Goto

Collaborating Authors

 Agents




f0eb6568ea114ba6e293f903c34d7488-Paper.pdf

Neural Information Processing Systems

Several works haveshown this vulnerability via adversarial attacks, butexisting approaches onimproving therobustness ofDRL under this setting have limited success and lack for theoretical principles. We show that naively applying existing techniques on improving robustness for classification tasks,likeadversarialtraining,areineffectiveformanyRLtasks.


c3e0c62ee91db8dc7382bde7419bb573-Supplemental.pdf

Neural Information Processing Systems

Theactiveagent trains (as a regular Double-DQN) up to the time of forking, at which point the passive agent is created asa'fork' (i.e.,with identical networkweights) oftheactiveagent.






Adversarially Robust Decision Transformer

Neural Information Processing Systems

However, in adversarial environments, these methods can be non-robust, since the return is dependent on the strategies of both the decision-maker and adversary. Training a probabilistic model conditioned on observed return to predict action can fail to generalize, as the trajectories that achieve a return in the dataset might have done so due to a suboptimal behavior adversary.