Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Beyond training-time poisoning: Component-level and post-training backdoors in deep reinforcement learning

Vyas, Sanyam, Caron, Alberto, Hicks, Chris, Burnap, Peter ORCID: https://orcid.org/0000-0003-0396-633X and Mavroudis, Vasilios 2026. Beyond training-time poisoning: Component-level and post-training backdoors in deep reinforcement learning. Presented at: AAAI Conference on Artificial Intelligence Conference, Singapore, 20-27 January 2026. Proceedings of the AAAI Conference on Artificial Intelligence , vol.40 (31) Washington DC, USA: AAAI Press, pp. 26072-26080. 10.1609/aaai.v40i31.39809

[thumbnail of aaai2026_btt_camera_ready___ (1).pdf]
Preview
PDF - Accepted Post-Print Version
Download (760kB) | Preview

Abstract

Deep Reinforcement Learning (DRL) systems are increasingly used in safety-critical applications, yet their security remains severely underexplored. This work investigates backdoor attacks, which implant hidden triggers that cause malicious actions only when specific inputs appear in the observation space. Existing DRL backdoor research focuses solely on training-time attacks requiring full adversarial access to the training pipeline. In contrast, we reveal critical vulnerabilities across the DRL supply chain where backdoors can be embedded with significantly reduced adversarial privileges. We introduce two novel attacks: (1) TrojanentRL, which exploits component-level flaws to implant a persistent backdoor that survives full model retraining; and (2) InfrectroRL, a post-training backdoor attack which requires no access to training, validation, or test data. Empirical and analytical evaluations across six Atari environments show our attacks rival state-of-the-art training-time backdoor attacks while operating under much stricter adversarial constraints. We also demonstrate that InfrectroRL further evades two leading DRL backdoor defenses. These findings challenge the current research focus and highlight the urgent need for robust defenses.

Item Type: Conference or Workshop Item - published (Paper)
Date Type: Publication
Status: Published
Schools: Schools > Computer Science & Informatics
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Publisher: AAAI Press
ISSN: 2159-5399
Date of First Compliant Deposit: 11 December 2025
Last Modified: 21 Apr 2026 10:18
URI: https://orca.cardiff.ac.uk/id/eprint/182861

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics