Skip to main navigation Skip to search Skip to main content

Policy Extraction-Based Adversarial Attack in Multi-Agent Reinforcement Learning

  • Bang Zhang
  • , Wenjian Luo*
  • , Kesheng Chen
  • , Yujiang Liu
  • , Shuhan Qi
  • , Xuan Wang
  • *Corresponding author for this work
  • Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Multi-Agent Reinforcement Learning (MARL) has achieved remarkable progress across diverse domains. Nevertheless, MARL-trained agents remain vulnerable to adversarial perturbations on their observations, which can severely degrade the overall team performance. In reality, it is hard to perform adversarial attacks on the agent team when the models and datasets of agents are unreachable by attackers. In this paper, we introduce the policy extraction-based adversarial attack in MARL, which provides methods for building substitute models to attack the agent team. We firstly collect the data of the victim agent by only observing its behaviors, and then train the substitute policy model with the collected dataset and multiple data augmentation methods. Finally, we perform a newly designed optimization-based black box adversarial attack on the victim agent with the stolen policy model. We conduct experiments on SMAC environments to carefully test the performance of the substitute policy models and attack effects of adversarial attacks. Experiment results demonstrate that our method could successfully change the actions of the agent in the agent team trained by QMIX algorithm in a black box environment.

Original languageEnglish
Title of host publicationAdvanced Intelligent Computing Technology and Applications - 22nd International Conference on Intelligent Computing, ICIC 2026, Proceedings
EditorsDe-Shuang Huang, Qinhu Zhang, Yijie Pan, Chuanlei Zhang, Wei Chen, Bo Li, Wenzheng Bao, Prashan Premaratne
PublisherSpringer Science and Business Media Deutschland GmbH
Pages316-331
Number of pages16
ISBN (Print)9789819233809
DOIs
StatePublished - 2027
Externally publishedYes
Event22nd International Conference on Intelligent Computing, ICIC 2026 - Toronto, Canada
Duration: 22 Jul 202626 Jul 2026

Publication series

NameLecture Notes in Computer Science
Volume16643 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference22nd International Conference on Intelligent Computing, ICIC 2026
Country/TerritoryCanada
CityToronto
Period22/07/2626/07/26

Keywords

  • Adversarial Attack
  • Multi-Agent Reinforcement Learning
  • Policy Extract

Fingerprint

Dive into the research topics of 'Policy Extraction-Based Adversarial Attack in Multi-Agent Reinforcement Learning'. Together they form a unique fingerprint.

Cite this