{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T21:02:21Z","timestamp":1784408541753,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":41,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819233809","type":"print"},{"value":"9789819233816","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-3381-6_26","type":"book-chapter","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T20:14:47Z","timestamp":1784405687000},"page":"316-331","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Policy Extraction-Based Adversarial Attack in Multi-Agent Reinforcement Learning"],"prefix":"10.1007","author":[{"given":"Bang","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenjian","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kesheng","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yujiang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shuhan","family":"Qi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,19]]},"reference":[{"key":"26_CR1","first-page":"1","volume-title":"2019 IEEE International Conference on Communications Workshops (ICC Workshops)","author":"J Cui","year":"2019","unstructured":"Cui, J., Liu, Y., Nallanathan, A.: The application of multi-agent reinforcement learning in UAV networks. In: 2019 IEEE International Conference on Communications Workshops (ICC Workshops), pp. 1\u20136. IEEE (2019)"},{"issue":"2","key":"26_CR2","doi-asserted-by":"publisher","first-page":"729","DOI":"10.1109\/TWC.2019.2935201","volume":"19","author":"J Cui","year":"2019","unstructured":"Cui, J., Liu, Y., Nallanathan, A.: Multi-agent reinforcement learning-based resource allocation for uav networks. IEEE Trans. Wirel. Commun. 19(2), 729\u2013743 (2019)","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"26_CR3","unstructured":"S. Shalev-Shwartz, S. Shammah, and A. Shashua, Safe, multi-agent, reinforcement learning for autonomous driving, arXiv preprint https:\/\/arxiv.org\/abs\/1610.03295, 2016"},{"issue":"3","key":"26_CR4","doi-asserted-by":"publisher","first-page":"1086","DOI":"10.1109\/TITS.2019.2901791","volume":"21","author":"T Chu","year":"2019","unstructured":"Chu, T., Wang, J., Codec\u00e0, L., Li, Z.: Multi-agent deep reinforcement learning for large-scale traffic signal control. IEEE Trans. Intell. Transp. Syst. 21(3), 1086\u20131095 (2019)","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"26_CR5","doi-asserted-by":"crossref","unstructured":"V. Behzadan and W. Hsu, Rl-based method for benchmarking the adversarial resilience and robustness of deep reinforcement learning policies. In: Computer Safety, Reliability, and Security: SAFECOMP 2019 Workshops, ASSURE, DECSoS, SASSUR, STRIVE, and WAISE, Turku, Finland, September 10, 2019, Proceedings 38. Springer, 2019, pp. 314\u2013325","DOI":"10.1007\/978-3-030-26250-1_25"},{"key":"26_CR6","unstructured":"A. Gleave, M. Dennis, C. Wild, N. Kant, S. Levine, and S. Russell, Adversarial policies: attacking deep reinforcement learning, arXiv preprint https:\/\/arxiv.org\/abs\/1905.10615, 2019."},{"key":"26_CR7","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1109\/SPW50608.2020.00027","volume-title":"2020 IEEE Security and Privacy Workshops (SPW)","author":"J Lin","year":"2020","unstructured":"Lin, J., Dzeparoska, K., Zhang, S.Q., Leon-Garcia, A., Papernot, N.: On the robustness of cooperative multi-agent reinforcement learning. In: 2020 IEEE Security and Privacy Workshops (SPW), pp. 62\u201368. IEEE (2020)"},{"key":"26_CR8","doi-asserted-by":"crossref","unstructured":"J. Guo, Y. Chen, Y. Hao, Z. Yin, Y. Yu, and S. Li, Towards comprehensive testing on the robustness of cooperative multi-agent reinforcement learning. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, 2022, pp. 115\u2013122","DOI":"10.1109\/CVPRW56347.2022.00022"},{"key":"26_CR9","unstructured":"Y. Hu and Z. Zhang, Sparse adversarial attack in multi-agent reinforcement learning, arXiv preprint https:\/\/arxiv.org\/abs\/2205.09362, 2022"},{"key":"26_CR10","doi-asserted-by":"crossref","unstructured":"Z. Zhou and G. Liu, Robustness testing for multi-agent reinforcement learning: state perturbations on critical agents, arXiv preprint https:\/\/arxiv.org\/abs\/2306.06136, 2023","DOI":"10.3233\/FAIA230632"},{"issue":"10","key":"26_CR11","doi-asserted-by":"publisher","first-page":"14370","DOI":"10.1109\/TNNLS.2023.3278715","volume":"35","author":"Z Zhou","year":"2023","unstructured":"Zhou, Z., Liu, G., Zhou, M.: A robust mean-field actor-critic reinforcement learning against adversarial perturbations on agent states. IEEE Trans. Neural Networks Learn. Syst. 35(10), 14370\u201314381 (2023)","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"26_CR12","unstructured":"N. Papernot, P. McDaniel, and I. Goodfellow, Transferability in machine learning: from phenomena to black-box attacks using adversarial samples, arXiv preprint https:\/\/arxiv.org\/abs\/1605.07277, 2016"},{"key":"26_CR13","doi-asserted-by":"crossref","unstructured":"F. Waseda, S. Nishikawa, T.