智能系统行为动力学理论与安全监测方法
网络出版日期: 2025-01-25
基金资助
国家自然科学基金(62476018)
版权
Behavioral dynamics theory and safety monitoring methods for intelligent systems
Online published: 2025-01-25
Copyright
人工智能(Artificial Intelligence,AI)在网络安全领域中得到愈发广泛的应用,但人工智能技术的黑箱性与真实应用场景的复杂性,给智能系统部署过程中的安全性带来了一系列重大挑战。虽然国内外对于智能算法监测开发了一系列平台与工具,但由于智能系统中存在复杂环境影响,且多个智能算法间相互耦合,仅保障智能算法安全仍然不足以保障整个智能系统的平稳运行,给智能系统的安全带来了新的挑战。在进行系统部署时对智能系统的安全性进行实时监测,确保智能系统时刻运行稳定,成为解决当前智能系统安全问题的重要途径。针对智能系统所面临的安全监测问题,首先,阐述智能系统的安全内涵,指出真实生活中由于智能系统安全风险而导致的社会问题。接着,从复杂系统的角度出发,提出智能系统的微观行为动力学与宏观行为动力学理论,并给出关于智能系统的监测方法。最后,结合应用场景,给出了机器人集群典型场景下的智能系统安全监测案例,并提出了未来展望。对智能系统安全监测理论和方法体系的研究与建设,可以有效识别并提前发现智能系统在部署过程中的潜在风险与安全隐患,是实现人工智能算法可信可靠的重要组成单元,对于实现人工智能安全具有重要意义。
李思民 , 王嘉凯 , 刘艾杉 , 刘祥龙 . 智能系统行为动力学理论与安全监测方法[J]. 网络空间安全科学学报, 2024 , 2(6) : 86 -97 . DOI: 10.20172/j.issn.2097-3136.240606
Artificial intelligence (AI) is increasingly being employed in the field of network security, yet the deployment of AI techniques faces significant challenges due to their inherent black-box nature and the complexity of real-world applications. While a variety of platforms and tools have been developed to monitor the security of AI algorithms, merely securing the intelligent algorithms is inadequate to ensure the stable operation of the intelligent systems as a whole due to the influence of the intricate environment within intelligent systems and the coupling between multiple AI algorithms, which presents new changes to their safety. To address these issues, it is essential to monitor the security of intelligent systems in real time during deployment to ensure stable operation. Aiming at the safety monitoring problems faced by intelligent systems, firstly, the definition of security within intelligent systems was clarified, and societal problems that could be traced back to the security challenges of intelligent systems in the real world were identified. Then proceeding from the perspective of complex system theory, the micro and macro behavioral dynamics for intelligent systems along with the corresponding monitoring methods were introduced. Lastly, a case study of monitoring intelligent systems for robot swarm control from the real-world application scenarios was presented, and the potential future research directions were proposed. The development and research into theories and methodologies for monitoring the safety of intelligent systems are crucial for effectively identifying and preemptively discovering the potential risks and security flaws during the deployment phase, which serves as a vital component in achieving trustworthy AI algorithms and is of significant importance in realizing safe AI.
表 1 MAPPO算法的训练参数Table 1 Hyperparameters for MAPPO algorithm |
| 参数类型 | 参数名 | 设置值 | 含义 |
| 环境 | difficulty | 7 | 攻击者内置策略难度系数 |
| obs_all_health | True | 观测是否包含全部智能体生命值 | |
| obs_own_health | True | 观测是否包含智能体自身生命值 | |
| reward_death_value | 10 | 攻击者的单位被击杀时给予的奖励值 | |
| reward_defeat | −200 | 被攻击者被击败时的奖励值(负值) | |
| reward_negative_scale | 1 | 用于缩放负值奖励的比例 | |
| reward_scale_rate | 20 | 用于缩放奖励的比例 | |
| reward_win | 200 | 被攻击者击败攻击者时的奖励值(负值) | |
| state_last_action | True | 状态信息是否包括智能体的上一次动作 | |
| 算法 | lr | 0.000 5 | 学习率 |
| gamma | 0.99 | 用于计算预期奖励的折扣率 | |
| hidden_dim | 64 | 隐藏层神经元数 | |
| grad_norm_clip | 10 | 梯度裁剪阈值 | |
| add_value_last_step | True | 在计算每个episode的累计奖励时,是否使用最后一步的价值估计 | |
| entropy_coef | 0.01 | 熵系数,用于策略的熵正则化项 |
| 1 |
赵楠, 缐珊珊. 人工智能应用现状及关键技术研究[J]. 中国电子科学研究院学报, 2017, 12 (6): 590- 592.
ZHAO N, XIAN S S. Research on the current application status and key technologies of artificial intelligence[J]. Journal of China Academy of Electronics and Information Technology, 2017, 12 (6): 590- 592.
|
| 2 |
刘祥龙. 打开算法“黑箱”[N]. 人民日报,2022-03-16(3).
