{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T04:15:43Z","timestamp":1768882543132,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":26,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,8,20]],"date-time":"2020-08-20T00:00:00Z","timestamp":1597881600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the US National Science Foundation","award":["IIS-1924928 IIS-1938167 OAC-1934600"],"award-info":[{"award-number":["IIS-1924928 IIS-1938167 OAC-1934600"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,8,23]]},"DOI":"10.1145\/3394486.3403089","type":"proceedings-article","created":{"date-parts":[[2020,8,20]],"date-time":"2020-08-20T23:18:56Z","timestamp":1597965536000},"page":"472-482","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":21,"title":["Malicious Attacks against Deep Reinforcement Learning Interpretations"],"prefix":"10.1145","author":[{"given":"Mengdi","family":"Huai","sequence":"first","affiliation":[{"name":"University of Virginia, Charlottesville, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianhui","family":"Sun","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Renqin","family":"Cai","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liuyi","family":"Yao","sequence":"additional","affiliation":[{"name":"State University of New York at Buffalo, Buffalo, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aidong","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,8,20]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Julius Adebayo Justin Gilmer Michael Muelly Ian Goodfellow Moritz Hardt and Been Kim. 2018. Sanity checks for saliency maps. In NeurIPS. 9505--9515.  Julius Adebayo Justin Gilmer Michael Muelly Ian Goodfellow Moritz Hardt and Been Kim. 2018. Sanity checks for saliency maps. In NeurIPS. 9505--9515."},{"key":"e_1_3_2_1_2_1","volume-title":"Exploratory Not Explanatory: Counterfactual Analysis of Saliency Maps for Deep Reinforcement Learning. arXiv preprint arXiv:1912.05743","author":"Atrey Akanksha","year":"2019","unstructured":"Akanksha Atrey , Kaleigh Clary , and David Jensen . 2019. Exploratory Not Explanatory: Counterfactual Analysis of Saliency Maps for Deep Reinforcement Learning. arXiv preprint arXiv:1912.05743 ( 2019 ). Akanksha Atrey, Kaleigh Clary, and David Jensen. 2019. Exploratory Not Explanatory: Counterfactual Analysis of Saliency Maps for Deep Reinforcement Learning. arXiv preprint arXiv:1912.05743 (2019)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62416-7_19"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013681"},{"key":"e_1_3_2_1_5_1","volume-title":"Visualizing and understanding atari agents. arXiv preprint arXiv:1711.00138","author":"Greydanus Sam","year":"2017","unstructured":"Sam Greydanus , Anurag Koul , Jonathan Dodge , and Alan Fern . 2017. Visualizing and understanding atari agents. arXiv preprint arXiv:1711.00138 ( 2017 ). Sam Greydanus, Anurag Koul, Jonathan Dodge, and Alan Fern. 2017. Visualizing and understanding atari agents. arXiv preprint arXiv:1711.00138 (2017)."},{"key":"e_1_3_2_1_6_1","volume-title":"Towards Interpretation of Pairwise Learning. In Thirty-fourth AAAI Conference on Artificial Intelligence.","author":"Huai Mengdi","year":"2020","unstructured":"Mengdi Huai , Di Wang , Chenglin Miao , and Aidong Zhang . 2020 . Towards Interpretation of Pairwise Learning. In Thirty-fourth AAAI Conference on Artificial Intelligence. Mengdi Huai, Di Wang, Chenglin Miao, and Aidong Zhang. 2020. Towards Interpretation of Pairwise Learning. In Thirty-fourth AAAI Conference on Artificial Intelligence."},{"key":"e_1_3_2_1_7_1","volume-title":"Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284","author":"Huang Sandy","year":"2017","unstructured":"Sandy Huang , Nicolas Papernot , Ian Goodfellow , Yan Duan , and Pieter Abbeel . 2017. Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284 ( 2017 ). Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel. 2017. Adversarial attacks on neural network policies. arXiv preprint arXiv:1702.02284 (2017)."},{"key":"e_1_3_2_1_8_1","volume-title":"Targeted Attacks on Deep Reinforcement Learning Agents through Adversarial Observations. arXiv preprint arXiv:1905.12282","author":"Hussenot L\u00e9onard","year":"2019","unstructured":"L\u00e9onard Hussenot , Matthieu Geist , and Olivier Pietquin . 2019. Targeted Attacks on Deep Reinforcement Learning Agents through Adversarial Observations. arXiv preprint arXiv:1905.12282 ( 2019 ). L\u00e9onard Hussenot, Matthieu Geist, and Olivier Pietquin. 