{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-policies-attacking-deep","title":"Adversarial Policies: Attacking Deep Reinforcement Learning","arxiv_id":"1905.10615","date":"2019-05-25","proceeding":"ICLR 2020 1","authors":["Adam Gleave","Michael Dennis","Cody Wild","Neel Kant","Sergey Levine","Stuart Russell"],"abstract":"Deep reinforcement learning (RL) policies are known to be vulnerable to adversarial perturbations to their observations, similar to adversarial examples for classifiers. However, an attacker is not usually able to directly modify another agent's observations. This might lead one to wonder: is it possible to attack an RL agent simply by choosing an adversarial policy acting in a multi-agent environment so as to create natural observations that are adversarial? We demonstrate the existence of adversarial policies in zero-sum games between simulated humanoid robots with proprioceptive observations, against state-of-the-art victims trained via self-play to be robust to opponents. The adversarial policies reliably win against the victims but generate seemingly random and uncoordinated behavior. We find that these policies are more successful in high-dimensional environments, and induce substantially different activations in the victim policy network than when the victim plays against a normal opponent. Videos are available at https://adversarialpolicies.github.io/.","url_abs":"https://arxiv.org/abs/1905.10615v3","url_pdf":"https://arxiv.org/pdf/1905.10615v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-policies-attacking-deep","repo_url":"https://github.com/HumanCompatibleAI/adversarial-policies","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"adversarial-policies-attacking-deep","repo_url":"https://github.com/dig-beihang/ami","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"Apache-2.0"}}],"tasks":[{"task_slug":"deep-reinforcement-learning","task_name":"Deep Reinforcement Learning"},{"task_slug":"reinforcement-learning","task_name":"Reinforcement Learning"},{"task_slug":"reinforcement-learning-1","task_name":"Reinforcement Learning (RL)"},{"task_slug":"reinforcement-learning-2","task_name":"reinforcement-learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1905.10615","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.10615"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/dig-beihang/ami","reach":{"status":"ok","spdx":"Apache-2.0"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/HumanCompatibleAI/adversarial-policies","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"unverified":5},"by_repo_kind":{"official":{"samples":5,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"4768901f0d6fe343","entry":"fit_ilqr","repo":"HumanCompatibleAI/adversarial-policies","repo_kind":"official","path":"experiments/planning/common.py","file_url":"https://github.com/HumanCompatibleAI/adversarial-policies/blob/HEAD/experiments/planning/common.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4768901f0d6fe343"}},{"code_sha256_prefix":"f3743f2ade53f538","entry":"get_final_model_path","repo":"HumanCompatibleAI/adversarial-policies","repo_kind":"official","path":"experiments/modelfree/highest_win_rate.py","file_url":"https://github.com/HumanCompatibleAI/adversarial-policies/blob/HEAD/experiments/modelfree/highest_win_rate.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"f3743f2ade53f538"}},{"code_sha256_prefix":"dac80b76cdcac1d3","entry":"get_sacred_config","repo":"HumanCompatibleAI/adversarial-policies","repo_kind":"official","path":"experiments/modelfree/highest_win_rate.py","file_url":"https://github.com/HumanCompatibleAI/adversarial-policies/blob/HEAD/experiments/modelfree/highest_win_rate.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"dac80b76cdcac1d3"}},{"code_sha256_prefix":"aca06d84ed47ac80","entry":"get_stats","repo":"HumanCompatibleAI/adversarial-policies","repo_kind":"official","path":"experiments/modelfree/highest_win_rate.py","file_url":"https://github.com/HumanCompatibleAI/adversarial-policies/blob/HEAD/experiments/modelfree/highest_win_rate.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"aca06d84ed47ac80"}},{"code_sha256_prefix":"821d38fa42efe55c","entry":"make_env","repo":"HumanCompatibleAI/adversarial-policies","repo_kind":"official","path":"experiments/planning/common.py","file_url":"https://github.com/HumanCompatibleAI/adversarial-policies/blob/HEAD/experiments/planning/common.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"821d38fa42efe55c"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}