{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/detecting-adversarial-attacks-on-neural","title":"Detecting Adversarial Attacks on Neural Network Policies with Visual Foresight","arxiv_id":"1710.00814","date":"2017-10-02","proceeding":null,"authors":["Yen-Chen Lin","Ming-Yu Liu","Min Sun","Jia-Bin Huang"],"abstract":"Deep reinforcement learning has shown promising results in learning control\npolicies for complex sequential decision-making tasks. However, these neural\nnetwork-based policies are known to be vulnerable to adversarial examples. This\nvulnerability poses a potentially serious threat to safety-critical systems\nsuch as autonomous vehicles. In this paper, we propose a defense mechanism to\ndefend reinforcement learning agents from adversarial attacks by leveraging an\naction-conditioned frame prediction module. Our core idea is that the\nadversarial examples targeting at a neural network-based policy are not\neffective for the frame prediction model. By comparing the action distribution\nproduced by a policy from processing the current observed frame to the action\ndistribution produced by the same policy from processing the predicted frame\nfrom the action-conditioned frame prediction module, we can detect the presence\nof adversarial examples. Beyond detecting the presence of adversarial examples,\nour method allows the agent to continue performing the task using the predicted\nframe when the agent is under attack. We evaluate the performance of our\nalgorithm using five games in Atari 2600. Our results demonstrate that the\nproposed defense mechanism achieves favorable performance against baseline\nalgorithms in detecting adversarial examples and in earning rewards when the\nagents are under attack.","url_abs":"http://arxiv.org/abs/1710.00814v1","url_pdf":"http://arxiv.org/pdf/1710.00814v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"detecting-adversarial-attacks-on-neural","repo_url":"https://github.com/yenchenlin/rl-attack-detection","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"tf","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"detecting-adversarial-attacks-on-neural","repo_url":"https://github.com/ssg-research/flare","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"Apache-2.0"}}],"tasks":[{"task_slug":"autonomous-vehicles","task_name":"Autonomous Vehicles"},{"task_slug":"decision-making","task_name":"Decision Making"},{"task_slug":"deep-reinforcement-learning","task_name":"Deep Reinforcement Learning"},{"task_slug":"reinforcement-learning","task_name":"Reinforcement Learning"},{"task_slug":"reinforcement-learning-1","task_name":"Reinforcement Learning (RL)"},{"task_slug":"sequential-decision-making","task_name":"Sequential Decision Making"},{"task_slug":"reinforcement-learning-2","task_name":"reinforcement-learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1710.00814","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1710.00814"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ssg-research/flare","reach":{"status":"ok","spdx":"Apache-2.0"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/yenchenlin/rl-attack-detection","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"unverified":10},"by_repo_kind":{"official":{"samples":10,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":10,"samples":[{"code_sha256_prefix":"ab0fe214d7d0f41c","entry":"fixed_list_blobs","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/azure_utils.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/azure_utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"ab0fe214d7d0f41c"}},{"code_sha256_prefix":"b7d6a34e1010c8d3","entry":"get_wrapper_by_name","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/misc_util.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/misc_util.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"b7d6a34e1010c8d3"}},{"code_sha256_prefix":"5908b0de70ae8316","entry":"linear_interpolation","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/schedules.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/schedules.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"5908b0de70ae8316"}},{"code_sha256_prefix":"d463e1295ed34b3c","entry":"make_output_format","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/logger.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/logger.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"d463e1295ed34b3c"}},{"code_sha256_prefix":"3dc7f82ede7de679","entry":"mean","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/tf_util.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/tf_util.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"3dc7f82ede7de679"}},{"code_sha256_prefix":"131bfcd55d2d25cc","entry":"pickle_load","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/misc_util.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/misc_util.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"131bfcd55d2d25cc"}},{"code_sha256_prefix":"accf0e50708b4878","entry":"pretty_eta","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/misc_util.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/misc_util.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"accf0e50708b4878"}},{"code_sha256_prefix":"ec87a50ac64b9e20","entry":"sum","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/tf_util.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/tf_util.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"ec87a50ac64b9e20"}},{"code_sha256_prefix":"9071c058ed8fc811","entry":"var","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/tf_util.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/tf_util.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"9071c058ed8fc811"}},{"code_sha256_prefix":"bad6b483657393a5","entry":"wrap_dqn","repo":"yenchenlin/rl-attack-detection","repo_kind":"official","path":"baselines/common/atari_wrappers_deprecated.py","file_url":"https://github.com/yenchenlin/rl-attack-detection/blob/HEAD/baselines/common/atari_wrappers_deprecated.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":false,"mcp_get_code":{"code_sha256":"bad6b483657393a5"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}