Data Poisoning Attack cks on Stoch chastic c Bandits Fang Liu - - PowerPoint PPT Presentation

data poisoning attack cks on stoch chastic c bandits
SMART_READER_LITE
LIVE PREVIEW

Data Poisoning Attack cks on Stoch chastic c Bandits Fang Liu - - PowerPoint PPT Presentation

Data Poisoning Attack cks on Stoch chastic c Bandits Fang Liu and Ness Shroff Outline Background q What are bandits? q Motivations Data poisoning attacks on stochastic bandits q Offline model q Online model q Simulation results


slide-1
SLIDE 1

Data Poisoning Attack cks on Stoch chastic c Bandits

Fang Liu and Ness Shroff

slide-2
SLIDE 2
  • Background

qWhat are bandits? qMotivations

  • Data poisoning attacks on stochastic bandits

qOffline model qOnline model qSimulation results

  • Conclusions and discussions

Outline

slide-3
SLIDE 3
  • Repeated game between an agent and an environment

What are bandits?

reward agent environment action Reinforcement learning

x

Online learning MAB

x

Stochastic

slide-4
SLIDE 4
  • Model

§ At each (discrete) time t, the agent plays action At from a set of K actions § The agent receives reward , drawn from unknown distribution At

What are bandits?

YAt,t

<latexit sha1_base64="fK3DLAWfZrBJ4YWuVe+8yrb6qWg=">AB73icbVBNS8NAEN34WetX1aOXxSJ4kJKIoN6qXjxWMLalDWGz3bRLdzdhdyKU0F/hxYOKV/+ON/+N2zYHbX0w8Hhvhpl5USq4Adf9dpaWV1bX1ksb5c2t7Z3dyt7+o0kyTZlPE5HoVkQME1wxHzgI1ko1IzISrBkNbyd+84lpwxP1AKOUBZL0FY85JWCldjvMr0M4hXFYqbo1dwq8SLyCVFGBRlj56vYSmkmgApiTMdzUwhyoFTwcblbmZYSuiQ9FnHUkUkM0E+PXiMj63Sw3GibSnAU/X3RE6kMSMZ2U5JYGDmvYn4n9fJIL4Mcq7SDJis0VxJjAkePI97nHNKIiRJYRqbm/FdEA0oWAzKtsQvPmXF4l/Vruqufn1fpNkUYJHaIjdI8dIHq6A41kI8okugZvaI3RzsvzrvzMWtdcoqZA/QHzucP89iQCw=</latexit><latexit sha1_base64="fK3DLAWfZrBJ4YWuVe+8yrb6qWg=">AB73icbVBNS8NAEN34WetX1aOXxSJ4kJKIoN6qXjxWMLalDWGz3bRLdzdhdyKU0F/hxYOKV/+ON/+N2zYHbX0w8Hhvhpl5USq4Adf9dpaWV1bX1ksb5c2t7Z3dyt7+o0kyTZlPE5HoVkQME1wxHzgI1ko1IzISrBkNbyd+84lpwxP1AKOUBZL0FY85JWCldjvMr0M4hXFYqbo1dwq8SLyCVFGBRlj56vYSmkmgApiTMdzUwhyoFTwcblbmZYSuiQ9FnHUkUkM0E+PXiMj63Sw3GibSnAU/X3RE6kMSMZ2U5JYGDmvYn4n9fJIL4Mcq7SDJis0VxJjAkePI97nHNKIiRJYRqbm/FdEA0oWAzKtsQvPmXF4l/Vruqufn1fpNkUYJHaIjdI8dIHq6A41kI8okugZvaI3RzsvzrvzMWtdcoqZA/QHzucP89iQCw=</latexit><latexit sha1_base64="fK3DLAWfZrBJ4YWuVe+8yrb6qWg=">AB73icbVBNS8NAEN34WetX1aOXxSJ4kJKIoN6qXjxWMLalDWGz3bRLdzdhdyKU0F/hxYOKV/+ON/+N2zYHbX0w8Hhvhpl5USq4Adf9dpaWV1bX1ksb5c2t7Z3dyt7+o0kyTZlPE5HoVkQME1wxHzgI1ko1IzISrBkNbyd+84lpwxP1AKOUBZL0FY85JWCldjvMr0M4hXFYqbo1dwq8SLyCVFGBRlj56vYSmkmgApiTMdzUwhyoFTwcblbmZYSuiQ9FnHUkUkM0E+PXiMj63Sw3GibSnAU/X3RE6kMSMZ2U5JYGDmvYn4n9fJIL4Mcq7SDJis0VxJjAkePI97nHNKIiRJYRqbm/FdEA0oWAzKtsQvPmXF4l/Vruqufn1fpNkUYJHaIjdI8dIHq6A41kI8okugZvaI3RzsvzrvzMWtdcoqZA/QHzucP89iQCw=</latexit>
  • Regret lower bounds

§ Problem-dependent: where is expected reward § Problem-independent:

  • Performance measure

§ Regret(loss) § Minimize regret = maximize total reward

  • Popular algorithms

§ Upper Confidence Bounds (UCB), Thompson Sampling, epsilon-greedy

R(T) = E " max

i∈[K] T

X

t=1

Yi,t −

T

X

t=1

YAt,t #

<latexit sha1_base64="VZwEYdZ9FuCainyckm02XT8hLWM=">ACPHicbZBLS8QwFIVT346vUZdugoOgoEMrgroQfCAIblRmfNDWkmbSmWCaluRWHEr/mBv/gzt3blyouHVtZpyFjl4InHz3XpJzwlRwDb9ZA0MDg2PjI6NlyYmp6ZnyrNz5zrJFGV1mohEXYZEM8ElqwMHwS5TxUgcCnYR3hx0+he3TGmeyBq0U+bHpCl5xCkBg4Jy7Wy5trLjxQRaYZgfFp5gEbjmfhfk3OMSu8d+4eksDnLYcYr2pXhq1Cs9bG9Az1FG+2wA/KFbtqdwv/FU5PVFCvToLyo9dIaBYzCVQrV3HTsHPiQJOBStKXqZSugNaTLXSElipv2867AS4Y0cJQocyTgLv25kZNY63YcmsmOTd3f68D/em4G0Zafc5lmwCT9fijKBIYEd6LEDa4YBdE2glDFzV8xbRFKJjASyYEp9/yX1Ffr25X7dONyu5+L40xtIAW0TJy0CbaRUfoBNURfoGb2iN+vBerHerY/v0QGrtzOPfpX1+QUmG690</latexit><latexit sha1_base64="VZwEYdZ9FuCainyckm02XT8hLWM=">ACPHicbZBLS8QwFIVT346vUZdugoOgoEMrgroQfCAIblRmfNDWkmbSmWCaluRWHEr/mBv/gzt3blyouHVtZpyFjl4InHz3XpJzwlRwDb9ZA0MDg2PjI6NlyYmp6ZnyrNz5zrJFGV1mohEXYZEM8ElqwMHwS5TxUgcCnYR3hx0+he3TGmeyBq0U+bHpCl5xCkBg4Jy7Wy5trLjxQRaYZgfFp5gEbjmfhfk3OMSu8d+4eksDnLYcYr2pXhq1Cs9bG9Az1FG+2wA/KFbtqdwv/FU5PVFCvToLyo9dIaBYzCVQrV3HTsHPiQJOBStKXqZSugNaTLXSElipv2867AS4Y0cJQocyTgLv25kZNY63YcmsmOTd3f68D/em4G0Zafc5lmwCT9fijKBIYEd6LEDa4YBdE2glDFzV8xbRFKJjASyYEp9/yX1Ffr25X7dONyu5+L40xtIAW0TJy0CbaRUfoBNURfoGb2iN+vBerHerY/v0QGrtzOPfpX1+QUmG690</latexit><latexit sha1_base64="VZwEYdZ9FuCainyckm02XT8hLWM=">ACPHicbZBLS8QwFIVT346vUZdugoOgoEMrgroQfCAIblRmfNDWkmbSmWCaluRWHEr/mBv/gzt3blyouHVtZpyFjl4InHz3XpJzwlRwDb9ZA0MDg2PjI6NlyYmp6ZnyrNz5zrJFGV1mohEXYZEM8ElqwMHwS5TxUgcCnYR3hx0+he3TGmeyBq0U+bHpCl5xCkBg4Jy7Wy5trLjxQRaYZgfFp5gEbjmfhfk3OMSu8d+4eksDnLYcYr2pXhq1Cs9bG9Az1FG+2wA/KFbtqdwv/FU5PVFCvToLyo9dIaBYzCVQrV3HTsHPiQJOBStKXqZSugNaTLXSElipv2867AS4Y0cJQocyTgLv25kZNY63YcmsmOTd3f68D/em4G0Zafc5lmwCT9fijKBIYEd6LEDa4YBdE2glDFzV8xbRFKJjASyYEp9/yX1Ffr25X7dONyu5+L40xtIAW0TJy0CbaRUfoBNURfoGb2iN+vBerHerY/v0QGrtzOPfpX1+QUmG690</latexit>

Ω X

i

µ∗ − µi KL(µa, µ∗) log T !

