Fetching the paper…
Reading the bibliography…
This paper presents the first model extraction attack against Deep Reinforcement Learning (DRL), which enables an external adversary to precisely recover a black-box DRL model only from its interaction with the environment.
Asynchronous methods for deep reinforcement learning. In International Conference on Machine Learning . 1928–1937
Volodymyr Mnih, Adria Puigdomenech Badia, Mehdi Mirza, Alex Graves, Timothy Lillicrap, Tim Harley, David Silver, and Koray Kavukcuoglu. 2016 · 1937
Earlier work this paper cites.
Divergence measures based on the Shannon entropy
Jianhua Lin. 1991 · 1991
Earlier work this paper cites.
Simple statistical gradient-following algorithms for connectionist reinforcement learning
Ronald J Williams. 1992 · 1992
Earlier work this paper cites.
Long short-term memory
Sepp Hochreiter and Jürgen Schmidhuber. 1997 · 1997
Earlier work this paper cites.
A survey of POMDP applications. In Working notes of AAAI 1998 Fall Symposium on Planning with Partially Observable Markov Decision Processes , Vol. 1724
Anthony R Cassandra. 1998 · 1998
Earlier work this paper cites.
Learning agents for uncertain environments. In Annual Conference on Computational Learning Theory . 101–103
Stuart Russell. 1998 · 1998
Earlier work this paper cites.
Autonomous inverted helicopter flight via reinforcement learning
Andrew Y Ng, Adam Coates, Mark Diel, Varun Ganapathi, Jamie Schulte, Ben Tse, Eric Berger, and Eric Liang. 2006 · 2006
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013 · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014 · 2014
Earlier work this paper cites.
Continuous control with deep reinforcement learning
Timothy P Lillicrap, Jonathan J Hunt, Alexander Pritzel, Nicolas Heess, Tom Erez, Yuval Tassa, David Silver, and Daan Wierstra. 2015 · 2015
Earlier work this paper cites.
Human-level control through deep reinforcement learning
Volodymyr Mnih, Koray Kavukcuoglu, David Silver, Andrei A Rusu, Joel Veness, Marc G Bellemare, Alex Graves, Martin Riedmiller, Andreas K Fidjeland, Georg Ostrovski, et al · 2015
Earlier work this paper cites.
Guided cost learning: Deep inverse optimal control via policy optimization. In International Conference on Machine Learning . 49–58
Chelsea Finn, Sergey Levine, and Pieter Abbeel. 2016 · 2016
Earlier work this paper cites.
Generative adversarial imitation learning. In Advances in Neural Information Processing Systems . 4565–4573
Jonathan Ho and Stefano Ermon. 2016 · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings. In IEEE European Symposium on Security and Privacy . 372–387
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016 · 2016
Earlier work this paper cites.
"Why should I trust you?": Explaining the predictions of any classifier. In ACM SIGKDD International Conference on Knowledge Discovery and Data Mining . 1135–1144
Marco Tulio Ribeiro, Sameer Singh, and Carlos Guestrin. 2016 · 2016
Earlier work this paper cites.
Mastering the game of Go with deep neural networks and tree search
David Silver, Aja Huang, Chris J Maddison, Arthur Guez, Laurent Sifre, George Van Den Driessche, Julian Schrittwieser, Ioannis Antonoglou, Veda Panneershelvam, Marc Lanctot, et al · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction apis. In USENIX Security Symposium . 601–618
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016 · 2016
Earlier work this paper cites.
Sample efficient actor-critic with experience replay
Ziyu Wang, Victor Bapst, Nicolas Heess, Volodymyr Mnih, Remi Munos, Koray Kavukcuoglu, and Nando de Freitas. 2016 · 2016
Earlier work this paper cites.
Vulnerability of deep reinforcement learning to policy induction attacks. In International Conference on Machine Learning and Data Mining in Pattern Recognition . 262–275
Vahid Behzadan and Arslan Munir. 2017 · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks. In IEEE Symposium on Security and Privacy . 39–57
Nicholas Carlini and David Wagner. 2017 · 2017
Cited alongside, same era.
OpenAI Baselines
Prafulla Dhariwal, Christopher Hesse, Oleg Klimov, Alex Nichol, Matthias Plappert, Alec Radford, John Schulman, Szymon Sidor, Yuhuai Wu, and Peter Zhokhov. 2017 · 2017
Cited alongside, same era.
Adversarial attacks on neural network policies
Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel. 2017 · 2017
Cited alongside, same era.
Imitation learning: A survey of learning methods
Ahmed Hussein, Mohamed Medhat Gaber, Eyad Elyan, and Chrisina Jayne. 2017 · 2017
Cited alongside, same era.
