{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T08:05:13Z","timestamp":1773734713561,"version":"3.50.1"},"reference-count":41,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T00:00:00Z","timestamp":1763424000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T00:00:00Z","timestamp":1763424000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,11,18]]},"DOI":"10.1109\/itsc60802.2025.11423822","type":"proceedings-article","created":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T20:10:23Z","timestamp":1773691823000},"page":"878-883","source":"Crossref","is-referenced-by-count":0,"title":["Advancing Robustness in Deep Reinforcement Learning with an Ensemble Defense Approach"],"prefix":"10.1109","author":[{"given":"Adithya","family":"Mohan","sequence":"first","affiliation":[{"name":"AImotion Bavaria, Technische Hochschule Ingolstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dominik","family":"R\u00f6\u00dfle","sequence":"additional","affiliation":[{"name":"AImotion Bavaria, Technische Hochschule Ingolstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Cremers","sequence":"additional","affiliation":[{"name":"School of Computation, Information and Technology, TU Munich,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Torsten","family":"Sch\u00f6n","sequence":"additional","affiliation":[{"name":"AImotion Bavaria, Technische Hochschule Ingolstadt,Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"issue":"4","key":"ref2","first-page":"2689","article-title":"A survey on adversarial attacks and defenses in reinforcement learning","volume":"55","author":"Feng","year":"2021","journal-title":"Artificial Intelligence Review"},{"key":"ref3","article-title":"Deep reinforcement learning: An overview","author":"Nguyen","year":"2019","journal-title":"arXiv preprint"},{"issue":"14","key":"ref4","first-page":"3652","article-title":"A review of applications of artificial intelligence and blockchain in the energy sector","volume":"13","author":"Lin","year":"2020","journal-title":"Energies"},{"key":"ref5","first-page":"1","article-title":"Adversarial attacks on neural network policies","volume-title":"Workshop on artificial intelligence safety2017 (AISafety 2017)","author":"Huang"},{"key":"ref6","article-title":"Whatever does not kill deep reinforcement learning, makes it stronger","author":"Behzadan","year":"2017","journal-title":"arXiv preprint"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref8","article-title":"Explaining and harnessing adversarial examples","volume-title":"International Conference on Learning Representations (ICLR)","author":"Goodfellow","year":"2015"},{"key":"ref9","article-title":"Ensemble methods as a defense to adversarial perturbations against deep neural networks","author":"Strauss","year":"2017","journal-title":"arXiv [stat.ML]"},{"key":"ref10","volume-title":"An environment for autonomous driving decisionmaking","author":"Leurent","year":"2018"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-15919-0_50"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3326410"},{"key":"ref13","article-title":"Gradient band-based adversarial training for generalized attack immunity of a3c path finding","author":"Chen","year":"2018","journal-title":"arXiv preprint"},{"key":"ref14","first-page":"1","article-title":"Adversarial attacks on neural network policies","volume-title":"Proc. ICLR","author":"Huang","year":"2017"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62416-7_19"},{"key":"ref16","first-page":"1944","article-title":"Delving into adversarial attacks on deep policies","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","volume":"70","author":"Kos","year":"2017"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00079"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.65109\/tytx9168"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CNS56114.2022.9947234"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.23919\/ACC50511.2021.9483080"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/525"},{"key":"ref22","first-page":"1","article-title":"Sequential attacks on agents for long-term adversarial goals","volume-title":"Proc. ACM Comput. Sci. Cars Symp.","author":"Tretschk","year":"2018"},{"key":"ref23","first-page":"1","article-title":"Trojdrl: Trojan attacks on deep reinforcement learning agents","volume-title":"Proc. 57th ACM\/IEEE Design Automat. Conf. (DAC)","author":"Panagiota","year":"2020"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6047"},{"key":"ref25","first-page":"12400","article-title":"Provably efficient black-box action poisoning attacks against reinforcement learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Liu","year":"2021"},{"key":"ref26","first-page":"1","article-title":"Strategically-timed stateobservation attacks on deep reinforcement learning agents","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Ye","year":"2021"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.65109\/RNCT3583"},{"key":"ref28","first-page":"8707","article-title":"Deep reinforcement learning with robust and smooth policy","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Shen","year":"2020"},{"key":"ref29","first-page":"1","article-title":"Robust reinforcement learning on state observations with learned optimal adversary","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Zhang","year":"2021"},{"key":"ref30","first-page":"6215","article-title":"Action robust reinforcement learning and applications in continuous control","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Tessler","year":"2019"},{"key":"ref31","article-title":"Detecting adversarial attacks on neural network policies with visual foresight","author":"Lin","year":"2017","journal-title":"arXiv preprint"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/DSC.2018.00125"},{"key":"ref33","article-title":"Optimal attacks on reinforcement learning policies","author":"Russo","year":"2019","journal-title":"arXiv preprint"},{"key":"ref34","first-page":"21024","article-title":"Robust deep reinforcement learning against adversarial perturbations on state observations","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NIPS)","volume":"33","author":"Zhang","year":"2020"},{"key":"ref35","article-title":"Online robustness training for deep reinforcement learning","author":"Fischer","year":"2019","journal-title":"arXiv preprint"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.106967"},{"key":"ref37","first-page":"1328","article-title":"Certified adversarial robustness for deep reinforcement learning","volume-title":"Proc. Conf. Robot Learn.","author":"L\u00fctjens","year":"2020"},{"key":"ref38","first-page":"26 156","article-title":"Robust deep reinforcement learning through adversarial loss","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Oikarinen","year":"2021"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/OJITS.2021.3118972"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.5220\/0013114200003890"},{"issue":"268","key":"ref41","first-page":"1","article-title":"Stable-Baselines3: Reliable reinforcement learning implementations","volume":"22","author":"Raffin","year":"2021","journal-title":"J. Mach. Learn. Res."}],"event":{"name":"2025 IEEE 28th International Conference on Intelligent Transportation Systems (ITSC)","location":"Gold Coast, Australia","start":{"date-parts":[[2025,11,18]]},"end":{"date-parts":[[2025,11,21]]}},"container-title":["2025 IEEE 28th International Conference on Intelligent Transportation Systems (ITSC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11422813\/11423000\/11423822.pdf?arnumber=11423822","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T05:49:45Z","timestamp":1773726585000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11423822\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,18]]},"references-count":41,"URL":"https:\/\/doi.org\/10.1109\/itsc60802.2025.11423822","relation":{},"subject":[],"published":{"date-parts":[[2025,11,18]]}}}