<latexit sha1_base64="BuR+vJ1wgr8ILupSCqF3XjLOl6o=">ACLHicbZDfShtBFMZn/VM12hrtpTeDQYjShk0pqHdBeyEoqJBUIROX2cnZzZCZ3WXmrBCWfSFvfJVS8MIWb30OJzEXNvbAD+7xmzhdmSlr0/Udvbn5h8cPS8kplde3jp/XqxuZPm+ZGQEekKjXIbegZAIdlKjgOjPAdajgKhwej/2rWzBWpkbRxn0NI8TGUnB0UlB9Qc71xBzpiDCOrO5DgpZshwUTCd3+x9dXcgy+L0rD4m/mWi7pZMpTFtMyPjAe4G1Zrf8CdF30NzCjUyrYug+pv1U5FrSFAobm236WfYK7hBKRSUFZbyLgY8hi6DhOuwfaKybYl3XFKn0apcSdBOlHfThRcWzvSoevUHAd21huL/O6OUYHvUImWY6QiNeHolxRTOk4OtqXBgSqkQMujHR/pWLAXVToAq64EJqzK7+HzrfGYcO/F5rHU3TWCZbZJvUSZPskxY5IRekQwS5I7/I/nj3XsP3l/v6bV1zpvOfCb/lPf8AoXCqHk=</latexit><latexit sha1_base64="BuR+vJ1wgr8ILupSCqF3XjLOl6o=">ACLHicbZDfShtBFMZn/VM12hrtpTeDQYjShk0pqHdBeyEoqJBUIROX2cnZzZCZ3WXmrBCWfSFvfJVS8MIWb30OJzEXNvbAD+7xmzhdmSlr0/Udvbn5h8cPS8kplde3jp/XqxuZPm+ZGQEekKjXIbegZAIdlKjgOjPAdajgKhwej/2rWzBWpkbRxn0NI8TGUnB0UlB9Qc71xBzpiDCOrO5DgpZshwUTCd3+x9dXcgy+L0rD4m/mWi7pZMpTFtMyPjAe4G1Zrf8CdF30NzCjUyrYug+pv1U5FrSFAobm236WfYK7hBKRSUFZbyLgY8hi6DhOuwfaKybYl3XFKn0apcSdBOlHfThRcWzvSoevUHAd21huL/O6OUYHvUImWY6QiNeHolxRTOk4OtqXBgSqkQMujHR/pWLAXVToAq64EJqzK7+HzrfGYcO/F5rHU3TWCZbZJvUSZPskxY5IRekQwS5I7/I/nj3XsP3l/v6bV1zpvOfCb/lPf8AoXCqHk=</latexit><latexit sha1_base64="BuR+vJ1wgr8ILupSCqF3XjLOl6o=">ACLHicbZDfShtBFMZn/VM12hrtpTeDQYjShk0pqHdBeyEoqJBUIROX2cnZzZCZ3WXmrBCWfSFvfJVS8MIWb30OJzEXNvbAD+7xmzhdmSlr0/Udvbn5h8cPS8kplde3jp/XqxuZPm+ZGQEekKjXIbegZAIdlKjgOjPAdajgKhwej/2rWzBWpkbRxn0NI8TGUnB0UlB9Qc71xBzpiDCOrO5DgpZshwUTCd3+x9dXcgy+L0rD4m/mWi7pZMpTFtMyPjAe4G1Zrf8CdF30NzCjUyrYug+pv1U5FrSFAobm236WfYK7hBKRSUFZbyLgY8hi6DhOuwfaKybYl3XFKn0apcSdBOlHfThRcWzvSoevUHAd21huL/O6OUYHvUImWY6QiNeHolxRTOk4OtqXBgSqkQMujHR/pWLAXVToAq64EJqzK7+HzrfGYcO/F5rHU3TWCZbZJvUSZPskxY5IRekQwS5I7/I/nj3XsP3l/v6bV1zpvOfCb/lPf8AoXCqHk=</latexit>

µi

<latexit sha1_base64="L/g2Nbif5/pHGY/b/yPoMjLzs4=">AB63icbVA9SwNBEJ2LXzF+RS1tFoNgFS4iqF3QxjKCZwLJEfY2e8mS3b1jd04IR36DjYWKrX/Izn/jJrlCow8GHu/NMDMvSqWw6PtfXmldW19o7xZ2dre2d2r7h82CQzjAcskYnpRNRyKTQPUKDkndRwqiLJ29H4Zua3H7mxItH3OEl5qOhQi1gwik4Keiri3615tf9Ochf0ihIDQq0+tXP3iBhmeIamaTWdht+imFODQom+bTSyxPKRvTIe86qniNsznx07JiVMGJE6MK41krv6cyKmydqIi16kojuyNxP/87oZxpdhLnSaIdsSjOJMGEzD4nA2E4QzlxhDIj3K2EjaihDF0+FRdCY/nlvyQ4q1/V/bvzWvO6SKMR3AMp9CAC2jCLbQgAYCnuAFXj3tPXtv3vuiteQVM4fwC97HN0W8joU=</latexit><latexit sha1_base64="L/g2Nbif5/pHGY/b/yPoMjLzs4=">AB63icbVA9SwNBEJ2LXzF+RS1tFoNgFS4iqF3QxjKCZwLJEfY2e8mS3b1jd04IR36DjYWKrX/Izn/jJrlCow8GHu/NMDMvSqWw6PtfXmldW19o7xZ2dre2d2r7h82CQzjAcskYnpRNRyKTQPUKDkndRwqiLJ29H4Zua3H7mxItH3OEl5qOhQi1gwik4Keiri3615tf9Ochf0ihIDQq0+tXP3iBhmeIamaTWdht+imFODQom+bTSyxPKRvTIe86qniNsznx07JiVMGJE6MK41krv6cyKmydqIi16kojuyNxP/87oZxpdhLnSaIdsSjOJMGEzD4nA2E4QzlxhDIj3K2EjaihDF0+FRdCY/nlvyQ4q1/V/bvzWvO6SKMR3AMp9CAC2jCLbQgAYCnuAFXj3tPXtv3vuiteQVM4fwC97HN0W8joU=</latexit><latexit sha1_base64="L/g2Nbif5/pHGY/b/yPoMjLzs4=">AB63icbVA9SwNBEJ2LXzF+RS1tFoNgFS4iqF3QxjKCZwLJEfY2e8mS3b1jd04IR36DjYWKrX/Izn/jJrlCow8GHu/NMDMvSqWw6PtfXmldW19o7xZ2dre2d2r7h82CQzjAcskYnpRNRyKTQPUKDkndRwqiLJ29H4Zua3H7mxItH3OEl5qOhQi1gwik4Keiri3615tf9Ochf0ihIDQq0+tXP3iBhmeIamaTWdht+imFODQom+bTSyxPKRvTIe86qniNsznx07JiVMGJE6MK41krv6cyKmydqIi16kojuyNxP/87oZxpdhLnSaIdsSjOJMGEzD4nA2E4QzlxhDIj3K2EjaihDF0+FRdCY/nlvyQ4q1/V/bvzWvO6SKMR3AMp9CAC2jCLbQgAYCnuAFXj3tPXtv3vuiteQVM4fwC97HN0W8joU=</latexit>

Ω ⇣√ KT ⌘

<latexit sha1_base64="OGLDUleD2BV15SICbUcCikU7Q/o=">ACBHicbVA9SwNBEN2LXzF+nVpqcRiE2ISLCGoXtBEsjJAzgVwIe5u5y5K9D3fnhHCksfGv2Fio2Poj7Pw3bj4KTXw8Hhvhpl5XiK4Qtv+NnILi0vLK/nVwtr6xuaWub1zp+JUMnBYLGLZ9KgCwSNwkKOAZiKBhp6Ahte/HPmNB5CKx1EdBwm0QxpE3OeMopY65r57E0JAXQE+lx1LzG7rg9dyYMeHnXMol2x7DmSWVKimSKWsf8crsxS0OIkAmqVKtiJ9jOqETOBAwLbqogoaxPA2hpGtEQVDsbfzG0DrXStfxY6orQGqu/JzIaKjUIPd0ZUuypW8k/ue1UvTP2hmPkhQhYpNFfiosjK1RJFaXS2AoBpQJrm+1WI9KilDHVxBh1CZfXmeOMfl87J9e1KsXkzTyJM9ckBKpEJOSZVckRpxCOP5Jm8kjfjyXgx3o2PSWvOmM7skj8wPn8A8GiYag=</latexit><latexit sha1_base64="OGLDUleD2BV15SICbUcCikU7Q/o=">ACBHicbVA9SwNBEN2LXzF+nVpqcRiE2ISLCGoXtBEsjJAzgVwIe5u5y5K9D3fnhHCksfGv2Fio2Poj7Pw3bj4KTXw8Hhvhpl5XiK4Qtv+NnILi0vLK/nVwtr6xuaWub1zp+JUMnBYLGLZ9KgCwSNwkKOAZiKBhp6Ahte/HPmNB5CKx1EdBwm0QxpE3OeMopY65r57E0JAXQE+lx1LzG7rg9dyYMeHnXMol2x7DmSWVKimSKWsf8crsxS0OIkAmqVKtiJ9jOqETOBAwLbqogoaxPA2hpGtEQVDsbfzG0DrXStfxY6orQGqu/JzIaKjUIPd0ZUuypW8k/ue1UvTP2hmPkhQhYpNFfiosjK1RJFaXS2AoBpQJrm+1WI9KilDHVxBh1CZfXmeOMfl87J9e1KsXkzTyJM9ckBKpEJOSZVckRpxCOP5Jm8kjfjyXgx3o2PSWvOmM7skj8wPn8A8GiYag=</latexit><latexit sha1_base64="OGLDUleD2BV15SICbUcCikU7Q/o=">ACBHicbVA9SwNBEN2LXzF+nVpqcRiE2ISLCGoXtBEsjJAzgVwIe5u5y5K9D3fnhHCksfGv2Fio2Poj7Pw3bj4KTXw8Hhvhpl5XiK4Qtv+NnILi0vLK/nVwtr6xuaWub1zp+JUMnBYLGLZ9KgCwSNwkKOAZiKBhp6Ahte/HPmNB5CKx1EdBwm0QxpE3OeMopY65r57E0JAXQE+lx1LzG7rg9dyYMeHnXMol2x7DmSWVKimSKWsf8crsxS0OIkAmqVKtiJ9jOqETOBAwLbqogoaxPA2hpGtEQVDsbfzG0DrXStfxY6orQGqu/JzIaKjUIPd0ZUuypW8k/ue1UvTP2hmPkhQhYpNFfiosjK1RJFaXS2AoBpQJrm+1WI9KilDHVxBh1CZfXmeOMfl87J9e1KsXkzTyJM9ckBKpEJOSZVckRpxCOP5Jm8kjfjyXgx3o2PSWvOmM7skj8wPn8A8GiYag=</latexit>
slide-5
SLIDE 5
  • Adversarial learning is well studied in deep learning
  • How robust are bandits?
  • Many applications

§ Clinical trials § Recommendation systems § Ad placement § A/B test § A component of game-playing algorithms (MCTS), e.g. AlphaGo § Resource allocation

  • If under stealthy attack, hard to detect (due to limited feedback)

Motivations

slide-6
SLIDE 6

Offline model

  • Distributed system
  • Algorithm updates in batches

§ Yahoo! Front Page (daily)

  • Attacker manipulates the

rewards by adding

  • Target arm , sub-optimal
  • Goal: bandit plays with

high prob. at T+1

  • Cost:

bandit environment attacker bandit algorithm

at

<latexit sha1_base64="n4fYNZoWf+O7SE01lOy5ILQCY/k=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile9rDXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8fvBONoQ=</latexit><latexit sha1_base64="n4fYNZoWf+O7SE01lOy5ILQCY/k=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile9rDXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8fvBONoQ=</latexit><latexit sha1_base64="n4fYNZoWf+O7SE01lOy5ILQCY/k=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile9rDXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8fvBONoQ=</latexit>

data buffer

  • f size T

(at, rt)

