Optimal Attack against Autoregressive Models by Manipulating the Environment
Yiding Chen, Xiaojin Zhu
Abstract
We describe an optimal adversarial attack formulation against autoregressive time series forecast using Linear Quadratic Regulator (LQR). In this threat model, the environment evolves according to a dynamical system; an autoregressive model observes the current environment state and predicts its future values; an attacker has the ability to modify the environment state in order to manipulate future autoregressive forecasts. The attacker's goal is to force autoregressive forecasts into tracking a target trajectory while minimizing its attack expenditure. In the white-box setting where the attacker knows the environment and forecast models, we present the optimal attack using LQR for linear models, and Model Predictive Control (MPC) for nonlinear models. In the black-box setting, we combine system identification and MPC. Experiments demonstrate the effectiveness of our attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db9afb43-82b3-40fc-acef-2435b05dfd3dCited by top-tier papers2
- Accumulative Poisoning Attacks on Real-time DataTianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su et al.NeurIPS 2021 · 25 citations
- Sequential Attacks on Kalman Filter-based Forward Collision Warning SystemsYuzhe Ma, Jon A. Sharp, Ruizhe Wang, Earlence Fernandes et al.AAAI 2021 · 14 citations
Related papers
- The Power of Predictions in Online ControlChenkai Yu, Guanya Shi, Soon-Jo Chung, Yisong Yue et al.NeurIPS 2020 · 88 citations
- Adversarial Attacks on Probabilistic Autoregressive Forecasting ModelsRaphaël Dang-Nhu, Gagandeep Singh, Pavol Bielik, Martin T. VechevICML 2020 · 28 citations
- Provably Efficient Black-Box Action Poisoning Attacks Against Reinforcement LearningGuanlin Liu, Lifeng LaiNeurIPS 2021 · 55 citations
- Policy Teaching via Environment Poisoning: Training-time Adversarial Attacks against Reinforcement LearningAmin Rakhsha, Goran Radanovic, Rati Devidze, Xiaojin Zhu et al.ICML 2020 · 145 citations
- Spatiotemporally Constrained Action Space Attacks on Deep Reinforcement Learning AgentsXian Yeow Lee, Sambit Ghadai, Kai Liang Tan, Chinmay Hegde et al.AAAI 2020 · 65 citations
