Grey-box Adversarial Attack on Communication in Multi-agent Reinforcement Learning

Xiao Ma,Wu-Jun Li
2023-01-01
Abstract:Although research on communication in multi-agent reinforcement learning~(MARL) has achieved some progress, the vulnerability of the communication mechanism in MARL caused by adversarial communication messages generated by malicious agents has not been well investigated. Existing works about adversarial communication messages in MARL focus on the black-box scenario where the attacker cannot access any model information about the multi-agent system (MAS). But a more practical setting is the grey-box scenario where the attacker can access the model information about its controlled agent. To the best of our knowledge, there has not been any work investigating grey-box attacks on communication in MARL. In this paper, we propose the first grey-box attack method on communication in MARL, which is called victim-simulation based adversarial attack (VSA). At each timestep, the attacker simulates a victim attacked by other regular agents' communication messages and generates adversarial perturbations on its received communication messages. The aggregation of these perturbations is sent by the attacker to the regular agents through communication messages, which will induce non-optimal actions of the regular agents. Experimental results show that VSA can effectively degrade the performance of the MAS on Predator-Prey. The findings in this paper will make researchers aware of the grey-box attack in MARL.
What problem does this paper attempt to address?