<latexit sha1_base64="r1y+/ytPOgSm2sVtU7+i07T0+NE=">AB73icbVBNS8NAEN34WetX1aOXxSJUkJKIoN4KevBYwdhKG8Jmu2mX7m7C7kQob/CiwcVr/4db/4bt20O2vpg4PHeDPzolRwA67Swtr6yurZc2yptb2zu7lb39B5NkmjKfJiLR7YgYJrhiPnAQrJ1qRmQkWCsaXk/81hPThifqHkYpCyTpKx5zSsBKjzUSwqkO4SsVN26OwVeJF5BqhAM6x8dXsJzSRTQAUxpuO5KQ50cCpYONyNzMsJXRI+qxjqSKSmSCfHjzGx1bp4TjRthTgqfp7IifSmJGMbKckMDz3kT8z+tkEF8GOVdpBkzR2aI4ExgSPke97hmFMTIEkI1t7diOiCaULAZlW0I3vzLi8Q/q1/V3bvzauOmSKOEDtERqiEPXaAGukVN5COKJHpGr+jN0c6L8+58zFqXnGLmAP2B8/kDTJmPnw=</latexit><latexit sha1_base64="r1y+/ytPOgSm2sVtU7+i07T0+NE=">AB73icbVBNS8NAEN34WetX1aOXxSJUkJKIoN4KevBYwdhKG8Jmu2mX7m7C7kQob/CiwcVr/4db/4bt20O2vpg4PHeDPzolRwA67Swtr6yurZc2yptb2zu7lb39B5NkmjKfJiLR7YgYJrhiPnAQrJ1qRmQkWCsaXk/81hPThifqHkYpCyTpKx5zSsBKjzUSwqkO4SsVN26OwVeJF5BqhAM6x8dXsJzSRTQAUxpuO5KQ50cCpYONyNzMsJXRI+qxjqSKSmSCfHjzGx1bp4TjRthTgqfp7IifSmJGMbKckMDz3kT8z+tkEF8GOVdpBkzR2aI4ExgSPke97hmFMTIEkI1t7diOiCaULAZlW0I3vzLi8Q/q1/V3bvzauOmSKOEDtERqiEPXaAGukVN5COKJHpGr+jN0c6L8+58zFqXnGLmAP2B8/kDTJmPnw=</latexit><latexit sha1_base64="r1y+/ytPOgSm2sVtU7+i07T0+NE=">AB73icbVBNS8NAEN34WetX1aOXxSJUkJKIoN4KevBYwdhKG8Jmu2mX7m7C7kQob/CiwcVr/4db/4bt20O2vpg4PHeDPzolRwA67Swtr6yurZc2yptb2zu7lb39B5NkmjKfJiLR7YgYJrhiPnAQrJ1qRmQkWCsaXk/81hPThifqHkYpCyTpKx5zSsBKjzUSwqkO4SsVN26OwVeJF5BqhAM6x8dXsJzSRTQAUxpuO5KQ50cCpYONyNzMsJXRI+qxjqSKSmSCfHjzGx1bp4TjRthTgqfp7IifSmJGMbKckMDz3kT8z+tkEF8GOVdpBkzR2aI4ExgSPke97hmFMTIEkI1t7diOiCaULAZlW0I3vzLi8Q/q1/V3bvzauOmSKOEDtERqiEPXaAGukVN5COKJHpGr+jN0c6L8+58zFqXnGLmAP2B8/kDTJmPnw=</latexit>

{~ ✏a}

<latexit sha1_base64="mpcOlGBIdMliJgvQ36wbdhK6GAQ=">AB/HicbVBNS8NAEN3Ur1q/4sfNS7AInkoqgnorevFYwWihCWGznbRLN7thd1OoIfhXvHhQ8eoP8ea/cdvmoK0PBh7vzTAzL0oZVdp1v63K0vLK6lp1vbaxubW9Y+/u3SuRSQIeEUzIToQVMrB01Qz6KQScBIxeIiG1xP/YQRSUcHv9DiFIMF9TmNKsDZSaB/4uT8CkvuQKsoEL0LsF6FdxvuFM4iaZakjkq0Q/vL7wmSJcA1YVipbtNdZBjqSlhUNT8TEGKyRD3oWsoxwmoIJ9eXzjHRuk5sZCmuHam6u+JHCdKjZPIdCZYD9S8NxH/87qZji+CnPI08DJbFGcMUcLZxKF06MSiGZjQzCR1NzqkAGWmGgTWM2E0Jx/eZF4p43Lhnt7Vm9dlWlU0SE6Qieoic5RC92gNvIQY/oGb2iN+vJerHerY9Za8UqZ/bRH1ifP8H1lZ4=</latexit><latexit sha1_base64="mpcOlGBIdMliJgvQ36wbdhK6GAQ=">AB/HicbVBNS8NAEN3Ur1q/4sfNS7AInkoqgnorevFYwWihCWGznbRLN7thd1OoIfhXvHhQ8eoP8ea/cdvmoK0PBh7vzTAzL0oZVdp1v63K0vLK6lp1vbaxubW9Y+/u3SuRSQIeEUzIToQVMrB01Qz6KQScBIxeIiG1xP/YQRSUcHv9DiFIMF9TmNKsDZSaB/4uT8CkvuQKsoEL0LsF6FdxvuFM4iaZakjkq0Q/vL7wmSJcA1YVipbtNdZBjqSlhUNT8TEGKyRD3oWsoxwmoIJ9eXzjHRuk5sZCmuHam6u+JHCdKjZPIdCZYD9S8NxH/87qZji+CnPI08DJbFGcMUcLZxKF06MSiGZjQzCR1NzqkAGWmGgTWM2E0Jx/eZF4p43Lhnt7Vm9dlWlU0SE6Qieoic5RC92gNvIQY/oGb2iN+vJerHerY9Za8UqZ/bRH1ifP8H1lZ4=</latexit><latexit sha1_base64="mpcOlGBIdMliJgvQ36wbdhK6GAQ=">AB/HicbVBNS8NAEN3Ur1q/4sfNS7AInkoqgnorevFYwWihCWGznbRLN7thd1OoIfhXvHhQ8eoP8ea/cdvmoK0PBh7vzTAzL0oZVdp1v63K0vLK6lp1vbaxubW9Y+/u3SuRSQIeEUzIToQVMrB01Qz6KQScBIxeIiG1xP/YQRSUcHv9DiFIMF9TmNKsDZSaB/4uT8CkvuQKsoEL0LsF6FdxvuFM4iaZakjkq0Q/vL7wmSJcA1YVipbtNdZBjqSlhUNT8TEGKyRD3oWsoxwmoIJ9eXzjHRuk5sZCmuHam6u+JHCdKjZPIdCZYD9S8NxH/87qZji+CnPI08DJbFGcMUcLZxKF06MSiGZjQzCR1NzqkAGWmGgTWM2E0Jx/eZF4p43Lhnt7Vm9dlWlU0SE6Qieoic5RC92gNvIQY/oGb2iN+vJerHerY9Za8UqZ/bRH1ifP8H1lZ4=</latexit>

rt

<latexit sha1_base64="vrhJq5VuMJ2Go9kg8pT6KTGsLgQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxorGFNpTNdtMu3WzC7kQoT/BiwcVr/4jb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bo0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqAcpD2I6UCISjKV7nUPe9WaW3dnIMvEK0gNCjR71a9uP2FZzBUySY3peG6KQU41Cib5pNLNDE8pG9EB71iqaMxNkM9OnZATq/RJlGhbCslM/T2R09iYcRzazpji0Cx6U/E/r5NhdBnkQqUZcsXmi6JMEkzI9G/SF5ozlGNLKNPC3krYkGrK0KZTsSF4iy8vE/+sflV3785rjesijTIcwTGcgcX0IBbaIPDAbwDK/w5kjnxXl3PuatJaeYOYQ/cD5/ANQajaw=</latexit><latexit sha1_base64="vrhJq5VuMJ2Go9kg8pT6KTGsLgQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxorGFNpTNdtMu3WzC7kQoT/BiwcVr/4jb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bo0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqAcpD2I6UCISjKV7nUPe9WaW3dnIMvEK0gNCjR71a9uP2FZzBUySY3peG6KQU41Cib5pNLNDE8pG9EB71iqaMxNkM9OnZATq/RJlGhbCslM/T2R09iYcRzazpji0Cx6U/E/r5NhdBnkQqUZcsXmi6JMEkzI9G/SF5ozlGNLKNPC3krYkGrK0KZTsSF4iy8vE/+sflV3785rjesijTIcwTGcgcX0IBbaIPDAbwDK/w5kjnxXl3PuatJaeYOYQ/cD5/ANQajaw=</latexit><latexit sha1_base64="vrhJq5VuMJ2Go9kg8pT6KTGsLgQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxorGFNpTNdtMu3WzC7kQoT/BiwcVr/4jb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bo0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqAcpD2I6UCISjKV7nUPe9WaW3dnIMvEK0gNCjR71a9uP2FZzBUySY3peG6KQU41Cib5pNLNDE8pG9EB71iqaMxNkM9OnZATq/RJlGhbCslM/T2R09iYcRzazpji0Cx6U/E/r5NhdBnkQqUZcsXmi6JMEkzI9G/SF5ozlGNLKNPC3krYkGrK0KZTsSF4iy8vE/+sflV3785rjesijTIcwTGcgcX0IBbaIPDAbwDK/w5kjnxXl3PuatJaeYOYQ/cD5/ANQajaw=</latexit>

a∗

<latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit>

a∗

<latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit>

✏t

<latexit sha1_base64="RSxk6TusV/Fv1+1J9e4RqUxSIfI=">AB8HicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxgrHFNpTNdtMu3WzC7kQof/CiwcVr/4cb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bg0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqHscpD2I6UCISjKVHrs8NUImqoe9as2tuzOQZeIVpAYFmr3qV7efsCzmCpmkxnQ8N8UgpxoFk3xS6WaGp5SN6IB3LFU05ibIZxdPyIlV+iRKtC2FZKb+nshpbMw4Dm1nTHFoFr2p+J/XyTC6DHKh0gy5YvNFUSYJmT6PukLzRnKsSWUaWFvJWxINWVoQ6rYELzFl5eJf1a/qrt357XGdZFGY7gGE7BgwtowC0wQcGCp7hFd4c47w4787HvLXkFDOH8AfO5w9Gw5DW</latexit><latexit sha1_base64="RSxk6TusV/Fv1+1J9e4RqUxSIfI=">AB8HicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxgrHFNpTNdtMu3WzC7kQof/CiwcVr/4cb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bg0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqHscpD2I6UCISjKVHrs8NUImqoe9as2tuzOQZeIVpAYFmr3qV7efsCzmCpmkxnQ8N8UgpxoFk3xS6WaGp5SN6IB3LFU05ibIZxdPyIlV+iRKtC2FZKb+nshpbMw4Dm1nTHFoFr2p+J/XyTC6DHKh0gy5YvNFUSYJmT6PukLzRnKsSWUaWFvJWxINWVoQ6rYELzFl5eJf1a/qrt357XGdZFGY7gGE7BgwtowC0wQcGCp7hFd4c47w4787HvLXkFDOH8AfO5w9Gw5DW</latexit><latexit sha1_base64="RSxk6TusV/Fv1+1J9e4RqUxSIfI=">AB8HicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxgrHFNpTNdtMu3WzC7kQof/CiwcVr/4cb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bg0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqHscpD2I6UCISjKVHrs8NUImqoe9as2tuzOQZeIVpAYFmr3qV7efsCzmCpmkxnQ8N8UgpxoFk3xS6WaGp5SN6IB3LFU05ibIZxdPyIlV+iRKtC2FZKb+nshpbMw4Dm1nTHFoFr2p+J/XyTC6DHKh0gy5YvNFUSYJmT6PukLzRnKsSWUaWFvJWxINWVoQ6rYELzFl5eJf1a/qrt357XGdZFGY7gGE7BgwtowC0wQcGCp7hFd4c47w4787HvLXkFDOH8AfO5w9Gw5DW</latexit>

C(T)2 =

T

X

t=1

✏2

t =

X

a∈A

||~ ✏a||2

2.

