{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/real-time-attacks-against-deep-reinforcement","title":"Real-time Adversarial Perturbations against Deep Reinforcement Learning Policies: Attacks and Defenses","arxiv_id":"2106.08746","date":"2021-06-16","proceeding":null,"authors":["Buse G. A. Tekgul","Shelly Wang","Samuel Marchal","N. Asokan"],"abstract":"Deep reinforcement learning (DRL) is vulnerable to adversarial perturbations. Adversaries can mislead the policies of DRL agents by perturbing the state of the environment observed by the agents. Existing attacks are feasible in principle, but face challenges in practice, either by being too slow to fool DRL policies in real time or by modifying past observations stored in the agent's memory. We show that Universal Adversarial Perturbations (UAP), independent of the individual inputs to which they are applied, can fool DRL policies effectively and in real time. We introduce three attack variants leveraging UAP. Via an extensive evaluation using three Atari 2600 games, we show that our attacks are effective, as they fully degrade the performance of three different DRL agents (up to 100%, even when the $l_\\infty$ bound on the perturbation is as small as 0.01). It is faster than the frame rate (60 Hz) of image capture and considerably faster than prior attacks ($\\approx 1.8$ms). Our attack technique is also efficient, incurring an online computational cost of $\\approx 0.027$ms. Using two tasks involving robotic movement, we confirm that our results generalize to complex DRL tasks. Furthermore, we demonstrate that the effectiveness of known defenses diminishes against universal perturbations. We introduce an effective technique that detects all known adversarial perturbations against DRL policies, including all universal perturbations presented in this paper.","url_abs":"https://arxiv.org/abs/2106.08746v4","url_pdf":"https://arxiv.org/pdf/2106.08746v4.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"real-time-attacks-against-deep-reinforcement","repo_url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"Apache-2.0"}}],"tasks":[{"task_slug":"atari-games","task_name":"Atari Games"},{"task_slug":"deep-reinforcement-learning","task_name":"Deep Reinforcement Learning"},{"task_slug":"reinforcement-learning-1","task_name":"Reinforcement Learning (RL)"},{"task_slug":"reinforcement-learning-2","task_name":"reinforcement-learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2106.08746","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2106.08746"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector","reach":{"status":"ok","spdx":"Apache-2.0"}}],"summary":{"ran_draft_wrong":1,"unverified":4},"by_repo_kind":{"official":{"samples":5,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"9de355e93051e4ad","entry":"init","repo":"ssg-research/ad3-action-distribution-divergence-detector","repo_kind":"official","path":"src/agents/models.py","file_url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector/blob/HEAD/src/agents/models.py","link_basis":"harvester_set","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"9de355e93051e4ad"}},{"code_sha256_prefix":"4c0653e7958792a3","entry":"add_paddings","repo":"ssg-research/ad3-action-distribution-divergence-detector","repo_kind":"official","path":"src/detection_module/DetectionModule.py","file_url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector/blob/HEAD/src/detection_module/DetectionModule.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"4c0653e7958792a3"}},{"code_sha256_prefix":"4cadff05eab7dfcd","entry":"parse_key","repo":"ssg-research/ad3-action-distribution-divergence-detector","repo_kind":"official","path":"src/create_detection_script.py","file_url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector/blob/HEAD/src/create_detection_script.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"4cadff05eab7dfcd"}},{"code_sha256_prefix":"3ba7c8da77c3ab15","entry":"post_process","repo":"ssg-research/ad3-action-distribution-divergence-detector","repo_kind":"official","path":"src/agents/action_conditional_video_prediction.py","file_url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector/blob/HEAD/src/agents/action_conditional_video_prediction.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"3ba7c8da77c3ab15"}},{"code_sha256_prefix":"a39e3b63ff5b97d2","entry":"pre_process","repo":"ssg-research/ad3-action-distribution-divergence-detector","repo_kind":"official","path":"src/agents/action_conditional_video_prediction.py","file_url":"https://github.com/ssg-research/ad3-action-distribution-divergence-detector/blob/HEAD/src/agents/action_conditional_video_prediction.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"Apache-2.0","inline_ok":true,"mcp_get_code":{"code_sha256":"a39e3b63ff5b97d2"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}