-N. Le, H. H. Nguyen, and I. Echizen, Closer look at the transferability of adversarial examples: How they fool different models differently. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, 2023, pp. 1360\u20131368","DOI":"10.1109\/WACV56688.2023.00141"},{"key":"26_CR14","unstructured":"C. Szegedy, et al., Intriguing properties of neural networks, arXiv preprint https:\/\/arxiv.org\/abs\/1312.6199, 2013"},{"key":"26_CR15","unstructured":"I.J. Goodfellow, J. Shlens, and C. Szegedy, Explaining and harnessing adversarial examples, arXiv preprint https:\/\/arxiv.org\/abs\/1412.6572, 2014"},{"key":"26_CR16","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, Towards deep learning models resistant to adversarial attacks, arXiv preprint https:\/\/arxiv.org\/abs\/1706.06083, 2017"},{"key":"26_CR17","unstructured":"A. Kurakin, I. Goodfellow, and S. Bengio, Adversarial machine learning at scale, arXiv preprint https:\/\/arxiv.org\/abs\/1611.01236, 2016"},{"key":"26_CR18","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1109\/SP.2017.49","volume-title":"2017 IEEE Symposium on Security and Privacy (sp)","author":"N Carlini","year":"2017","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (sp), pp. 39\u201357. IEEE (2017)"},{"key":"26_CR19","doi-asserted-by":"crossref","unstructured":"S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, 2016, pp. 2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"26_CR20","doi-asserted-by":"crossref","unstructured":"P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM workshop on artificial intelligence and security, 2017, pp. 15\u201326","DOI":"10.1145\/3128572.3140448"},{"key":"26_CR21","doi-asserted-by":"crossref","unstructured":"C.-C. Tu, et al., Autozoom: autoencoder-based zeroth order optimization method for attacking black-box neural networks. In: Proceedings of the Thirty-Third AAAI Conference on Artificial Intelligence and Thirty-First Innovative Applications of Artificial Intelligence Conference and Ninth AAAI Symposium on Educational Advances in Artificial Intelligence, 2019, pp. 742\u2013749","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"26_CR22","unstructured":"W. Brendel, J. Rauber, and M. Bethge, Decision-based adversarial attacks: Reliable attacks against black-box machine learning models, arXiv preprint https:\/\/arxiv.org\/abs\/1712.04248, 2017"},{"issue":"178","key":"26_CR23","first-page":"1","volume":"21","author":"T Rashid","year":"2020","unstructured":"Rashid, T., Samvelyan, M., De Witt, C.S., Farquhar, G., Foerster, J., Whiteson, S.: Monotonic value function factorisation for deep multi-agent reinforcement learning. J. Mach. Learn. Res. 21(178), 1\u201351 (2020)","journal-title":"J. Mach. Learn. Res."},{"key":"26_CR24","unstructured":"P. Sunehag, et al., Value-decomposition networks for cooperative multi-agent learning, arXiv preprint https:\/\/arxiv.org\/abs\/1706.05296, 2017"},{"key":"26_CR25","unstructured":"S. Huang, N. Papernot, I. Goodfellow, Y. Duan, and P. Abbeel, Adversarial attacks on neural network policies, arXiv preprint https:\/\/arxiv.org\/abs\/1702.02284, 2017"},{"key":"26_CR26","doi-asserted-by":"crossref","unstructured":"Y.-C. Lin, Z.-W. Hong, Y.-H. Liao, M.-L. Shih, M.-Y. Liu, and M. Sun, Tactics of adversarial attack on deep reinforcement learning agents, arXiv preprint https:\/\/arxiv.org\/abs\/1703.06748, 2017","DOI":"10.24963\/ijcai.2017\/525"},{"key":"26_CR27","unstructured":"S. Han, S. Su, S. He, S. Han, H. Yang, and F. Miao, What is the solution for state-adversarial multi-agent reinforcement learning? arXiv preprint https:\/\/arxiv.org\/abs\/2212.02705, 2022"},{"key":"26_CR28","doi-asserted-by":"crossref","unstructured":"S. Li, et al., Attacking cooperative multi-agent reinforcement learning by adversarial minority influence, arXiv preprint https:\/\/arxiv.org\/abs\/2302.03322, 2023","DOI":"10.2139\/ssrn.4946720"},{"key":"26_CR29","volume-title":"2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)","author":"B Zhang","year":"2025","unstructured":"Zhang, B., Luo, W., Chen, K., Liu, Y., Qi, S., Wang, X.: Black-box adversarial robustness testing with partial observation for multi-agent reinforcement learning. In: 2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS). IEEE (2025)"},{"issue":"01","key":"26_CR30","first-page":"865","volume":"34","author":"S Pal","year":"2020","unstructured":"Pal, S., Gupta, Y., Shukla, A., Kanade, A., Shevade, S., Ganapathy, V.: Activethief: Model extraction using active learning and unannotated public data. Proc. AAAI Conf. Artif. Intell. 