Adversarial Attacks on Gaussian Process Bandits
Eric Han, Jonathan Scarlett
摘要
Gaussian processes (GP) are a widely-adopted tool used to sequentially optimize black-box functions, where evaluations are costly and potentially noisy. Recent works on GP bandits have proposed to move beyond random noise and devise algorithms robust to adversarial attacks . This paper studies this problem from the attacker’s perspective, proposing various adversarial attack methods with differing assumptions on the attacker’s strength and prior information. Our goal is to understand adversarial attacks on GP bandits from theoretical and practical perspectives. We focus primarily on targeted attacks on the popular GP-UCB algorithm and a related elimination-based algorithm, based on adversarially perturbing the function f to produce another function ˜ f whose optima are in some target region R target . Based on our theoretical analysis, we devise both white-box attacks (known f ) and black-box attacks (unknown f ), with the former including a Subtraction attack and Clipping attack, and the latter including an Aggressive subtraction attack. We demonstrate that adversarial attacks on GP bandits can succeed in forcing the algorithm towards R target even with a low attack budget, and we test our attacks’ effectiveness on a diverse range of objective functions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- A Robust Phased Elimination Algorithm for Corruption-Tolerant Gaussian Process BanditsIlija Bogunovic, Zihan Li, Andreas Krause, Jonathan ScarlettNeurIPS 2022 · 被引用 13 次
- Robust Neural Contextual Bandit against Adversarial CorruptionsYunzhe Qi, Yikun Ban, Arindam Banerjee, Jingrui HeNeurIPS 2024 · 被引用 7 次
它引用的顶会 Paper3
- Adversarial Attacks on Linear Contextual BanditsEvrard Garcelon, Baptiste Rozière, Laurent Meunier, Jean Tarbouriech 等NeurIPS 2020 · 被引用 60 次
- On Lower Bounds for Standard and Robust Gaussian Process Bandit OptimizationXu Cai, Jonathan ScarlettICML 2021 · 被引用 32 次
- Lenient Regret and Good-Action Identification in Gaussian Process BanditsXu Cai, Selwyn Gomes, Jonathan ScarlettICML 2021 · 被引用 12 次
相关 Paper
- Gaussian Process Upper Confidence Bound Achieves Nearly-Optimal Regret in Noise-Free Gaussian Process BanditsShogo IwazakiNeurIPS 2025 · 被引用 10 次
- Misspecified Gaussian Process Bandit OptimizationIlija Bogunovic, Andreas KrauseNeurIPS 2021 · 被引用 69 次
- Robust Bayesian Optimisation with Unbounded CorruptionsAbdelhamid Ezzerg, Ilija Bogunovic, Jeremias KnoblauchICML 2026 · 被引用 1 次
- When Are Linear Stochastic Bandits Attackable?Huazheng Wang, Haifeng Xu, Hongning WangICML 2022 · 被引用 13 次
- Near-linear time Gaussian process optimization with adaptive batching and resparsificationDaniele Calandriello, Luigi Carratino, Alessandro Lazaric, Michal Valko 等ICML 2020 · 被引用 23 次
