kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Korkmaz, Ezgi
Publications (2 of 2) Show all publications
Korkmaz, E. (2021). Inaccuracy of State-Action Value Function For Non-Optimal Actions in Adversarially Trained Deep Neural Policies. In: 2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGITION WORKSHOPS (CVPRW 2021): . Paper presented at IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), JUN 19-25, 2021, ELECTR NETWORK (pp. 2323-2327). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Inaccuracy of State-Action Value Function For Non-Optimal Actions in Adversarially Trained Deep Neural Policies
2021 (English)In: 2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGITION WORKSHOPS (CVPRW 2021), Institute of Electrical and Electronics Engineers (IEEE) , 2021, p. 2323-2327Conference paper, Published paper (Refereed)
Abstract [en]

The introduction of deep neural networks as function approximator for the state-action value function has led to the creation of a new research area for self-learning systems that explore policies from high dimensional input. While the success of deep neural policies has resulted in the deployment of these policies in diversified application domains, there are significant concerns regarding their robustness towards specifically crafted malicious perturbations introduced to their inputs. Several studies have focused on making deep neural policies resistant to such perturbations via training with the existence of these perturbations (i.e. adversarial training). In this paper we focus on conducting an investigation on the state-action value function learned by state-of-the-art adversarially trained deep neural policies and vanilla trained deep neural policies. We perform several experiments in the OpenAI Baselines and we show that the state-action value functions learned by vanilla trained deep neural policies have better estimates for the non-optimal actions than the state-of-the-art adversarially trained deep neural policies. We believe our study lays out intriguing properties of adversarial training and could be critical step towards obtaining robust and reliable policies.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2021
Series
IEEE Computer Society Conference on Computer Vision and Pattern Recognition Workshops, ISSN 2160-7508
National Category
Computer graphics and computer vision Computer Sciences
Identifiers
urn:nbn:se:kth:diva-305085 (URN)10.1109/CVPRW53098.2021.00264 (DOI)000705890202049 ()2-s2.0-85114695534 (Scopus ID)
Conference
IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), JUN 19-25, 2021, ELECTR NETWORK
Note

Part of proceedings: ISBN 978-1-6654-4899-4, QC 20230117

Available from: 2021-11-23 Created: 2021-11-23 Last updated: 2025-02-01Bibliographically approved
Korkmaz, E. (2021). Investigating Vulnerabilities of Deep Neural Policies. In: 37th Conference on Uncertainty in Artificial Intelligence, UAI 2021: . Paper presented at 37th Conference on Uncertainty in Artificial Intelligence, UAI 2021, Virtual Online, 27-30 July 2021 (pp. 1661-1670). Association For Uncertainty in Artificial Intelligence (AUAI)
Open this publication in new window or tab >>Investigating Vulnerabilities of Deep Neural Policies
2021 (English)In: 37th Conference on Uncertainty in Artificial Intelligence, UAI 2021, Association For Uncertainty in Artificial Intelligence (AUAI) , 2021, p. 1661-1670Conference paper, Published paper (Refereed)
Abstract [en]

Reinforcement learning policies based on deep neural networks are vulnerable to imperceptible adversarial perturbations to their inputs, in much the same way as neural network image classifiers. Recent work has proposed several methods to improve the robustness of deep reinforcement learning agents to adversarial perturbations based on training in the presence of these imperceptible perturbations (i.e. adversarial training). In this paper, we study the effects of adversarial training on the neural policy learned by the agent. In particular, we follow two distinct parallel approaches to investigate the outcomes of adversarial training on deep neural policies based on worst-case distributional shift and feature sensitivity. For the first approach, we compare the Fourier spectrum of minimal perturbations computed for both adversarially trained and vanilla trained neural policies. Via experiments in the OpenAI Atari environments we show that minimal perturbations computed for adversarially trained policies are more focused on lower frequencies in the Fourier domain, indicating a higher sensitivity of these policies to low frequency perturbations. For the second approach, we propose a novel method to measure the feature sensitivities of deep neural policies and we compare these feature sensitivity differences in state-of-the-art adversarially trained deep neural policies and vanilla trained deep neural policies. We believe our results can be an initial step towards understanding the relationship between adversarial training and different notions of robustness for neural policies. 

Place, publisher, year, edition, pages
Association For Uncertainty in Artificial Intelligence (AUAI), 2021
Keywords
Deep neural networks, Feature sensitivity, Fourier spectra, Fourier-domain, High sensitivity, Image Classifiers, Lower frequencies, Neural-networks, Policy-based, Reinforcement learning agent, Shift-and, Reinforcement learning
National Category
Physiology and Anatomy
Identifiers
urn:nbn:se:kth:diva-317513 (URN)2-s2.0-85121686550 (Scopus ID)
Conference
37th Conference on Uncertainty in Artificial Intelligence, UAI 2021, Virtual Online, 27-30 July 2021
Note

Duplicate in Scopus 2-s2.0-85163377135

QC 20220914

Available from: 2022-09-14 Created: 2022-09-14 Last updated: 2025-02-10Bibliographically approved
Organisations

Search in DiVA

Show all publications