Skip to main content

Table 2 Features for adversarial perturbations against single same original clean map, which can show how the different characteristics affect the interference of adversarial example

From: Adversarial attack and defense in reinforcement learning-from AI security view

Number

Point coordinates

Max Q-value

Top ΔQ

On the boundary

Point 1

(4,5)

90.2229

0.0198

True

Point 2

(4,10)

140.7650

0.1616

True

Point 3

(2,3)

60.9148

0.2214

True

Point 4

(3,4)

71.4446

0.3199

True

Point 5

(5,6)

109.0013

0.3595

True

Point 6

(0,2)

48.4608

0.4645

True

Point 7

(6,7)

126.3412

0.6992

True

Number

On the path

Top angle size

Angle size

Perturbation point

Point 1

True

Ø

74∘

True

Point 2

False

Ø

Ø

True

Point 3

True

Ø

75∘

True

Point 4

True

3

69∘

True

Point 5

True

1

84∘

True

Point 6

True

Ø

71∘

True

Point 7

True

2

77∘

False