LIU X L. Opening the “black box” of algorithms[N]. People’s Daily,2022-03-16(3).
|
| 3 |
KATZENBACH C, ULBRICHT L. Algorithmic governance[J]. Internet Policy Review, 2019, 8 (4): 1- 18.
|
| 4 |
GRITSENKO D, WOOD M. Algorithmic governance: a modes of governance approach[J]. Regulation & Governance, 2022, 16 (1): 45- 62.
|
| 5 |
PAPERNOT N, FAGHRI F, CARLINI N, et al. Technical report on the cleverhans v2.1. 0 adversarial examples library[J]. ArXiv preprint ArXiv:, 1610, 00768, 2016.
|
| 6 |
NICOLAE M I, SINN M, TRAN M N, et al. Adversarial Robustness Toolbox v1.0. 0[J]. ArXiv preprint ArXiv:, 1807, 01069, 2018.
|
| 7 |
GOODMAN D, XIN H, YANG W, et al. Advbox: a toolbox to generate adversarial examples that fool neural networks[J]. ArXiv preprint ArXiv:, 2001, 05574, 2020.
|
| 8 |
GUO J, BAO W, WANG J, et al. A comprehensive evaluation framework for deep model robustness[J]. ArXiv preprint ArXiv:, 2101, 09617, 2021.
|
| 9 |
GOODFELLOW I J, SHLENS J, SZEGEDY C. Explaining and harnessing adversarial examples[J]. ArXiv preprint ArXiv:, 1412, 6572, 2014.
|
| 10 |
MADRY A, MAKELOV A, SCHMIDT L, et al. Towards deep learning models resistant to adversarial attacks[J]. ArXiv preprint ArXiv:, 1706, 06083, 2017.
|
| 11 |
GEIRHOS R, RUBISCH P, MICHAELIS C, et al. ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness[J]. ArXiv preprint ArXiv:, 1811, 12231, 2018.
|
| 12 |
HARDT M,PRICE E,SREBRO N. Equality of opportunity in supervised learning[C]//Advances in Neural Information Processing Systems. Curran Associates Inc.,2016:3323-3331.
|
| 13 |
ENSIGN D,FRIEDLER S A,NEVILLE S,et al. Runaway feedback loops in predictive policing[C]//Conference on Fairness,Accountability and Transparency. PMLR,2018:160-171.
|
| 14 |
CALVANO E, CALZOLARI G, DENICOLO V, et al. Artificial intelligence, algorithmic pricing, and collusion[J]. American Economic Review, 2020, 110 (10): 3267- 3297.
|
| 15 |
WANG X, SIRIANNI A D, TANG S, et al. Public discourse and social network echo chambers driven by socio-cognitive biases[J]. Physical Review X, 2020, 10 (4): 041042.
|
| 16 |
MOLINA M. What is an intelligent system?[J]. ArXiv preprint ArXiv:, 2009, 09083, 2020.
|
| 17 |
HE K,ZHANG X,REN S,et al. Deep residual learning for image recognition[C]//Proceedings of the IEEE conference on Computer Vision and Pattern Recognition. IEEE,2016:770-778.
|
| 18 |
GIRSHICK R. Fast r-CNN[C]//Proceedings of the IEEE international conference on computer vision. IEEE,2015:1440-1448.
|
| 19 |
VASWANI A,SHAZEER N,PARMAR N,et al. Attention is all you need[C]//Advances in Neural Information Processing Systems. Curran Associates Inc.,2017:5998-6008.
|
| 20 |
DEVLIN J, CHANG M W, LEE K, et al. BERT: pre-training of deep bidirectional transformers for language understanding[J]. ArXiv preprint ArXiv:, 1810, 04805, 2018.
|
| 21 |
SZEGEDY C, ZAREMBA W, SUTSKEVER I, et al. Intriguing properties of neural networks[J]. ArXiv preprint ArXiv:, 1312, 6199, 2013.
|
| 22 |
KUŚMIERCZYK M. Algorithmic bias in the light of the GDPR and the proposed AI act[J]. Equality. Faces of Modern Europe. Wrocław:Willy Brandt Center for German and European Studies,2022.
|
| 23 |
GRIMMELIKHUIJSEN S, MEIJER A. Legitimacy of algorithmic decision-making: six threats and the need for a calibrated institutional response[J]. Perspectives on Public Management and Governance, 2022, 5 (3): 232- 242.
|
| 24 |
郑志明, 吕金虎, 韦卫. 精准智能理论: 面向复杂动态对象的人工智能[J]. 中国科学: 信息科学, 2021, 51 (4): 13.