Protecting intellectual property of deep neural networks with watermarking. In Asia Conference on Computer and Communications Security . 159–172
Jialong Zhang, Zhongshu Gu, Jiyong Jang, Hui Wu, Marc Ph Stoecklin, Heqing Huang, and Ian Molloy. 2018 · 2018
Later among the works it cites.
CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel. In USENIX Security Symposium . 515–532
Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019 · 2019
Later among the works it cites.
Sequential triggers for watermarking of deep reinforcement learning policies
Vahid Behzadan and William Hsu. 2019 · 2019
Later among the works it cites.
PRADA: protecting against DNN model stealing attacks. In IEEE European Symposium on Security and Privacy . 512–527
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N Asokan. 2019 · 2019
Later among the works it cites.
Modeling Human Behavior in Space Invaders
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Proximal policy optimization algorithms
John Schulman, Filip Wolski, Prafulla Dhariwal, Alec Radford, and Oleg Klimov. 2017 · 2017
Cited alongside, same era.
Embedding watermarks into deep neural networks. In International Conference on Multimedia Retrieval . 269–277
Yusuke Uchida, Yuki Nagai, Shigeyuki Sakazawa, and Shin’ichi Satoh. 2017 · 2017
Cited alongside, same era.
Scalable trust-region method for deep reinforcement learning using kronecker-factored approximation. In Advances in Neural Information Processing Systems . 5279–5288
Yuhuai Wu, Elman Mansimov, Roger B Grosse, Shun Liao, and Jimmy Ba. 2017 · 2017
Cited alongside, same era.
Target-driven visual navigation in indoor scenes using deep reinforcement learning. In IEEE International Conference on Robotics and Automation . 3357–3364
Yuke Zhu, Roozbeh Mottaghi, Eric Kolve, Joseph J Lim, Abhinav Gupta, Li Fei-Fei, and Ali Farhadi. 2017 · 2017
Cited alongside, same era.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In USENIX Security Symposium . 1615–1631
Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018 · 2018
Cited alongside, same era.
Exploring connections between active learning and model extraction
Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2018 · 2018
Cited alongside, same era.
Copycat CNN: Stealing knowledge by persuading confession with random non-labeled data. In International Joint Conference on Neural Networks . 1–8
Jacson Rodrigues Correia-Silva, Rodrigo F Berriel, Claudine Badue, Alberto F de Souza, and Thiago Oliveira-Santos. 2018 · 2018
Cited alongside, same era.
James Lennon. 2019 · 2019
Later among the works it cites.
Model reconstruction from model explanations. In The Conference on Fairness, Accountability, and Transparency . 1–9
Smitha Milli, Ludwig Schmidt, Anca D Dragan, and Moritz Hardt. 2019 · 2019
Later among the works it cites.
Towards reverse-engineering black-box neural networks
Seong Joon Oh, Bernt Schiele, and Mario Fritz. 2019 · 2019
Later among the works it cites.
Knockoff nets: Stealing functionality of black-box models. In IEEE Conference on Computer Vision and Pattern Recognition . 4954–4963
Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2019 · 2019
Later among the works it cites.
A framework for the extraction of deep neural networks by leveraging public data
Soham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade, Shirish Shevade, and Vinod Ganapathy. 2019 · 2019
Later among the works it cites.
Characterizing attacks on deep reinforcement learning
Chaowei Xiao, Xinlei Pan, Warren He, Jian Peng, Mingjie Sun, Jinfeng Yi, Mingyan Liu, Bo Li, and Dawn Song. 2019 · 2019
Later among the works it cites.
Improving transferability of adversarial examples with input diversity. In IEEE Conference on Computer Vision and Pattern Recognition . 2730–2739
Cihang Xie, Zhishuai Zhang, Yuyin Zhou, Song Bai, Jianyu Wang, Zhou Ren, and Alan L Yuille. 2019 · 2019
Later among the works it cites.
Safe, multi-agent, reinforcement learning for autonomous driving
2020 · 2020
Closest in time.
Learning to drive in a day
JUNE 2018 · 2020
Closest in time.
Cryptanalytic Extraction of Neural Network Models
Nicholas Carlini, Matthew Jagielski, and Ilya Mironov. 2020 · 2020
Closest in time.
DeepSniffer: A DNN Model Extraction Framework Based on Learning Architectural Hints. In International Conference on Architectural Support for Programming Languages and Operating Systems . 385–399
Xing Hu, Ling Liang, Shuangchen Li, Lei Deng, Pengfei Zuo, Yu Ji, Xinfeng Xie, Yufei Ding, Chang Liu, Timothy Sherwood, et al · 2020
Closest in time.
High accuracy and high fidelity extraction of neural networks. In USENIX Security Symposium
Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot. 2020 · 2020
Closest in time.
CloudLeak: Large-scale deep learning models stealing through adversarial examples. In Network and Distributed Systems Security Symposium
Honggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai, Tsung-Yi Ho, and Yier Jin. 2020 · 2020
Closest in time.