<latexit sha1_base64="TzvrnV2ABs04AoKf2GIxptEliwU=">ACO3icbVCxThtBFNyDBxDiCFlmhUWEjTW3QkpSQEyoqEkwgYkn316t36GFXt7p913SNb5PoyGj6CjokmRGnTszZOlEBGWmk0M0/73iS5kpZ8/95bWHz1em59qa+svp27V1jfePUZoUR2BWZysx5AhaV1NglSQrPc4OQJgrPkqvDqX92jcbKTHdonGM/hQstR1IAOSlunBxud3YGId/jkS3SuKS9oBp0IsytVJkehDH9sSCSOkqBLgWo8qCqJpPoGkX5O1vFMJnE4SBsxY2m3/Jn4C9JMCdNsdx3LiLhpkoUtQkFjbC/yc+iUYkJhVY8KizmIK7jAnqMaUrT9cnZ8xbecMuSjzLinic/UvydKSK0dp4lLTpe3z72p+D+vV9DoU7+UOi8ItXj6aFQoThmfNsmH0qAgNXYEhJFuVy4uwYAg13fdlRA8P/kl6Yatzy3/y26zvT9vo8Y+sE2zQL2kbXZETtmXSbYDXtg39h379b76v3wfj5F7z5zHv2D7xfjy1DrnE=</latexit><latexit sha1_base64="TzvrnV2ABs04AoKf2GIxptEliwU=">ACO3icbVCxThtBFNyDBxDiCFlmhUWEjTW3QkpSQEyoqEkwgYkn316t36GFXt7p913SNb5PoyGj6CjokmRGnTszZOlEBGWmk0M0/73iS5kpZ8/95bWHz1em59qa+svp27V1jfePUZoUR2BWZysx5AhaV1NglSQrPc4OQJgrPkqvDqX92jcbKTHdonGM/hQstR1IAOSlunBxud3YGId/jkS3SuKS9oBp0IsytVJkehDH9sSCSOkqBLgWo8qCqJpPoGkX5O1vFMJnE4SBsxY2m3/Jn4C9JMCdNsdx3LiLhpkoUtQkFjbC/yc+iUYkJhVY8KizmIK7jAnqMaUrT9cnZ8xbecMuSjzLinic/UvydKSK0dp4lLTpe3z72p+D+vV9DoU7+UOi8ItXj6aFQoThmfNsmH0qAgNXYEhJFuVy4uwYAg13fdlRA8P/kl6Yatzy3/y26zvT9vo8Y+sE2zQL2kbXZETtmXSbYDXtg39h379b76v3wfj5F7z5zHv2D7xfjy1DrnE=</latexit><latexit sha1_base64="TzvrnV2ABs04AoKf2GIxptEliwU=">ACO3icbVCxThtBFNyDBxDiCFlmhUWEjTW3QkpSQEyoqEkwgYkn316t36GFXt7p913SNb5PoyGj6CjokmRGnTszZOlEBGWmk0M0/73iS5kpZ8/95bWHz1em59qa+svp27V1jfePUZoUR2BWZysx5AhaV1NglSQrPc4OQJgrPkqvDqX92jcbKTHdonGM/hQstR1IAOSlunBxud3YGId/jkS3SuKS9oBp0IsytVJkehDH9sSCSOkqBLgWo8qCqJpPoGkX5O1vFMJnE4SBsxY2m3/Jn4C9JMCdNsdx3LiLhpkoUtQkFjbC/yc+iUYkJhVY8KizmIK7jAnqMaUrT9cnZ8xbecMuSjzLinic/UvydKSK0dp4lLTpe3z72p+D+vV9DoU7+UOi8ItXj6aFQoThmfNsmH0qAgNXYEhJFuVy4uwYAg13fdlRA8P/kl6Yatzy3/y26zvT9vo8Y+sE2zQL2kbXZETtmXSbYDXtg39h379b76v3wfj5F7z5zHv2D7xfjy1DrnE=</latexit>

1 − δ

<latexit sha1_base64="xY/UKVehusCScHupSrlRJwdFqE=">AB7nicbVBNS8NAEN34WetX1aOXxSJ4sSQiqBcpePFYwdpCG8pmM2mXbjZxdyKU0D/hxYOKV3+PN/+N2zYHbX0w8Hhvhpl5QSqFQdf9dpaWV1bX1ksb5c2t7Z3dyt7+g0kyzaHJE5nodsAMSKGgiQIltFMNLA4ktILhzcRvPYE2IlH3OErBj1lfiUhwhlZqe6fdECSyXqXq1twp6CLxClIlBRq9ylc3THgWg0IumTEdz03Rz5lGwSWMy93MQMr4kPWhY6liMRg/n947psdWCWmUaFsK6VT9PZGz2JhRHNjOmOHAzHsT8T+vk2F06edCpRmC4rNFUSYpJnTyPA2FBo5yZAnjWthbKR8wzTjaiMo2BG/+5UXSPKtd1dy782r9ukijRA7JETkhHrkgdXJLGqRJOJHkmbySN+fReXHenY9Z65JTzByQP3A+fwDW1I9d</latexit><latexit sha1_base64="xY/UKVehusCScHupSrlRJwdFqE=">AB7nicbVBNS8NAEN34WetX1aOXxSJ4sSQiqBcpePFYwdpCG8pmM2mXbjZxdyKU0D/hxYOKV3+PN/+N2zYHbX0w8Hhvhpl5QSqFQdf9dpaWV1bX1ksb5c2t7Z3dyt7+g0kyzaHJE5nodsAMSKGgiQIltFMNLA4ktILhzcRvPYE2IlH3OErBj1lfiUhwhlZqe6fdECSyXqXq1twp6CLxClIlBRq9ylc3THgWg0IumTEdz03Rz5lGwSWMy93MQMr4kPWhY6liMRg/n947psdWCWmUaFsK6VT9PZGz2JhRHNjOmOHAzHsT8T+vk2F06edCpRmC4rNFUSYpJnTyPA2FBo5yZAnjWthbKR8wzTjaiMo2BG/+5UXSPKtd1dy782r9ukijRA7JETkhHrkgdXJLGqRJOJHkmbySN+fReXHenY9Z65JTzByQP3A+fwDW1I9d</latexit><latexit sha1_base64="xY/UKVehusCScHupSrlRJwdFqE=">AB7nicbVBNS8NAEN34WetX1aOXxSJ4sSQiqBcpePFYwdpCG8pmM2mXbjZxdyKU0D/hxYOKV3+PN/+N2zYHbX0w8Hhvhpl5QSqFQdf9dpaWV1bX1ksb5c2t7Z3dyt7+g0kyzaHJE5nodsAMSKGgiQIltFMNLA4ktILhzcRvPYE2IlH3OErBj1lfiUhwhlZqe6fdECSyXqXq1twp6CLxClIlBRq9ylc3THgWg0IumTEdz03Rz5lGwSWMy93MQMr4kPWhY6liMRg/n947psdWCWmUaFsK6VT9PZGz2JhRHNjOmOHAzHsT8T+vk2F06edCpRmC4rNFUSYpJnTyPA2FBo5yZAnjWthbKR8wzTjaiMo2BG/+5UXSPKtd1dy782r9ukijRA7JETkhHrkgdXJLGqRJOJHkmbySN+fReXHenY9Z65JTzByQP3A+fwDW1I9d</latexit>
slide-7
SLIDE 7

Offline model: epsilon greedy algorithm

  • Optimal para:
  • Post-attack empirical mean:
  • Attack error tolerance:
  • Quadratic program with linear constraints

at = ( A, αt arg maxa∈A ˜ µa(t − 1), .

