Policy Disruption in Reinforcement Learning:Adversarial Attack with Large Language Models and Critical State Identification

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Jiang, Junyong, Tian, Buwei, Xu, Chenxing, Li, Songze, Dong, Lu
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866912499454967808
author Jiang, Junyong
Tian, Buwei
Xu, Chenxing
Li, Songze
Dong, Lu
author_facet Jiang, Junyong
Tian, Buwei
Xu, Chenxing
Li, Songze
Dong, Lu
contents Reinforcement learning (RL) has achieved remarkable success in fields like robotics and autonomous driving, but adversarial attacks designed to mislead RL systems remain challenging. Existing approaches often rely on modifying the environment or policy, limiting their practicality. This paper proposes an adversarial attack method in which existing agents in the environment guide the target policy to output suboptimal actions without altering the environment. We propose a reward iteration optimization framework that leverages large language models (LLMs) to generate adversarial rewards explicitly tailored to the vulnerabilities of the target agent, thereby enhancing the effectiveness of inducing the target agent toward suboptimal decision-making. Additionally, a critical state identification algorithm is designed to pinpoint the target agent's most vulnerable states, where suboptimal behavior from the victim leads to significant degradation in overall performance. Experimental results in diverse environments demonstrate the superiority of our method over existing approaches.
format Preprint
id arxiv_https___arxiv_org_abs_2507_18113
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Policy Disruption in Reinforcement Learning:Adversarial Attack with Large Language Models and Critical State Identification
Jiang, Junyong
Tian, Buwei
Xu, Chenxing
Li, Songze
Dong, Lu
Machine Learning
Reinforcement learning (RL) has achieved remarkable success in fields like robotics and autonomous driving, but adversarial attacks designed to mislead RL systems remain challenging. Existing approaches often rely on modifying the environment or policy, limiting their practicality. This paper proposes an adversarial attack method in which existing agents in the environment guide the target policy to output suboptimal actions without altering the environment. We propose a reward iteration optimization framework that leverages large language models (LLMs) to generate adversarial rewards explicitly tailored to the vulnerabilities of the target agent, thereby enhancing the effectiveness of inducing the target agent toward suboptimal decision-making. Additionally, a critical state identification algorithm is designed to pinpoint the target agent's most vulnerable states, where suboptimal behavior from the victim leads to significant degradation in overall performance. Experimental results in diverse environments demonstrate the superiority of our method over existing approaches.
title Policy Disruption in Reinforcement Learning:Adversarial Attack with Large Language Models and Critical State Identification
topic Machine Learning
url https://arxiv.org/abs/2507.18113