发表机构
School of Engineering and Applied Sciences, Harvard University; Whiting School of Engineering at the Johns Hopkins University(哈佛大学工程与应用科学学院; 约翰斯·霍普金斯大学惠廷工程学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对多机器人系统中智能体被入侵导致规划与执行不匹配的问题,提出信任感知监测器结合分层二分匹配策略,实现对定位欺骗的检测与弹性路由,恢复滚动规划的成本优势。
AI 中文摘要
多机器人系统中的序贯决策通常假设规划信息可靠,且智能体执行规划者预期的动作,但被入侵的智能体可能违反这两项假设,导致规划模型与物理执行不匹配。我们研究了存在定位欺骗的在线多机器人路由问题,针对具备监测能力的对手,提出了距离约束型欺骗模型,以及一种分层二分匹配策略,该策略在最大化分配影响力的同时限制欺骗幅度。为缓解此类攻击,我们开发了信任感知监测器,其结合了利用真实GPS欺骗数据校准的概率定位信任,以及任务执行的行为证据,用于对智能体分类并将检测到的对手从后续规划中移除。我们进一步表明,未被检测到的对手会因违反规划者-执行一致性,导致滚动(rollout)失去预期的成本改善行为,而信任感知移除在检测到对手后恢复了这种一致性,从而实现稳定路由并恢复滚动相对于基础策略的经验优势。使用真实GPS欺骗数据集和旧金山出租车需求开展的实验,验证了在不同欺骗能力、对手集群规模、自适应攻击、监测配置及滚动 horizon(规划时域)下,该方法可实现有效检测和弹性路由。
英文摘要
Sequential decision-making in multi-robot systems typically assumes that planning information is reliable and that agents execute the actions anticipated by the planner. Compromised agents can violate both assumptions, creating a mismatch between the planning model and physical execution. We study this problem in online multi-robot routing under localization spoofing. We introduce a distance-constrained spoofing model for monitor-aware adversaries, together with a tiered bipartite matching strategy that maximizes assignment influence while limiting spoofing magnitude. To mitigate such attacks, we develop a trust-aware monitor that combines probabilistic localization trust, calibrated using real GPS spoofing data, with behavioral evidence from task execution to classify agents and remove detected adversaries from subsequent planning. We further show that undetected adversaries can cause rollout to lose its expected cost-improvement behavior by violating planner-execution consistency. Trust-aware removal restores this consistency after detection, enabling stable routing and recovery of rollout's empirical advantage over the base policy. Experiments using real GPS spoofing datasets and San Francisco taxicab demand demonstrate effective detection and resilient routing across varying spoofing capabilities, adversarial fleet sizes, adaptive attacks, monitoring configurations, and rollout horizons.
Comments20 pages, 17 figures