<latexit sha1_base64="s/s649NGgNEhPhJti5/EgIjwkg=">ACjHicbVFda9RAFJ3Erxo/utVHXwYXpYKGRJRapVIRxMcKri3sLOFmcnd36GQSZm7cLiH/xl/km/GyW4eauFgcs565H3mtlaMk+ROEN27eun1n52507/6Dh7ujvUc/XNVYiRNZ6cqe5eBQK4MTUqTxrLYIZa7xND/3POnP9E6VZnvtK5xVsLCqLmSQB7KRr8go6NI5LhQpXeyHWRILygtrCw4o3XVrbUa15F96JEmgpQbefupf8Od8qV3Ed84L0PXS2wlpIwF24bUXWQtCmUtVnSClC2xF2XSe7PbpVfrCW2dKlqiXSmHvgk0xdBQnI3GSZxsgl9P0iEZsyFOstFvUVSyKdGQ1ODcNE1qmrVgSUndmzcOa5DnsMCpTw2U6GbtZpsdf+aRgvux/TPEN+jlihZK59Zl7pX9XO4q14P/46YNzd/NWmXqhtDI7UfzRnOqeH8aXiLkvyuCwXSKt8rl0uwIMkfMPJLSK+OfD2ZvI4P4+Tbm/Hx2EbO+wJe8r2WcoO2DH7yk7YhMkgCpLgMHgf7oZvw/h0VYaBkPNY/ZPhF/+AkiGx/U=</latexit><latexit sha1_base64="s/s649NGgNEhPhJti5/EgIjwkg=">ACjHicbVFda9RAFJ3Erxo/utVHXwYXpYKGRJRapVIRxMcKri3sLOFmcnd36GQSZm7cLiH/xl/km/GyW4eauFgcs565H3mtlaMk+ROEN27eun1n52507/6Dh7ujvUc/XNVYiRNZ6cqe5eBQK4MTUqTxrLYIZa7xND/3POnP9E6VZnvtK5xVsLCqLmSQB7KRr8go6NI5LhQpXeyHWRILygtrCw4o3XVrbUa15F96JEmgpQbefupf8Od8qV3Ed84L0PXS2wlpIwF24bUXWQtCmUtVnSClC2xF2XSe7PbpVfrCW2dKlqiXSmHvgk0xdBQnI3GSZxsgl9P0iEZsyFOstFvUVSyKdGQ1ODcNE1qmrVgSUndmzcOa5DnsMCpTw2U6GbtZpsdf+aRgvux/TPEN+jlihZK59Zl7pX9XO4q14P/46YNzd/NWmXqhtDI7UfzRnOqeH8aXiLkvyuCwXSKt8rl0uwIMkfMPJLSK+OfD2ZvI4P4+Tbm/Hx2EbO+wJe8r2WcoO2DH7yk7YhMkgCpLgMHgf7oZvw/h0VYaBkPNY/ZPhF/+AkiGx/U=</latexit><latexit sha1_base64="s/s649NGgNEhPhJti5/EgIjwkg=">ACjHicbVFda9RAFJ3Erxo/utVHXwYXpYKGRJRapVIRxMcKri3sLOFmcnd36GQSZm7cLiH/xl/km/GyW4eauFgcs565H3mtlaMk+ROEN27eun1n52507/6Dh7ujvUc/XNVYiRNZ6cqe5eBQK4MTUqTxrLYIZa7xND/3POnP9E6VZnvtK5xVsLCqLmSQB7KRr8go6NI5LhQpXeyHWRILygtrCw4o3XVrbUa15F96JEmgpQbefupf8Od8qV3Ed84L0PXS2wlpIwF24bUXWQtCmUtVnSClC2xF2XSe7PbpVfrCW2dKlqiXSmHvgk0xdBQnI3GSZxsgl9P0iEZsyFOstFvUVSyKdGQ1ODcNE1qmrVgSUndmzcOa5DnsMCpTw2U6GbtZpsdf+aRgvux/TPEN+jlihZK59Zl7pX9XO4q14P/46YNzd/NWmXqhtDI7UfzRnOqeH8aXiLkvyuCwXSKt8rl0uwIMkfMPJLSK+OfD2ZvI4P4+Tbm/Hx2EbO+wJe8r2WcoO2DH7yk7YhMkgCpLgMHgf7oZvw/h0VYaBkPNY/ZPhF/+AkiGx/U=</latexit>

αt = Θ(1/t)

<latexit sha1_base64="k6b3Axd6rHkN65OK/kKjS8M9u9c=">AB/nicbVA9SwNBEN2LXzF+RQUbm8UgxCbeiaAWSsDGMkLOBHIhzG32kiV7H+zOCSGm8K/YWKjY+jvs/Ddukis0+mDg8d4M/P8RAqNtv1l5RYWl5ZX8quFtfWNza3i9s6djlPFuMtiGaumD5pLEXEXBUreTBSH0Je84Q+uJ37jnist4qiOw4S3Q+hFIhAM0Eid4p4HMulDB+kl9ep9jlB2jvGoUyzZFXsK+pc4GSmRDLVO8dPrxiwNeYRMgtYtx06wPQKFgk+Lnip5gmwAfR4y9AIQq7bo+n9Y3polC4NYmUqQjpVf06MINR6GPqmMwTs63lvIv7ntVIMztsjESUp8ojNFgWpBjTSRi0KxRnKIeGAFPC3EpZHxQwNJEVTAjO/Mt/iXtSuajYt6el6lWRp7skwNSJg45I1VyQ2rEJYw8kCfyQl6tR+vZerPeZ605K5vZJb9gfXwDQyKUfw=</latexit><latexit sha1_base64="k6b3Axd6rHkN65OK/kKjS8M9u9c=">AB/nicbVA9SwNBEN2LXzF+RQUbm8UgxCbeiaAWSsDGMkLOBHIhzG32kiV7H+zOCSGm8K/YWKjY+jvs/Ddukis0+mDg8d4M/P8RAqNtv1l5RYWl5ZX8quFtfWNza3i9s6djlPFuMtiGaumD5pLEXEXBUreTBSH0Je84Q+uJ37jnist4qiOw4S3Q+hFIhAM0Eid4p4HMulDB+kl9ep9jlB2jvGoUyzZFXsK+pc4GSmRDLVO8dPrxiwNeYRMgtYtx06wPQKFgk+Lnip5gmwAfR4y9AIQq7bo+n9Y3polC4NYmUqQjpVf06MINR6GPqmMwTs63lvIv7ntVIMztsjESUp8ojNFgWpBjTSRi0KxRnKIeGAFPC3EpZHxQwNJEVTAjO/Mt/iXtSuajYt6el6lWRp7skwNSJg45I1VyQ2rEJYw8kCfyQl6tR+vZerPeZ605K5vZJb9gfXwDQyKUfw=</latexit><latexit sha1_base64="k6b3Axd6rHkN65OK/kKjS8M9u9c=">AB/nicbVA9SwNBEN2LXzF+RQUbm8UgxCbeiaAWSsDGMkLOBHIhzG32kiV7H+zOCSGm8K/YWKjY+jvs/Ddukis0+mDg8d4M/P8RAqNtv1l5RYWl5ZX8quFtfWNza3i9s6djlPFuMtiGaumD5pLEXEXBUreTBSH0Je84Q+uJ37jnist4qiOw4S3Q+hFIhAM0Eid4p4HMulDB+kl9ep9jlB2jvGoUyzZFXsK+pc4GSmRDLVO8dPrxiwNeYRMgtYtx06wPQKFgk+Lnip5gmwAfR4y9AIQq7bo+n9Y3polC4NYmUqQjpVf06MINR6GPqmMwTs63lvIv7ntVIMztsjESUp8ojNFgWpBjTSRi0KxRnKIeGAFPC3EpZHxQwNJEVTAjO/Mt/iXtSuajYt6el6lWRp7skwNSJg45I1VyQ2rEJYw8kCfyQl6tR+vZerPeZ605K5vZJb9gfXwDQyKUfw=</latexit>

˜ µa(t)

<latexit sha1_base64="kwFjXRmo/MBs6D0W3D4itR/9BvI=">AB+HicbVBNS8NAEN3Ur1q/oh69LBahXkoqgnqRghePFYwtNCFsNpt26W4SdieFEvpPvHhQ8epP8ea/cdvmoK0PBh7vzTAzL8wE1+A431ZlbX1jc6u6XdvZ3ds/sA+PnSaK8pcmopU9UKimeAJc4GDYL1MSJDwbrh6G7md8dMaZ4mjzDJmC/JIOExpwSMFNi2B1xErPBkPg1IA84Du+40nTnwKmVpI5KdAL7y4tSmkuWABVE637LycAviAJOBZvWvFyzjNARGbC+oQmRTPvF/PIpPjNKhONUmUoAz9XfEwWRWk9kaDolgaFe9mbif14/h/jaL3iS5cASulgU5wJDimcx4IgrRkFMDCFUcXMrpkOiCAUTVs2E0Fp+eZW4F82bpvNwW/flmlU0Qk6RQ3UQleoje5RB7mIojF6Rq/ozSqsF+vd+li0Vqxy5hj9gfX5A8FEk0M=</latexit><latexit sha1_base64="kwFjXRmo/MBs6D0W3D4itR/9BvI=">AB+HicbVBNS8NAEN3Ur1q/oh69LBahXkoqgnqRghePFYwtNCFsNpt26W4SdieFEvpPvHhQ8epP8ea/cdvmoK0PBh7vzTAzL8wE1+A431ZlbX1jc6u6XdvZ3ds/sA+PnSaK8pcmopU9UKimeAJc4GDYL1MSJDwbrh6G7md8dMaZ4mjzDJmC/JIOExpwSMFNi2B1xErPBkPg1IA84Du+40nTnwKmVpI5KdAL7y4tSmkuWABVE637LycAviAJOBZvWvFyzjNARGbC+oQmRTPvF/PIpPjNKhONUmUoAz9XfEwWRWk9kaDolgaFe9mbif14/h/jaL3iS5cASulgU5wJDimcx4IgrRkFMDCFUcXMrpkOiCAUTVs2E0Fp+eZW4F82bpvNwW/flmlU0Qk6RQ3UQleoje5RB7mIojF6Rq/ozSqsF+vd+li0Vqxy5hj9gfX5A8FEk0M=</latexit><latexit sha1_base64="kwFjXRmo/MBs6D0W3D4itR/9BvI=">AB+HicbVBNS8NAEN3Ur1q/oh69LBahXkoqgnqRghePFYwtNCFsNpt26W4SdieFEvpPvHhQ8epP8ea/cdvmoK0PBh7vzTAzL8wE1+A431ZlbX1jc6u6XdvZ3ds/sA+PnSaK8pcmopU9UKimeAJc4GDYL1MSJDwbrh6G7md8dMaZ4mjzDJmC/JIOExpwSMFNi2B1xErPBkPg1IA84Du+40nTnwKmVpI5KdAL7y4tSmkuWABVE637LycAviAJOBZvWvFyzjNARGbC+oQmRTPvF/PIpPjNKhONUmUoAz9XfEwWRWk9kaDolgaFe9mbif14/h/jaL3iS5cASulgU5wJDimcx4IgrRkFMDCFUcXMrpkOiCAUTVs2E0Fp+eZW4F82bpvNwW/flmlU0Qk6RQ3UQleoje5RB7mIojF6Rq/ozSqsF+vd+li0Vqxy5hj9gfX5A8FEk0M=</latexit>

