Deep Reinforcement Learning for Adversarial Perturbation in RNNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems that utilize recurrent neural networks (RNNs) for processing sequence-based data are vulnerable to adversarial perturbations, which require expert tuning and are not conducive to online attacks, as they rely on hand-engineered attack sizes and iterative methods that are not effective for real-time systems.

Innovation Solution

A deep reinforcement learning-based attack system that generates perturbations by training a reinforcement learning agent to determine the magnitude and timing of attacks on RNNs, using a computer program to produce perturbed input signals that alter the system's output, thereby identifying failure modes and improving attack strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hand-engineered attack sizes and iterative methods are used, then attack effectiveness is achieved, but the system cannot be applied to online real-time attacks

Engineering Contradiction:
Improveattack effectivenessVSAvoidonline applicability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical iterative attack process with a reinforcement learning agent that learns attack strategies through interaction with the RNN system. The RL agent substitutes the traditional hand-engineered iterative approach, enabling real-time online attacks by learning optimal perturbation strategies without requiring multiple iterative passes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The reinforcement learning agent autonomously learns and optimizes attack strategies through self-interaction with the target RNN system. The agent receives rewards based on attack success and automatically improves its perturbation generation capability, eliminating the need for external expert tuning and enabling adaptive online attacks.

Inventive Principle:
Principle #25Self-service

2Manufacturing precision

If expert tuning via experimentation is used, then attack parameters are optimized, but the process requires significant time and manual intervention

Engineering Contradiction:
Improveattack parameter optimizationVSAvoidtuning time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The reinforcement learning agent performs self-tuning by autonomously learning optimal attack parameters through interaction with the target system. The agent automatically adjusts perturbation magnitudes, timings, and patterns based on observed system responses and reward signals, eliminating the need for manual expert experimentation and dramatically reducing tuning time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the reinforcement learning agent receives reward signals based on attack success metrics. This feedback loop enables the agent to continuously learn and optimize attack parameters, automatically adapting to the target RNN system's behavior without requiring manual intervention or extensive experimentation.

Inventive Principle:
Principle #23Feedback

3Reliability

If iterative attacks are used, then attack thoroughness is achieved, but the method is not conducive to attacking time series RNN online

Engineering Contradiction:
Improveattack thoroughnessVSAvoidonline attack speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the iterative attack mechanism with a reinforcement learning-based approach that learns attack strategies through environmental interaction. The RL agent achieves thorough attack coverage by exploring the state space and learning optimal policies, while maintaining online attack capability through efficient learning algorithms that do not require multiple iterative passes over the data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12073318B2Deep reinforcement learning based method for surreptitiously generating signals to fool a recurrent neural network
Publication Date: 2024.08.27 HRL LAB
  • US12073318B2 patent drawing
  • US12073318B2 patent drawing
  • US12073318B2 patent drawing

AI summary

Described is an attack system for generating perturbations of input signals in a recurrent neural network (RNN) based target system using a deep reinforcement learning agent to generate the perturbations. The attack system trains a reinforcement learning agent to determine a magnitude of a perturbation with which to attack the RNN based target system. A perturbed input sensor signal having the determined magnitude is generated and presented to the RNN based target system such that the RNN based target system produces an altered output in response to the perturbed input sensor signal. The system identifies a failure mode of the RNN based target system using the altered output.