TY - GEN
T1 - Zero-One Attack
T2 - 15th Annual ACM/IEEE International Conference on Cyber-Physical Systems, ICCPS 2024
AU - Bak, Stanley
AU - Bogomolov, Sergiy
AU - Hekal, Abdelrahman
AU - Krish, Veena
AU - Mata, Andrew
AU - Rahmati, Amir
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - Autonomous cyber-physical systems with deep-learning components have shown great promise but have so far enjoyed limited adoption. Part of the problem is that, beyond average-case analysis, guaranteeing robustness and reasoning about worst-case behaviors in these systems is difficult. Previous research has developed attacks that can degrade a system's performance using small perturbations on observed states, as well as ways to retrain the networks that appear to make them robust to such attacks. In this work, we advance the state of the art by developing a new method called the Zero-One Attack, which is able to bypass the current strongest defense.The Zero-One Attack minimizes reward by combining an outer loop zeroth-order gradient-free optimization with an inner loop, first-order gradient-based method. This setup both reduces the dimensionality of the zeroth-order optimization problem and leverages efficient gradient-based search methods for neural networks, such as projected gradient descent. In addition to state observation noise, we consider a new attack model with bounded perturbations to the execution time instant of the control policy, as real-time schedulers usually guarantee execution once per period, which may not be strictly periodic. On the Mujoco Half Cheetah system with the best current defense, the Zero-One Attack degrades the performance 195% beyond the state-of-the-art, which increases to 522% more degradation when also attacking timing jitter.
AB - Autonomous cyber-physical systems with deep-learning components have shown great promise but have so far enjoyed limited adoption. Part of the problem is that, beyond average-case analysis, guaranteeing robustness and reasoning about worst-case behaviors in these systems is difficult. Previous research has developed attacks that can degrade a system's performance using small perturbations on observed states, as well as ways to retrain the networks that appear to make them robust to such attacks. In this work, we advance the state of the art by developing a new method called the Zero-One Attack, which is able to bypass the current strongest defense.The Zero-One Attack minimizes reward by combining an outer loop zeroth-order gradient-free optimization with an inner loop, first-order gradient-based method. This setup both reduces the dimensionality of the zeroth-order optimization problem and leverages efficient gradient-based search methods for neural networks, such as projected gradient descent. In addition to state observation noise, we consider a new attack model with bounded perturbations to the execution time instant of the control policy, as real-time schedulers usually guarantee execution once per period, which may not be strictly periodic. On the Mujoco Half Cheetah system with the best current defense, the Zero-One Attack degrades the performance 195% beyond the state-of-the-art, which increases to 522% more degradation when also attacking timing jitter.
KW - CPS
KW - deep-learning
KW - optimization
KW - sensor noise
UR - https://www.scopus.com/pages/publications/85198521413
U2 - 10.1109/ICCPS61052.2024.00008
DO - 10.1109/ICCPS61052.2024.00008
M3 - Conference contribution
AN - SCOPUS:85198521413
T3 - Proceedings - 15th ACM/IEEE International Conference on Cyber-Physical Systems, ICCPS 2024
SP - 12
EP - 22
BT - Proceedings - 15th ACM/IEEE International Conference on Cyber-Physical Systems, ICCPS 2024
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 13 May 2024 through 16 May 2024
ER -