2019. Targeted Attacks on Deep Reinforcement Learning Agents through Adversarial Observations. arXiv preprint arXiv:1905.12282 (2019)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278721.3278776"},{"key":"e_1_3_2_1_10_1","unstructured":"Michael Kearns and Satinder Singh. 2002. Near-Optimal Reinforcement Learning in Polynomial Time. Mach. Learn. (2002).  Michael Kearns and Satinder Singh. 2002. Near-Optimal Reinforcement Learning in Polynomial Time. Mach. Learn. (2002)."},{"key":"e_1_3_2_1_11_1","volume-title":"Explainable AI: Interpreting, Explaining and Visualizing Deep Learning","author":"Kindermans Pieter-Jan","unstructured":"Pieter-Jan Kindermans , Sara Hooker , Julius Adebayo , Maximilian Alber , Kristof T Sch\u00fctt , Sven Dahne , Dumitru Erhan , and Been Kim . 2019. The (un) reliability of saliency methods . In Explainable AI: Interpreting, Explaining and Visualizing Deep Learning . Springer , 267--280. Pieter-Jan Kindermans, Sara Hooker, Julius Adebayo, Maximilian Alber, Kristof T Sch\u00fctt, Sven Dahne, Dumitru Erhan, and Been Kim. 2019. The (un) reliability of saliency methods. In Explainable AI: Interpreting, Explaining and Visualizing Deep Learning. Springer, 267--280."},{"key":"e_1_3_2_1_12_1","volume-title":"Tactics of adversarial attack on deep reinforcement learning agents. arXiv preprint arXiv:1703.06748","author":"Lin Yen-Chen","year":"2017","unstructured":"Yen-Chen Lin , Zhang-Wei Hong , Yuan-Hong Liao , Meng-Li Shih , Ming-Yu Liu , and Min Sun . 2017. Tactics of adversarial attack on deep reinforcement learning agents. arXiv preprint arXiv:1703.06748 ( 2017 ). Yen-Chen Lin, Zhang-Wei Hong, Yuan-Hong Liao, Meng-Li Shih, Ming-Yu Liu, and Min Sun. 2017. Tactics of adversarial attack on deep reinforcement learning agents. arXiv preprint arXiv:1703.06748 (2017)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186032"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3209582.3209594"},{"key":"e_1_3_2_1_15_1","volume-title":"Nature","volume":"518","author":"Mnih Volodymyr","year":"2015","unstructured":"Volodymyr Mnih , Koray Kavukcuoglu , David Silver , Andrei A Rusu , Joel Veness , Marc G Bellemare , Alex Graves , Martin Riedmiller , Andreas K Fidjeland , Georg Ostrovski , 2015 . Human-level control through deep reinforcement learning . Nature , Vol. 518 , 7540 (2015), 529. Volodymyr Mnih, Koray Kavukcuoglu, David Silver, Andrei A Rusu, Joel Veness, Marc G Bellemare, Alex Graves, Martin Riedmiller, Andreas K Fidjeland, Georg Ostrovski, et al. 2015. Human-level control through deep reinforcement learning. Nature, Vol. 518, 7540 (2015), 529."},{"key":"e_1_3_2_1_16_1","volume-title":"Proc. of the 17th International Conference on Autonomous Agents and MultiAgent Systems. 2040--2042","author":"Pattanaik Anay","year":"2018","unstructured":"Anay Pattanaik , Zhenyi Tang , Shuijing Liu , Gautham Bommannan , and Girish Chowdhary . 2018 . Robust deep reinforcement learning with adversarial attacks . In Proc. of the 17th International Conference on Autonomous Agents and MultiAgent Systems. 2040--2042 . Anay Pattanaik, Zhenyi Tang, Shuijing Liu, Gautham Bommannan, and Girish Chowdhary. 2018. Robust deep reinforcement learning with adversarial attacks. In Proc. of the 17th International Conference on Autonomous Agents and MultiAgent Systems. 2040--2042."},{"key":"e_1_3_2_1_17_1","volume-title":"Minimalistic Attacks: How Little it Takes to Fool a Deep Reinforcement Learning Policy. arXiv preprint arXiv:1911.03849","author":"Qu Xinghua","year":"2019","unstructured":"Xinghua Qu , Zhu Sun , Pengfei Wei , Yew-Soon Ong , and Abhishek Gupta . 2019 . Minimalistic Attacks: How Little it Takes to Fool a Deep Reinforcement Learning Policy. arXiv preprint arXiv:1911.03849 (2019). Xinghua Qu, Zhu Sun, Pengfei Wei, Yew-Soon Ong, and Abhishek Gupta. 2019. Minimalistic Attacks: How Little it Takes to Fool a Deep Reinforcement Learning Policy. arXiv preprint arXiv:1911.03849 (2019)."},{"key":"e_1_3_2_1_18_1","unstructured":"John Schulman Sergey Levine Pieter Abbeel Michael Jordan and Philipp Moritz. 2015. Trust region policy optimization. In ICML. 1889--1897.  John Schulman Sergey Levine Pieter Abbeel Michael Jordan and Philipp Moritz. 2015. Trust region policy optimization. In ICML. 1889--1897."},{"key":"e_1_3_2_1_19_1","volume-title":"Stealthy and efficient adversarial attacks against deep reinforcement learning. arXiv preprint arXiv:2005.07099","author":"Sun Jianwen","year":"2020","unstructured":"Jianwen Sun , Tianwei Zhang , Xiaofei Xie , Lei Ma , Yan Zheng , Kangjie Chen , and Yang Liu . 