δ = K − 1 K αT +1

<latexit sha1_base64="p4h3IJ7vs4VkZTfSmhtoOm2MOkI=">ACnicbVDLSsNAFJ3UV62vqks3Q4sgiCURQV0oBTdCNxUaW2hCuJlO2qGTBzMToYTs3fgrblyouPUL3Pk3Th8LbT1w4XDOvdx7j59wJpVpfhuFpeWV1bXiemljc2t7p7y7dy/jVBqk5jHouODpJxF1FZMcdpJBIXQ57TtD2/GfvuBCsniqKVGCXVD6EcsYASUlrxyxelRrgBfYScQLGiZVnjdwBngzAy1rHVu6Vq2bNnAvEmtGqmiGplf+cnoxSUMaKcJByq5lJsrNQChGOM1LTipAmQIfdrVNIKQSjeb/JLjQ630cBALXZHCE/X3RAahlKPQ150hqIGc98bif143VcGFm7EoSRWNyHRkHKsYjwOBveYoETxkSZABNO3YjIAnYnS8ZV0CNb8y4vEPq1d1sy7s2r9epZGER2gCjpCFjpHdXSLmshGBD2iZ/SK3own48V4Nz6mrQVjNrOP/sD4/AEFbZn2</latexit><latexit sha1_base64="p4h3IJ7vs4VkZTfSmhtoOm2MOkI=">ACnicbVDLSsNAFJ3UV62vqks3Q4sgiCURQV0oBTdCNxUaW2hCuJlO2qGTBzMToYTs3fgrblyouPUL3Pk3Th8LbT1w4XDOvdx7j59wJpVpfhuFpeWV1bXiemljc2t7p7y7dy/jVBqk5jHouODpJxF1FZMcdpJBIXQ57TtD2/GfvuBCsniqKVGCXVD6EcsYASUlrxyxelRrgBfYScQLGiZVnjdwBngzAy1rHVu6Vq2bNnAvEmtGqmiGplf+cnoxSUMaKcJByq5lJsrNQChGOM1LTipAmQIfdrVNIKQSjeb/JLjQ630cBALXZHCE/X3RAahlKPQ150hqIGc98bif143VcGFm7EoSRWNyHRkHKsYjwOBveYoETxkSZABNO3YjIAnYnS8ZV0CNb8y4vEPq1d1sy7s2r9epZGER2gCjpCFjpHdXSLmshGBD2iZ/SK3own48V4Nz6mrQVjNrOP/sD4/AEFbZn2</latexit><latexit sha1_base64="p4h3IJ7vs4VkZTfSmhtoOm2MOkI=">ACnicbVDLSsNAFJ3UV62vqks3Q4sgiCURQV0oBTdCNxUaW2hCuJlO2qGTBzMToYTs3fgrblyouPUL3Pk3Th8LbT1w4XDOvdx7j59wJpVpfhuFpeWV1bXiemljc2t7p7y7dy/jVBqk5jHouODpJxF1FZMcdpJBIXQ57TtD2/GfvuBCsniqKVGCXVD6EcsYASUlrxyxelRrgBfYScQLGiZVnjdwBngzAy1rHVu6Vq2bNnAvEmtGqmiGplf+cnoxSUMaKcJByq5lJsrNQChGOM1LTipAmQIfdrVNIKQSjeb/JLjQ630cBALXZHCE/X3RAahlKPQ150hqIGc98bif143VcGFm7EoSRWNyHRkHKsYjwOBveYoETxkSZABNO3YjIAnYnS8ZV0CNb8y4vEPq1d1sy7s2r9epZGER2gCjpCFjpHdXSLmshGBD2iZ/SK3own48V4Nz6mrQVjNrOP/sD4/AEFbZn2</latexit>

P1 : min

~ ✏a:a∈A

X

a∈A

||~ ✏a||2

2

s.t. ˜ µa∗(T) ˜ µa(T) + ⇠, 8a 6= a∗

<latexit sha1_base64="dIwav9begNyInh9BdiF4uFStNnk=">ACnicbVFdb9MwFHXC1a+CjzCg6ECDYaipJq0MQk04AEkQBRpZXqLrpxbztrtpPFzrTKDT+LH8Ib/wanKxLruJKlo3Pusa/PzQopjI3j30F45eq16zfW1ls3b92+c7d97/53k1clxz7PZV4OMjAohca+FVbioCgRVCbxIDt+3+gHp1gaket9OytwpGCqxURwsJ5K2z97abJLmRI6dewUuWNYGCFzXaewC0xopsAecZDubV3TZz98UWYqlbpVcT5f9c/nh920y1jLRDb67VCjtExVdX+isMX9cb+c8qmeHJBAc9usjPxkjYmNslLkJIC07mlr6m3pe1OHMWLopdBsgQdsqxe2v7FxjmvFGrLJRgzTOLCjhyUVnCJdYtVBgvgxzDFoYcaFJqRW+Rb06eGVM/hT/a0gX7r8OBMmamMt/ZBGJWtYb8nzas7GRn5IQuKouanz80qS1OW2WRceiRG7lzAPgpfCzUn4EJXDrV9ryISrX74M+t3oVR/2+rsvVmsUYekidkgyRkm+yRj6RH+oQHj4J3wafgc/g4/B+Cb+et4bB0vOAXKhw8AcsWc7B</latexit><latexit sha1_base64="dIwav9begNyInh9BdiF4uFStNnk=">ACnicbVFdb9MwFHXC1a+CjzCg6ECDYaipJq0MQk04AEkQBRpZXqLrpxbztrtpPFzrTKDT+LH8Ib/wanKxLruJKlo3Pusa/PzQopjI3j30F45eq16zfW1ls3b92+c7d97/53k1clxz7PZV4OMjAohca+FVbioCgRVCbxIDt+3+gHp1gaket9OytwpGCqxURwsJ5K2z97abJLmRI6dewUuWNYGCFzXaewC0xopsAecZDubV3TZz98UWYqlbpVcT5f9c/nh920y1jLRDb67VCjtExVdX+isMX9cb+c8qmeHJBAc9usjPxkjYmNslLkJIC07mlr6m3pe1OHMWLopdBsgQdsqxe2v7FxjmvFGrLJRgzTOLCjhyUVnCJdYtVBgvgxzDFoYcaFJqRW+Rb06eGVM/hT/a0gX7r8OBMmamMt/ZBGJWtYb8nzas7GRn5IQuKouanz80qS1OW2WRceiRG7lzAPgpfCzUn4EJXDrV9ryISrX74M+t3oVR/2+rsvVmsUYekidkgyRkm+yRj6RH+oQHj4J3wafgc/g4/B+Cb+et4bB0vOAXKhw8AcsWc7B</latexit><latexit sha1_base64="dIwav9begNyInh9BdiF4uFStNnk=">ACnicbVFdb9MwFHXC1a+CjzCg6ECDYaipJq0MQk04AEkQBRpZXqLrpxbztrtpPFzrTKDT+LH8Ib/wanKxLruJKlo3Pusa/PzQopjI3j30F45eq16zfW1ls3b92+c7d97/53k1clxz7PZV4OMjAohca+FVbioCgRVCbxIDt+3+gHp1gaket9OytwpGCqxURwsJ5K2z97abJLmRI6dewUuWNYGCFzXaewC0xopsAecZDubV3TZz98UWYqlbpVcT5f9c/nh920y1jLRDb67VCjtExVdX+isMX9cb+c8qmeHJBAc9usjPxkjYmNslLkJIC07mlr6m3pe1OHMWLopdBsgQdsqxe2v7FxjmvFGrLJRgzTOLCjhyUVnCJdYtVBgvgxzDFoYcaFJqRW+Rb06eGVM/hT/a0gX7r8OBMmamMt/ZBGJWtYb8nzas7GRn5IQuKouanz80qS1OW2WRceiRG7lzAPgpfCzUn4EJXDrV9ryISrX74M+t3oVR/2+rsvVmsUYekidkgyRkm+yRj6RH+oQHj4J3wafgc/g4/B+Cb+et4bB0vOAXKhw8AcsWc7B</latexit>
slide-8
SLIDE 8

Offline model: UCB algorithm

  • Attack error tolerance:
  • Conditional “deterministic” algorithm
  • Quadratic program with linear constraints

P2 : min

~ ✏a:a∈A

X

a∈A

||~ ✏a||2

2

s.t. ua∗(T + 1) ua(T + 1) + ⇠, 8a 6= a∗

<latexit sha1_base64="j1/Tpg50boGqOaxH2e4Eg0KXhTs=">ACmXicbVFNbxMxEPUuXyV8pXDgAeLCFRotdqNKgGVigpIUHEKoqGV4nQ160xSq7Z3sb0V0Wb5T/wVbvwbvMkeIGUkS8/vzRuPZ7JCuvi+HcQXrl67fqNjZudW7fv3L3X3bz/1eal4TjkuczNSQYWpdA4dMJPCkMgsokHmfn7xv9+AKNFbk+cvMCxwpmWkwFB+eptPtzkPb3KFNCpxW7QF4xLKyQua5T2AMmNFPgzjI6m1d02c/fFBmS5VW6+Jise5fLE7aZ8xpnNdqgxNx0YuaouUvsLpi3raDt5TtkMv3kGVrdt9l3s0CaLTXMDUlLwJRzdp97RSbu9OIqXQS+DpAU90sYg7f5ik5yXCrXjEqwdJXHhxhUYJ7jEusNKiwXwc5jhyEMNCu24Wo62pk89M6G+DX+0o0v2b0cFytq5ynxmMwu7rjXk/7R6avxpXQRelQ89VD01JSl9NmT3QiDHIn5x4AN8L3SvkZGODOb7MZQrL+5ctg2I9eR/Hn3d7Bm3YaG+QReUK2SEJekgNySAZkSHjwMNgPgQfw8fhu/Aw/LRKDYPW84D8E+GXP0o6ytY=</latexit><latexit sha1_base64="j1/Tpg50boGqOaxH2e4Eg0KXhTs=">ACmXicbVFNbxMxEPUuXyV8pXDgAeLCFRotdqNKgGVigpIUHEKoqGV4nQ160xSq7Z3sb0V0Wb5T/wVbvwbvMkeIGUkS8/vzRuPZ7JCuvi+HcQXrl67fqNjZudW7fv3L3X3bz/1eal4TjkuczNSQYWpdA4dMJPCkMgsokHmfn7xv9+AKNFbk+cvMCxwpmWkwFB+eptPtzkPb3KFNCpxW7QF4xLKyQua5T2AMmNFPgzjI6m1d02c/fFBmS5VW6+Jise5fLE7aZ8xpnNdqgxNx0YuaouUvsLpi3raDt5TtkMv3kGVrdt9l3s0CaLTXMDUlLwJRzdp97RSbu9OIqXQS+DpAU90sYg7f5ik5yXCrXjEqwdJXHhxhUYJ7jEusNKiwXwc5jhyEMNCu24Wo62pk89M6G+DX+0o0v2b0cFytq5ynxmMwu7rjXk/7R6avxpXQRelQ89VD01JSl9NmT3QiDHIn5x4AN8L3SvkZGODOb7MZQrL+5ctg2I9eR/Hn3d7Bm3YaG+QReUK2SEJekgNySAZkSHjwMNgPgQfw8fhu/Aw/LRKDYPW84D8E+GXP0o6ytY=</latexit><latexit sha1_base64="j1/Tpg50boGqOaxH2e4Eg0KXhTs=">ACmXicbVFNbxMxEPUuXyV8pXDgAeLCFRotdqNKgGVigpIUHEKoqGV4nQ160xSq7Z3sb0V0Wb5T/wVbvwbvMkeIGUkS8/vzRuPZ7JCuvi+HcQXrl67fqNjZudW7fv3L3X3bz/1eal4TjkuczNSQYWpdA4dMJPCkMgsokHmfn7xv9+AKNFbk+cvMCxwpmWkwFB+eptPtzkPb3KFNCpxW7QF4xLKyQua5T2AMmNFPgzjI6m1d02c/fFBmS5VW6+Jise5fLE7aZ8xpnNdqgxNx0YuaouUvsLpi3raDt5TtkMv3kGVrdt9l3s0CaLTXMDUlLwJRzdp97RSbu9OIqXQS+DpAU90sYg7f5ik5yXCrXjEqwdJXHhxhUYJ7jEusNKiwXwc5jhyEMNCu24Wo62pk89M6G+DX+0o0v2b0cFytq5ynxmMwu7rjXk/7R6avxpXQRelQ89VD01JSl9NmT3QiDHIn5x4AN8L3SvkZGODOb7MZQrL+5ctg2I9eR/Hn3d7Bm3YaG+QReUK2SEJekgNySAZkSHjwMNgPgQfw8fhu/Aw/LRKDYPW84D8E+GXP0o6ytY=</latexit>

at = arg max

a∈A ua(t) := ˜

µa(t − 1) + 3σ s log t Na(t − 1).