ZHENG Z M, LÜ J H, WEI W, et al. Theory of precise intelligence: artificial intelligence for complex dynamic objects[J]. Science China: Information Sciences, 2021, 51 (4): 13.
|
| 25 |
ACHLIOPTAS D, D’SOUZA R M, SPENCER J. Explosive percolation in random networks[J]. Science, 2009, 323 (5920): 1453- 1455.
|
| 26 |
RIORDAN O, WARNKE L. Explosive percolation is continuous[J]. Science, 2011, 333 (6040): 322- 324.
|
| 27 |
HUANG S Y, ZOU X W, TAN Z J, et al. Network-induced nonequilibrium phase transition in the “game of Life”[J]. Physical Review E, 2003, 67 (2): 026107.
|
| 28 |
WANG W X, LÜ J, CHEN G, et al. Phase transition and hysteresis loop in structured games with global updating[J]. Physical Review E, 2008, 77 (4): 046109.
|
| 29 |
WANG X, LI W, LIU L, et al. Promoting information diffusion through interlayer recovery processes in multiplex networks[J]. Physical Review E, 2017, 96 (3): 032304.
|
| 30 |
COOPER I,MONDAL A,ANTONOPOULOS C G . A SIR model assumption for the spread of COVID-19 in different communities[J]. Chaos, Solitons &Fractals, 2020, 139: 110057.
|
| 31 |
SHAO Y, WANG X, FU F. Evolutionary dynamics of group cooperation with asymmetrical environmental feedback[J]. Europhysics Letters, 2019, 126 (4): 40005.
|
| 32 |
LIU A, LIU X, YU H, et al. Training robust deep neural networks via adversarial noise propagation[J]. IEEE Transactions on Image Processing, 2021, 30, 5769- 5781.
|
| 33 |
LI T, LIU A, LIU X, et al. Understanding adversarial robustness via critical attacking route[J]. Information Sciences, 2021, 547, 568- 578.
|
| 34 |
JAQUES N,LAZARIDOU A,HUGHES E,et al. Social influence as intrinsic motivation for multi-agent deep reinforcement learning[C]//International Conference on Machine Learning. PMLR,2019:3040-3049.
|
| 35 |
LI S, GUO J, XIU J, et al. Attacking cooperative multi-agent reinforcement learning by adversarial minority influence[J]. ArXiv preprint ArXiv:, 2302, 03322, 2023.
|
| 36 |
SCHULMAN J, WOLSKI F, DHARIWAL P, et al. Proximal policy optimization algorithms[J]. ArXiv preprint ArXiv:, 1707, 06347, 2017.
|
| 37 |
SCHULMAN J, MORITZ P, LEVINE S, et al. High-dimensional continuous control using generalized advantage estimation[J]. ArXiv preprint ArXiv:, 1506, 02438, 2015.
|
| 38 |
YU C, VELU A, VINITSKY E, et al. The surprising effectiveness of PPO in cooperative multi-agent games[J]. Advances in Neural Information Processing Systems, 2022, 35, 24611- 24624.
|
| 39 |
GUO J,CHEN Y,HAO Y,et al. Towards comprehensive testing on the robustness of cooperative multi-agent reinforcement learning[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. IEEE,2022:115-122.
|
| 40 |
BUBECK S, CHANDRASEKARAN V, ELDAN R, et al. Sparks of artificial general intelligence: early experiments with GPT-4[J]. ArXiv preprint ArXiv:, 2303, 12712, 2023.
|
| 41 |
HAO S, GU Y, MA H, et al. Reasoning with language model is planning with world model[J]. ArXiv preprint ArXiv:, 2305, 14992, 2023.
|
| 42 |
SALMAN H,LI J,RAZENSHTEYN I,et al. Provably robust deep learning via adversarially trained smoothed classifiers[C]//Advances in Neural Information Processing Systems. Curran Associates Inc.,2019:11292-11303.
|
| 43 |
CROCE F,ANDRIUSHCHENKO M,HEIN M. Provable robustness of relu networks via maximization of linear regions[C]//the 22nd International Conference on Artificial Intelligence and Statistics. PMLR,2019:2057-2066.
|
| 44 |
FARMER J D, FOLEY D. The economy needs agent-based modelling[J]. Nature, 2009, 460 (7256): 685- 686.
|
| 45 |
JANSSEN M A. Agent-based modelling[J]. Modelling in Ecological Economics, 2005, 155 (1): 172- 181.
|
| 46 |
YAO X,ZHOU J,ZHANG J,et al. From intelligent manufacturing to smart manufacturing for industry 4.0 driven by next generation artificial intelligence and further on[C]//2017 5th International Conference on Enterprise Systems (ES). IEEE,2017:311-318.
|
| 47 |
KAUFMANN E, BAUERSFELD L, LOQUERCIO A, et al. Champion-level drone racing using deep reinforcement learning[J]. Nature, 2023, 620 (7976): 982- 987.
|
/
| 〈 |
|
〉 |