34(01), 865\u2013872 (2020)","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"issue":"6","key":"26_CR31","doi-asserted-by":"publisher","first-page":"1427","DOI":"10.1109\/TETCI.2022.3182415","volume":"6","author":"W Luo","year":"2022","unstructured":"Luo, W., Zhang, L., Han, P., Liu, C.: Taking away both model and data: Remember training data by parameter combinations. IEEE Trans. Emerging Top. Comput. Intell. 6(6), 1427\u20131437 (2022)","journal-title":"IEEE Trans. Emerging Top. Comput. Intell."},{"key":"26_CR32","doi-asserted-by":"crossref","unstructured":"T. Orekondy, B. Schiele, and M. Fritz, Knockoff nets: Stealing functionality of black-box models. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, 2019, pp. 4954\u20134963","DOI":"10.1109\/CVPR.2019.00509"},{"key":"26_CR33","doi-asserted-by":"crossref","unstructured":"S. Kariyappa, A. Prakash, and M. K. Qureshi, Maze: Data-free model stealing attack using zeroth-order gradient estimation. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2021, pp. 13\u00a0814\u201313\u00a0823","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"26_CR34","unstructured":"M. Samvelyan, et al., The starcraft multi-agent challenge, arXiv preprint https:\/\/arxiv.org\/abs\/1902.04043, 2019"},{"key":"26_CR35","unstructured":"Konda, V., Tsitsiklis, J.: Actor-critic algorithms. Adv. Neural Inf. Proces. Syst. 12 (1999)"},{"key":"26_CR36","unstructured":"V. Mnih, et al., Playing Atari with deep reinforcement learning, arXiv preprint https:\/\/arxiv.org\/abs\/1312.5602, 2013"},{"issue":"7540","key":"26_CR37","doi-asserted-by":"publisher","first-page":"529","DOI":"10.1038\/nature14236","volume":"518","author":"V Mnih","year":"2015","unstructured":"Mnih, V., et al.: Human-level control through deep reinforcement learning. Nature. 518(7540), 529\u2013533 (2015)","journal-title":"Nature"},{"key":"26_CR38","volume-title":"2015 AAAI Fall Symposium Series","author":"M Hausknecht","year":"2015","unstructured":"Hausknecht, M., Stone, P.: Deep recurrent q-learning for partially observable mdps. In: 2015 AAAI Fall Symposium Series (2015)"},{"issue":"7","key":"26_CR39","doi-asserted-by":"publisher","first-page":"3625","DOI":"10.3390\/s23073625","volume":"23","author":"J Orr","year":"2023","unstructured":"Orr, J., Dutta, A.: Multi-agent deep reinforcement learning for multi-robot applications: a survey. Sensors. 23(7), 3625 (2023)","journal-title":"Sensors"},{"key":"26_CR40","doi-asserted-by":"crossref","unstructured":"N. Papernot, P. McDaniel, S. Jha, et al., The Limitations of Deep Learning in Adversarial Settings. In: 2016 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 372\u2013387, 2016","DOI":"10.1109\/EuroSP.2016.36"},{"key":"26_CR41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28929-8","volume-title":"A Concise Introduction to Decentralized POMDPs","author":"FA Oliehoek","year":"2016","unstructured":"Oliehoek, F.A., Amato, C.: A Concise Introduction to Decentralized POMDPs. Springer (2016)"}],"container-title":["Lecture Notes in Computer Science","Advanced Intelligent Computing Technology and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-3381-6_26","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T20:14:50Z","timestamp":1784405690000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-3381-6_26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,19]]},"ISBN":["9789819233809","9789819233816"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-3381-6_26","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,19]]},"assertion":[{"value":"19 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toronto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icic2026a","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ic-icc.cn\/2026\/index.htm","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}