TY - JOUR
T1 - Adversarial Attacks Against Deep Reinforcement Learning-Based Jamming Decision-Making
AU - Zhang, Ruibin
AU - Li, Yunjie
AU - Jia, Yubo
AU - Liu, Jiabin
N1 - Publisher Copyright:
© 1965-2011 IEEE.
PY - 2026
Y1 - 2026
N2 - The intelligence of jamming decision-making has been significantly enhanced by deep reinforcement learning (DRL), owing to its capability to autonomously discover optimal strategies through interaction with the environment. This advancement creates an urgent demand for innovative antijamming techniques specifically designed to counter intelligent jammers. To this end, this work presents a black-box framework against intelligent jamming decision-making, in which adversarial attacks are employed to compromise the effectiveness of DRL-based jamming strategies. The core concept involves manipulating the opponent’s observations through deliberate adjustments of radar pulse parameters, thereby misleading its decision-making process. Specifically, we first introduce parameter-guided behavior cloning (PBC) to address the lack of prior knowledge about the victim agent. PBC trains a surrogate agent from demonstration data while aligning its parameters with those of the victim agent to approximate the target policy, thereby providing the gradient information required for updating adversarial perturbations. On this basis, we develop the boundary-constrained adaptive distortion attack (BADA), which incorporates an adaptive moment-based update mechanism to stabilize the search for optimal perturbations. An adaptive step size scheme is introduced, employing larger updates in the early phase to speed up convergence and smaller ones later to mitigate oscillations and stabilize the search around the optimum. To ensure physical feasibility, BADA strictly enforces radar pulse constraints by clipping parameters to their prescribed ranges at each iteration. Extensive experiments demonstrate that the proposed adversarial pulse parameters effectively disrupt DRL-based jammers, thereby improving radar detection performance under jamming conditions. These results validate the feasibility and effectiveness of the proposed antiintelligent jamming framework.
AB - The intelligence of jamming decision-making has been significantly enhanced by deep reinforcement learning (DRL), owing to its capability to autonomously discover optimal strategies through interaction with the environment. This advancement creates an urgent demand for innovative antijamming techniques specifically designed to counter intelligent jammers. To this end, this work presents a black-box framework against intelligent jamming decision-making, in which adversarial attacks are employed to compromise the effectiveness of DRL-based jamming strategies. The core concept involves manipulating the opponent’s observations through deliberate adjustments of radar pulse parameters, thereby misleading its decision-making process. Specifically, we first introduce parameter-guided behavior cloning (PBC) to address the lack of prior knowledge about the victim agent. PBC trains a surrogate agent from demonstration data while aligning its parameters with those of the victim agent to approximate the target policy, thereby providing the gradient information required for updating adversarial perturbations. On this basis, we develop the boundary-constrained adaptive distortion attack (BADA), which incorporates an adaptive moment-based update mechanism to stabilize the search for optimal perturbations. An adaptive step size scheme is introduced, employing larger updates in the early phase to speed up convergence and smaller ones later to mitigate oscillations and stabilize the search around the optimum. To ensure physical feasibility, BADA strictly enforces radar pulse constraints by clipping parameters to their prescribed ranges at each iteration. Extensive experiments demonstrate that the proposed adversarial pulse parameters effectively disrupt DRL-based jammers, thereby improving radar detection performance under jamming conditions. These results validate the feasibility and effectiveness of the proposed antiintelligent jamming framework.
KW - Adversarial attacks
KW - antijamming
KW - deep reinforcement learning (DRL)
KW - jamming decision-making
KW - multifunction radar (MFR)
UR - https://www.scopus.com/pages/publications/105040934757
U2 - 10.1109/TAES.2026.3700141
DO - 10.1109/TAES.2026.3700141
M3 - Article
AN - SCOPUS:105040934757
SN - 0018-9251
VL - 62
SP - 11923
EP - 11940
JO - IEEE Transactions on Aerospace and Electronic Systems
JF - IEEE Transactions on Aerospace and Electronic Systems
ER -