AAAI 2025technical2 citations

Can Go AIs Be Adversarially Robust?

Tom Tseng, Euan McLean, Kellin Pelrine, Tony Tong Wang, Adam Gleave

Abstract

Prior work found that superhuman Go AIs like KataGo can be defeated by simple adversarial strategies. In this paper, we study if defenses can improve KataGo's worst-case performance. We test three natural defenses: adversarial training on hand-constructed positions, iterated adversarial training, and changing the network architecture. We find that though some of these defenses protect against previously discovered attacks, none withstand adaptive attacks. In particular, we are able to train new adversaries that reliably defeat our defended agents by causing them to blunder in ways humans would not. Our results suggest that building robust AI systems is challenging even for superhuman systems in narrow domains like Go.

BibTeX
@article{Tseng_McLean_Pelrine_Wang_Gleave_2025, title={Can Go AIs Be Adversarially Robust?}, volume={39}, url={https://ojs.aaai.org/index.php/AAAI/article/view/34980}, DOI={10.1609/aaai.v39i26.34980}, abstractNote={Prior work found that superhuman Go AIs like KataGo can be defeated by simple adversarial strategies. In this paper, we study if defenses can improve KataGo’s worst-case performance. We test three natural defenses: adversarial training on hand-constructed positions, iterated adversarial training, and changing the network architecture. We find that though some of these defenses protect against previously discovered attacks, none withstand adaptive attacks.
In particular, we are able to train new adversaries that reliably defeat our defended agents by causing them to blunder in ways humans would not. Our results suggest that building robust AI systems is challenging even for superhuman systems in narrow domains like Go.}, number={26}, journal={Proceedings of the AAAI Conference on Artificial Intelligence}, author={Tseng, Tom and McLean, Euan and Pelrine, Kellin and Wang, Tony Tong and Gleave, Adam}, year={2025}, month={Apr.}, pages={27662-27670} }
Can Go AIs Be Adversarially Robust? · AAAI 2025