TY - JOUR
T1 - BLAST
T2 - A Stealthy Backdoor Leverage Attack Against Cooperative Multi-Agent Deep Reinforcement Learning-Based Systems
AU - Fang, Jing
AU - Yan, Saihao
AU - Yin, Xueyu
AU - Yu, Yinbo
AU - Tian, Chunwei
AU - Liu, Jiajia
N1 - Publisher Copyright:
© 2015 IEEE. All rights reserved.
PY - 2026
Y1 - 2026
N2 - Recent studies have shown that cooperative multiagent deep reinforcement learning (c-MADRL) is under the threat of backdoor attacks. Once a backdoor trigger is observed, it will perform malicious actions, resulting in failures or achieving malicious goals. However, existing backdoor attacks suffer from several issues, e.g., instant trigger patterns lack stealthiness, the backdoor is trained or activated by an additional network, or all agents are backdoored. To this end, in this paper, we propose a novel Backdoor Leverage Attack againST c-MADRL, BLAST, which attacks the entire multi-agent team by embedding the backdoor only in a single agent. Firstly, we introduce adversary spatiotemporal behavior patterns as the backdoor trigger rather than manually injected fixed visual patterns or instant status and control the period to perform malicious actions. This method can guarantee the stealthiness and practicality of BLAST. Secondly, we hack the original reward function of the backdoor agent via unilateral guidance to inject BLAST, to achieve the leverage attack effect that can pry open the entire multi-agent system via a single backdoor agent. We evaluate our BLAST against 3 classic c-MADRL algorithms (VDN, QMIX, and MAPPO) in 2 popular c-MADRL environments (SMAC and Pursuit), and 3 existing defense mechanisms. The experimental results demonstrate that BLAST can achieve a high attack success rate while maintaining a low clean performance variance rate.
AB - Recent studies have shown that cooperative multiagent deep reinforcement learning (c-MADRL) is under the threat of backdoor attacks. Once a backdoor trigger is observed, it will perform malicious actions, resulting in failures or achieving malicious goals. However, existing backdoor attacks suffer from several issues, e.g., instant trigger patterns lack stealthiness, the backdoor is trained or activated by an additional network, or all agents are backdoored. To this end, in this paper, we propose a novel Backdoor Leverage Attack againST c-MADRL, BLAST, which attacks the entire multi-agent team by embedding the backdoor only in a single agent. Firstly, we introduce adversary spatiotemporal behavior patterns as the backdoor trigger rather than manually injected fixed visual patterns or instant status and control the period to perform malicious actions. This method can guarantee the stealthiness and practicality of BLAST. Secondly, we hack the original reward function of the backdoor agent via unilateral guidance to inject BLAST, to achieve the leverage attack effect that can pry open the entire multi-agent system via a single backdoor agent. We evaluate our BLAST against 3 classic c-MADRL algorithms (VDN, QMIX, and MAPPO) in 2 popular c-MADRL environments (SMAC and Pursuit), and 3 existing defense mechanisms. The experimental results demonstrate that BLAST can achieve a high attack success rate while maintaining a low clean performance variance rate.
KW - Cooperative multi-agent deep reinforcement learning
KW - backdoor attack
KW - unilateral influence
UR - https://www.scopus.com/pages/publications/105043284092
U2 - 10.1109/TCCN.2026.3706546
DO - 10.1109/TCCN.2026.3706546
M3 - 文章
AN - SCOPUS:105043284092
SN - 2332-7731
VL - 12
SP - 9312
EP - 9325
JO - IEEE Transactions on Cognitive Communications and Networking
JF - IEEE Transactions on Cognitive Communications and Networking
ER -