计算机科学
稳健性(进化)
梯度下降
控制理论(社会学)
对抗制
数学优化
计算
有界函数
最优化问题
可扩展性
摄动(天文学)
控制器(灌溉)
二次方程
噪音(视频)
最优控制
鲁棒控制
趋同(经济学)
灵敏度(控制系统)
水准点(测量)
理论(学习稳定性)
脆弱性(计算)
合成数据
数学
线性系统
半定规划
二次增长
梯度法
控制系统
钥匙(锁)
迭代法
出处
期刊:Automatica
[Elsevier BV]
日期:2026-06-10
卷期号:191: 113125-113125
标识
DOI:10.1016/j.automatica.2026.113125
摘要
This study explores the vulnerability of direct data-driven control, particularly in the linear quadratic regulator (LQR) problem, to adversarial perturbations in offline collected data. We focus on stealthy attacks that subtly alter training data to destabilize the closed-loop system while evading detection. To craft such attacks, we propose Directed Gradient Sign Method (DGSM) and its iterative variant (I-DGSM), which adapt techniques from adversarial machine learning to align perturbations with the gradient of the closed-loop spectral radius. A key technical contribution is an efficient and exact gradient computation method using implicit differentiation through the Karush–Kuhn–Tucker conditions of the underlying semidefinite program. For defense, we introduce two strategies: (i) regularization to reduce controller sensitivity, and (ii) robust data-driven control that ensures stability under bounded perturbations. Experiments across benchmark systems reveal that even imperceptibly small perturbations, up to ten times smaller than random noise, can lead to instability, while the proposed defenses significantly reduce attack success rates with minimal performance loss. We also assess transferability under partial knowledge, demonstrating the importance of protecting training data. This work highlights critical security risks in data-driven control and proposes practical methods for both attack and defense.
科研通智能强力驱动
Strongly Powered by AbleSci AI