2020. Stealthy and efficient adversarial attacks against deep reinforcement learning. arXiv preprint arXiv:2005.07099 ( 2020 ). Jianwen Sun, Tianwei Zhang, Xiaofei Xie, Lei Ma, Yan Zheng, Kangjie Chen, and Yang Liu. 2020. Stealthy and efficient adversarial attacks against deep reinforcement learning. arXiv preprint arXiv:2005.07099 (2020)."},{"key":"e_1_3_2_1_20_1","volume-title":"Reinforcement learning: An introduction","author":"Sutton Richard S","unstructured":"Richard S Sutton and Andrew G Barto . 2018. Reinforcement learning: An introduction . MIT press . Richard S Sutton and Andrew G Barto. 2018. Reinforcement learning: An introduction. MIT press."},{"key":"e_1_3_2_1_21_1","volume-title":"Marc Lanctot, and Nando De Freitas.","author":"Wang Ziyu","year":"2015","unstructured":"Ziyu Wang , Tom Schaul , Matteo Hessel , Hado Van Hasselt , Marc Lanctot, and Nando De Freitas. 2015 . Dueling network architectures for deep reinforcement learning. arXiv preprint arXiv:1511.06581 (2015). Ziyu Wang, Tom Schaul, Matteo Hessel, Hado Van Hasselt, Marc Lanctot, and Nando De Freitas. 2015. Dueling network architectures for deep reinforcement learning. arXiv preprint arXiv:1511.06581 (2015)."},{"key":"e_1_3_2_1_22_1","volume-title":"Benelux Conference on Artificial Intelligence. Springer, 151--165","author":"Weitkamp Laurens","unstructured":"Laurens Weitkamp , Elise van der Pol, and Zeynep Akata. 2018. Visual rationalizations in deep reinforcement learning for atari games . In Benelux Conference on Artificial Intelligence. Springer, 151--165 . Laurens Weitkamp, Elise van der Pol, and Zeynep Akata. 2018. Visual rationalizations in deep reinforcement learning for atari games. In Benelux Conference on Artificial Intelligence. Springer, 151--165."},{"key":"e_1_3_2_1_23_1","volume-title":"Structured adversarial attack: Towards general implementation and better interpretability. arXiv preprint arXiv:1808.01664","author":"Xu Kaidi","year":"2018","unstructured":"Kaidi Xu , Sijia Liu , Pu Zhao , Pin-Yu Chen , Huan Zhang , Quanfu Fan , Deniz Erdogmus , Yanzhi Wang , and Xue Lin . 2018. Structured adversarial attack: Towards general implementation and better interpretability. arXiv preprint arXiv:1808.01664 ( 2018 ). Kaidi Xu, Sijia Liu, Pu Zhao, Pin-Yu Chen, Huan Zhang, Quanfu Fan, Deniz Erdogmus, Yanzhi Wang, and Xue Lin. 2018. Structured adversarial attack: Towards general implementation and better interpretability. arXiv preprint arXiv:1808.01664 (2018)."},{"key":"e_1_3_2_1_24_1","volume-title":"An Initial Attempt of Combining Visual Selective Attention with Deep Reinforcement Learning. arXiv preprint arXiv:1811.04407","author":"Yuezhang Liu","year":"2018","unstructured":"Liu Yuezhang , Ruohan Zhang , and Dana H Ballard . 2018. An Initial Attempt of Combining Visual Selective Attention with Deep Reinforcement Learning. arXiv preprint arXiv:1811.04407 ( 2018 ). Liu Yuezhang, Ruohan Zhang, and Dana H Ballard. 2018. An Initial Attempt of Combining Visual Selective Attention with Deep Reinforcement Learning. arXiv preprint arXiv:1811.04407 (2018)."},{"key":"e_1_3_2_1_25_1","unstructured":"Tom Zahavy Nir Ben-Zrihem and Shie Mannor. 2016. Graying the black box: Understanding dqns. In ICML. 1899--1908.  Tom Zahavy Nir Ben-Zrihem and Shie Mannor. 2016. Graying the black box: Understanding dqns. In ICML. 1899--1908."},{"key":"e_1_3_2_1_26_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Zhang Xinyang","year":"2020","unstructured":"Xinyang Zhang , Ningfei Wang , Hua Shen , Shouling Ji , Xiapu Luo , and Ting Wang . 2020 . Interpretable deep learning under fire . In 29th USENIX Security Symposium (USENIX Security 20) . Xinyang Zhang, Ningfei Wang, Hua Shen, Shouling Ji, Xiapu Luo, and Ting Wang. 2020. Interpretable deep learning under fire. In 29th USENIX Security Symposium (USENIX Security 20)."}],"event":{"name":"KDD '20: The 26th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Virtual Event CA USA","acronym":"KDD '20","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery &amp; Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394486.3403089","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394486.3403089","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:38Z","timestamp":1750200098000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394486.3403089"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,20]]},"references-count":26,"alternative-id":["10.1145\/3394486.3403089","10.1145\/3394486"],"URL":"https:\/\/doi.org\/10.1145\/3394486.3403089","relation":{},"subject":[],"published":{"date-parts":[[2020,8,20]]},"assertion":[{"value":"2020-08-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}