yajie
    Xue Jingfeng
    CHINESE JOURNAL OF ELECTRONICS, 2021, 30 (03) : 406 - 412
  • [8] Query-Efficient Black-Box Attack Against Sequence-Based Malware Classifiers
    Rosenberg, Ishai
    Shabtai, Asaf
    Elovici, Yuval
    Rokach, Lior
    36TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2020), 2020, : 611 - 626
  • [9] MalAder: Decision-Based Black-Box Attack Against API Sequence Based Malware Detectors
    Chen, Xiaohui
    Cui, Lei
    Wen, Hui
    Li, Zhi
    Zhu, Hongsong
    Hao, Zhiyu
    Sun, Limin
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, DSN, 2023, : 165 - 178
  • [10] Reputation Defender: Local Black-Box Adversarial Attack against Image-Translation-Based DeepFake
    Yang, Wang
    Zhao, Lingchen
    Ye, Dengpan
    2024 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, ICME 2024, 2024,