Worst-Case Discovery and Runtime Protection for RL-Based Network Controllers

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Hè, Hongyu, Jin, Minhao, Apostolaki, Maria
Format: Preprint
Publié: 2026
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915983632891904
author Hè, Hongyu
Jin, Minhao
Apostolaki, Maria
author_facet Hè, Hongyu
Jin, Minhao
Apostolaki, Maria
contents RL-based controllers achieve strong average-case performance in networking tasks such as congestion control and adaptive bitrate streaming. Yet their performance can degrade severely under network conditions where strong performance is still achievable. Identifying such conditions and quantifying the resulting performance gap is intractable by enumeration, while the sequential and closed-loop nature of RL controllers makes formal verification methods impractical. We present ReGuard, a framework that discovers worst-case scenarios for a given RL controller and protects it against them at inference time without retraining. Discovery is formulated as a bilevel regret-maximization problem, which yields a certified lower bound on the worst-case performance gap. The discovered trajectories are then analyzed as counterfactuals and compiled into lightweight logic rules that intervene only when a risky state is detected, leaving the controller's behavior unchanged otherwise. We evaluate ReGuard across three RL-based network controllers: Pensieve, Sage, and Park. ReGuard discovers scenarios in which the controller's performance is 43$-$64% worse than what is achievable. ReGuard not only discovers gaps 57% to 6$\times$ larger than those found by the strongest baselines but also shrinks them by 79$-$85% via lightweight rule-based protection while preserving nominal performance. ReGuard's protection extends beyond the scenarios it discovers, improving performance across a wider range of network conditions.
format Preprint
id arxiv_https___arxiv_org_abs_2605_04373
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Worst-Case Discovery and Runtime Protection for RL-Based Network Controllers
Hè, Hongyu
Jin, Minhao
Apostolaki, Maria
Networking and Internet Architecture
Artificial Intelligence
Systems and Control
68M12, 68M15, 68T05, 68Q25, 68M20
C.2.2; I.2.6; C.4; C.2.6
RL-based controllers achieve strong average-case performance in networking tasks such as congestion control and adaptive bitrate streaming. Yet their performance can degrade severely under network conditions where strong performance is still achievable. Identifying such conditions and quantifying the resulting performance gap is intractable by enumeration, while the sequential and closed-loop nature of RL controllers makes formal verification methods impractical. We present ReGuard, a framework that discovers worst-case scenarios for a given RL controller and protects it against them at inference time without retraining. Discovery is formulated as a bilevel regret-maximization problem, which yields a certified lower bound on the worst-case performance gap. The discovered trajectories are then analyzed as counterfactuals and compiled into lightweight logic rules that intervene only when a risky state is detected, leaving the controller's behavior unchanged otherwise. We evaluate ReGuard across three RL-based network controllers: Pensieve, Sage, and Park. ReGuard discovers scenarios in which the controller's performance is 43$-$64% worse than what is achievable. ReGuard not only discovers gaps 57% to 6$\times$ larger than those found by the strongest baselines but also shrinks them by 79$-$85% via lightweight rule-based protection while preserving nominal performance. ReGuard's protection extends beyond the scenarios it discovers, improving performance across a wider range of network conditions.
title Worst-Case Discovery and Runtime Protection for RL-Based Network Controllers
topic Networking and Internet Architecture
Artificial Intelligence
Systems and Control
68M12, 68M15, 68T05, 68Q25, 68M20
C.2.2; I.2.6; C.4; C.2.6
url https://arxiv.org/abs/2605.04373