<latexit sha1_base64="/mQRMGAmxSs+Wv2L7AZTKDabTk=">ACUHicbVHPaxQxGM1s1dbx17Y9egkuQou4zKigLbRUvHgqFVxb2CzDN9nMbGiSmSbfiEuYf7GHevL/8OJBbWa7grY+CHm890LyveS1kg6T5FvUW7l1+87q2t343v0HDx/1zc+uaqxXIx4pSp7koMTShoxQolKnNRWgM6VOM5P3X+8WdhnazMR5zXYqKhNLKQHDBIWX8GdI9ysCWTMOXzAOTJjCcVD+bdvSJoMt3Ka7IYRSTYVnumk7Xm6TZ/Rl8zJUgNzZxY9Kyxwz1RVUmz94TLVtsM4zvqDZJgsQG+SdEkGZImjrH/BphVvtDIFTg3TpMaJx4sSq5EG7PGiRr4KZRiHKgBLdzELxp6dOgTGlR2bAM0oX69wkP2rm5zkOym9Vd9zrxf964weLNxEtTNygMv7qoaBTFinb10qm0gqOaBwLcyvBWymcQWsHwCV0J6fWRb5LRi+HOMPnwanCwv2xjTwmT8gWSclrckDekyMyIpyck+/kJ/kVfY1+RL970VX0z042yT/oxZdi87Ld</latexit><latexit sha1_base64="/mQRMGAmxSs+Wv2L7AZTKDabTk=">ACUHicbVHPaxQxGM1s1dbx17Y9egkuQou4zKigLbRUvHgqFVxb2CzDN9nMbGiSmSbfiEuYf7GHevL/8OJBbWa7grY+CHm890LyveS1kg6T5FvUW7l1+87q2t343v0HDx/1zc+uaqxXIx4pSp7koMTShoxQolKnNRWgM6VOM5P3X+8WdhnazMR5zXYqKhNLKQHDBIWX8GdI9ysCWTMOXzAOTJjCcVD+bdvSJoMt3Ka7IYRSTYVnumk7Xm6TZ/Rl8zJUgNzZxY9Kyxwz1RVUmz94TLVtsM4zvqDZJgsQG+SdEkGZImjrH/BphVvtDIFTg3TpMaJx4sSq5EG7PGiRr4KZRiHKgBLdzELxp6dOgTGlR2bAM0oX69wkP2rm5zkOym9Vd9zrxf964weLNxEtTNygMv7qoaBTFinb10qm0gqOaBwLcyvBWymcQWsHwCV0J6fWRb5LRi+HOMPnwanCwv2xjTwmT8gWSclrckDekyMyIpyck+/kJ/kVfY1+RL970VX0z042yT/oxZdi87Ld</latexit><latexit sha1_base64="/mQRMGAmxSs+Wv2L7AZTKDabTk=">ACUHicbVHPaxQxGM1s1dbx17Y9egkuQou4zKigLbRUvHgqFVxb2CzDN9nMbGiSmSbfiEuYf7GHevL/8OJBbWa7grY+CHm890LyveS1kg6T5FvUW7l1+87q2t343v0HDx/1zc+uaqxXIx4pSp7koMTShoxQolKnNRWgM6VOM5P3X+8WdhnazMR5zXYqKhNLKQHDBIWX8GdI9ysCWTMOXzAOTJjCcVD+bdvSJoMt3Ka7IYRSTYVnumk7Xm6TZ/Rl8zJUgNzZxY9Kyxwz1RVUmz94TLVtsM4zvqDZJgsQG+SdEkGZImjrH/BphVvtDIFTg3TpMaJx4sSq5EG7PGiRr4KZRiHKgBLdzELxp6dOgTGlR2bAM0oX69wkP2rm5zkOym9Vd9zrxf964weLNxEtTNygMv7qoaBTFinb10qm0gqOaBwLcyvBWymcQWsHwCV0J6fWRb5LRi+HOMPnwanCwv2xjTwmT8gWSclrckDekyMyIpyck+/kJ/kVfY1+RL970VX0z042yT/oxZdi87Ld</latexit>

δ = 0

<latexit sha1_base64="BOHPRlRGv1vY0mJoqrq7oAf76Ls=">AB8nicbVBNS8NAEN3Urxq/qh69LBbBU0lEUA9KwYvHCsYWmlA2m027dLMJuxOhP4NLx5UvPprvPlv3LQ5aOuDgcd7M8zMCzPBNTjOt1VbWV1b36hv2lvbO7t7jf2DR53mijKPpiJVvZBoJrhkHnAQrJcpRpJQsG4vi397hNTmqfyASYZCxIylDzmlICRfD9iAgi+xo5tDxpNp+XMgJeJW5EmqtAZNL78KV5wiRQbTu04GQUEUcCrY1PZzTJCx2TI+oZKkjAdFLObp/jEKBGOU2VKAp6pvycKkmg9SULTmRAY6UWvFP/z+jnEl0HBZYDk3S+KM4FhSXAeCIK0ZBTAwhVHFzK6YjogFE1MZgrv48jLxzlpXLef+vNm+qdKoyN0jE6Riy5QG92hDvIQRl6Rq/ozcqtF+vd+pi31qxq5hD9gfX5Aw7Ij+g=</latexit><latexit sha1_base64="BOHPRlRGv1vY0mJoqrq7oAf76Ls=">AB8nicbVBNS8NAEN3Urxq/qh69LBbBU0lEUA9KwYvHCsYWmlA2m027dLMJuxOhP4NLx5UvPprvPlv3LQ5aOuDgcd7M8zMCzPBNTjOt1VbWV1b36hv2lvbO7t7jf2DR53mijKPpiJVvZBoJrhkHnAQrJcpRpJQsG4vi397hNTmqfyASYZCxIylDzmlICRfD9iAgi+xo5tDxpNp+XMgJeJW5EmqtAZNL78KV5wiRQbTu04GQUEUcCrY1PZzTJCx2TI+oZKkjAdFLObp/jEKBGOU2VKAp6pvycKkmg9SULTmRAY6UWvFP/z+jnEl0HBZYDk3S+KM4FhSXAeCIK0ZBTAwhVHFzK6YjogFE1MZgrv48jLxzlpXLef+vNm+qdKoyN0jE6Riy5QG92hDvIQRl6Rq/ozcqtF+vd+pi31qxq5hD9gfX5Aw7Ij+g=</latexit><latexit sha1_base64="BOHPRlRGv1vY0mJoqrq7oAf76Ls=">AB8nicbVBNS8NAEN3Urxq/qh69LBbBU0lEUA9KwYvHCsYWmlA2m027dLMJuxOhP4NLx5UvPprvPlv3LQ5aOuDgcd7M8zMCzPBNTjOt1VbWV1b36hv2lvbO7t7jf2DR53mijKPpiJVvZBoJrhkHnAQrJcpRpJQsG4vi397hNTmqfyASYZCxIylDzmlICRfD9iAgi+xo5tDxpNp+XMgJeJW5EmqtAZNL78KV5wiRQbTu04GQUEUcCrY1PZzTJCx2TI+oZKkjAdFLObp/jEKBGOU2VKAp6pvycKkmg9SULTmRAY6UWvFP/z+jnEl0HBZYDk3S+KM4FhSXAeCIK0ZBTAwhVHFzK6YjogFE1MZgrv48jLxzlpXLef+vNm+qdKoyN0jE6Riy5QG92hDvIQRl6Rq/ozcqtF+vd+pi31qxq5hD9gfX5Aw7Ij+g=</latexit>
slide-9
SLIDE 9

Offline model: Thompson Sampling

  • Bayesian algorithm: prior-posterior, prob. matching
  • Quadratic program with convex constraints

at = arg max

a∈A θa(t) ∼ N(˜

µa(t − 1)/σ2, σ2/Na(t − 1))

<latexit sha1_base64="Kjn5FzVaFbg2yYz5xHfqPfaoZDI=">ACVHicbVHRahQxFM1MrdZV260+hJchF3Q7UwR1Ael4otPpYJrC5t1uJO9uxuaZIbkTnEZ5if7Iv6JL4KZ7SjaeiBwOdcknuSl1p5SpLvUbx1a/v2nZ27vXv3H+zu9fcfvZF5SROZKELd5aDR60sTkiRxrPSIZhc42l+/r71Ty/QeVXYT7QucWZgadVCSaAgZX0NGfE3XIBbCgNfsxqEsoHRSoKu3zWNoBUSZDCkERdeGf7HPG6GgpSeYy1M1bSJ5+noIGSWBr4cPvtNDo47a9TL+oNknGzAb5K0IwPW4STrX4p5ISuDlqQG76dpUtKsBkdKamx6ovJYgjyHJU4DtWDQz+pNKw1/GpQ5XxQuHEt8o/49UYPxfm3ykGxX8te9VvyfN61o8WpWK1tWhFZeXbSoNKeCtxXzuXIoSa8DAelUeCuXK3AgKXxEW0J6feWbZHI4fj1OPr4YHL3t2thj9kTNmQpe8mO2Ad2wiZMskv2I4qiOPoW/Yy34u2raBx1M4/YP4h3fwE/crHp</latexit><latexit sha1_base64="Kjn5FzVaFbg2yYz5xHfqPfaoZDI=">ACVHicbVHRahQxFM1MrdZV260+hJchF3Q7UwR1Ael4otPpYJrC5t1uJO9uxuaZIbkTnEZ5if7Iv6JL4KZ7SjaeiBwOdcknuSl1p5SpLvUbx1a/v2nZ27vXv3H+zu9fcfvZF5SROZKELd5aDR60sTkiRxrPSIZhc42l+/r71Ty/QeVXYT7QucWZgadVCSaAgZX0NGfE3XIBbCgNfsxqEsoHRSoKu3zWNoBUSZDCkERdeGf7HPG6GgpSeYy1M1bSJ5+noIGSWBr4cPvtNDo47a9TL+oNknGzAb5K0IwPW4STrX4p5ISuDlqQG76dpUtKsBkdKamx6ovJYgjyHJU4DtWDQz+pNKw1/GpQ5XxQuHEt8o/49UYPxfm3ykGxX8te9VvyfN61o8WpWK1tWhFZeXbSoNKeCtxXzuXIoSa8DAelUeCuXK3AgKXxEW0J6feWbZHI4fj1OPr4YHL3t2thj9kTNmQpe8mO2Ad2wiZMskv2I4qiOPoW/Yy34u2raBx1M4/YP4h3fwE/crHp</latexit><latexit sha1_base64="Kjn5FzVaFbg2yYz5xHfqPfaoZDI=">ACVHicbVHRahQxFM1MrdZV260+hJchF3Q7UwR1Ael4otPpYJrC5t1uJO9uxuaZIbkTnEZ5if7Iv6JL4KZ7SjaeiBwOdcknuSl1p5SpLvUbx1a/v2nZ27vXv3H+zu9fcfvZF5SROZKELd5aDR60sTkiRxrPSIZhc42l+/r71Ty/QeVXYT7QucWZgadVCSaAgZX0NGfE3XIBbCgNfsxqEsoHRSoKu3zWNoBUSZDCkERdeGf7HPG6GgpSeYy1M1bSJ5+noIGSWBr4cPvtNDo47a9TL+oNknGzAb5K0IwPW4STrX4p5ISuDlqQG76dpUtKsBkdKamx6ovJYgjyHJU4DtWDQz+pNKw1/GpQ5XxQuHEt8o/49UYPxfm3ykGxX8te9VvyfN61o8WpWK1tWhFZeXbSoNKeCtxXzuXIoSa8DAelUeCuXK3AgKXxEW0J6feWbZHI4fj1OPr4YHL3t2thj9kTNmQpe8mO2Ad2wiZMskv2I4qiOPoW/Yy34u2raBx1M4/YP4h3fwE/crHp</latexit>

P3 : min

~ ✏a:a2A

X

a2A

||~ ✏a||2

2

s.t. X

a6=a∗

Φ ˜ µa(T) ˜ µa∗(T) 3p 1/ma + 1/ma∗ !  ˜ µa(T) ˜ µa∗(T)  0, 8a 6= a⇤

<latexit sha1_base64="KRihKP4kNpndsdpEftrUJGwJ2k=">ADMHicjVJLbxMxEPYurxJeKRy5WI1AKY+wSZGASEWtOMAxiIZWipPVrONrNreje2tFDnLT+LCP0FcegDElV+BN82hpBwYydanb+abGc84yQU3NopOg/DS5StXr21cr924ev2nfrm3Y8mKzRlfZqJTB8lYJjgivUt4Id5ZqBTAQ7TI7fVP7DE6YNz9SBnedsKGieMopWE/Fm8HbXrzTxURyFTtywqgjLDdcZKqMoQuEKyLBTikIt1+W+OEnb5iYQsZu3blYrOsXi1En7hBSMy3bWtOqzO7C6FJelNOBEtk6QavNxyMWaOyMInaB5sPz1PuErhydIRwycSRjvEzLR17WcyhsfVvYwoS6L5ZGq3sc8w2TMhAWPIWHCsZnqUj+ND6VvbNXT/9SsUkVPcCUgaZBCLx8Bd7FPqIW1xtRK1oavgjaK9BAK+vF9a9knNFCMmWpAGMG7Si3QwfacipYWSOFYTnQY5iwgYcKJDNDt9x4iR94Zox9G/4oi5fseYUDacxcJj6y2pBZ91Xkv3yDwqYvh46rvLBM0bNCaSGwzXD1fCYa0atmHsAVHPfK6ZT8Iuz/pNVQ2ivP/ki6Hdar1rR+eNvderaWyg+2gLNVEbvUB76B3qoT6iwefgW/A9+BF+CU/Dn+Gvs9AwWGnuob8s/P0H2X4Jew=</latexit><latexit sha1_base64="KRihKP4kNpndsdpEftrUJGwJ2k=">ADMHicjVJLbxMxEPYurxJeKRy5WI1AKY+wSZGASEWtOMAxiIZWipPVrONrNreje2tFDnLT+LCP0FcegDElV+BN82hpBwYydanb+abGc84yQU3NopOg/DS5StXr21cr924ev2nfrm3Y8mKzRlfZqJTB8lYJjgivUt4Id5ZqBTAQ7TI7fVP7DE6YNz9SBnedsKGieMopWE/Fm8HbXrzTxURyFTtywqgjLDdcZKqMoQuEKyLBTikIt1+W+OEnb5iYQsZu3blYrOsXi1En7hBSMy3bWtOqzO7C6FJelNOBEtk6QavNxyMWaOyMInaB5sPz1PuErhydIRwycSRjvEzLR17WcyhsfVvYwoS6L5ZGq3sc8w2TMhAWPIWHCsZnqUj+ND6VvbNXT/9SsUkVPcCUgaZBCLx8Bd7FPqIW1xtRK1oavgjaK9BAK+vF9a9knNFCMmWpAGMG7Si3QwfacipYWSOFYTnQY5iwgYcKJDNDt9x4iR94Zox9G/4oi5fseYUDacxcJj6y2pBZ91Xkv3yDwqYvh46rvLBM0bNCaSGwzXD1fCYa0atmHsAVHPfK6ZT8Iuz/pNVQ2ivP/ki6Hdar1rR+eNvderaWyg+2gLNVEbvUB76B3qoT6iwefgW/A9+BF+CU/Dn+Gvs9AwWGnuob8s/P0H2X4Jew=</latexit><latexit sha1_base64="KRihKP4kNpndsdpEftrUJGwJ2k=">ADMHicjVJLbxMxEPYurxJeKRy5WI1AKY+wSZGASEWtOMAxiIZWipPVrONrNreje2tFDnLT+LCP0FcegDElV+BN82hpBwYydanb+abGc84yQU3NopOg/DS5StXr21cr924ev2nfrm3Y8mKzRlfZqJTB8lYJjgivUt4Id5ZqBTAQ7TI7fVP7DE6YNz9SBnedsKGieMopWE/Fm8HbXrzTxURyFTtywqgjLDdcZKqMoQuEKyLBTikIt1+W+OEnb5iYQsZu3blYrOsXi1En7hBSMy3bWtOqzO7C6FJelNOBEtk6QavNxyMWaOyMInaB5sPz1PuErhydIRwycSRjvEzLR17WcyhsfVvYwoS6L5ZGq3sc8w2TMhAWPIWHCsZnqUj+ND6VvbNXT/9SsUkVPcCUgaZBCLx8Bd7FPqIW1xtRK1oavgjaK9BAK+vF9a9knNFCMmWpAGMG7Si3QwfacipYWSOFYTnQY5iwgYcKJDNDt9x4iR94Zox9G/4oi5fseYUDacxcJj6y2pBZ91Xkv3yDwqYvh46rvLBM0bNCaSGwzXD1fCYa0atmHsAVHPfK6ZT8Iuz/pNVQ2ivP/ki6Hdar1rR+eNvderaWyg+2gLNVEbvUB76B3qoT6iwefgW/A9+BF+CU/Dn+Gvs9AwWGnuob8s/P0H2X4Jew=</latexit>
slide-10
SLIDE 10

Online model

  • Algorithm updates online
  • Attacker manipulates the

rewards by adding

  • Target arm , sub-optimal
  • Goal: bandit plays in

with high prob.

  • Cost:

rt

<latexit sha1_base64="vrhJq5VuMJ2Go9kg8pT6KTGsLgQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxorGFNpTNdtMu3WzC7kQoT/BiwcVr/4jb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bo0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqAcpD2I6UCISjKV7nUPe9WaW3dnIMvEK0gNCjR71a9uP2FZzBUySY3peG6KQU41Cib5pNLNDE8pG9EB71iqaMxNkM9OnZATq/RJlGhbCslM/T2R09iYcRzazpji0Cx6U/E/r5NhdBnkQqUZcsXmi6JMEkzI9G/SF5ozlGNLKNPC3krYkGrK0KZTsSF4iy8vE/+sflV3785rjesijTIcwTGcgcX0IBbaIPDAbwDK/w5kjnxXl3PuatJaeYOYQ/cD5/ANQajaw=</latexit><latexit sha1_base64="vrhJq5VuMJ2Go9kg8pT6KTGsLgQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxorGFNpTNdtMu3WzC7kQoT/BiwcVr/4jb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bo0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqAcpD2I6UCISjKV7nUPe9WaW3dnIMvEK0gNCjR71a9uP2FZzBUySY3peG6KQU41Cib5pNLNDE8pG9EB71iqaMxNkM9OnZATq/RJlGhbCslM/T2R09iYcRzazpji0Cx6U/E/r5NhdBnkQqUZcsXmi6JMEkzI9G/SF5ozlGNLKNPC3krYkGrK0KZTsSF4iy8vE/+sflV3785rjesijTIcwTGcgcX0IBbaIPDAbwDK/w5kjnxXl3PuatJaeYOYQ/cD5/ANQajaw=</latexit><latexit sha1_base64="vrhJq5VuMJ2Go9kg8pT6KTGsLgQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxorGFNpTNdtMu3WzC7kQoT/BiwcVr/4jb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bo0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqAcpD2I6UCISjKV7nUPe9WaW3dnIMvEK0gNCjR71a9uP2FZzBUySY3peG6KQU41Cib5pNLNDE8pG9EB71iqaMxNkM9OnZATq/RJlGhbCslM/T2R09iYcRzazpji0Cx6U/E/r5NhdBnkQqUZcsXmi6JMEkzI9G/SF5ozlGNLKNPC3krYkGrK0KZTsSF4iy8vE/+sflV3785rjesijTIcwTGcgcX0IBbaIPDAbwDK/w5kjnxXl3PuatJaeYOYQ/cD5/ANQajaw=</latexit>

a∗

<latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit>

a∗

<latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit><latexit sha1_base64="eIrVhlCND1+kHEgBlcAOJ1KYMvg=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBZBPJRUBPUiBS8eKxpbaGOZbDft0s0m7G6EvoTvHhQ8eo/8ua/cdvmoK0PBh7vzTAzL0gE18Z1v53C0vLK6lpxvbSxubW9U97de9BxqijzaCxi1QpQM8El8w3grUSxTAKBGsGw+uJ3xiSvNY3ptRwvwI+5KHnKx0h0+nTLFbfqTkEWS0nFcjR6Ja/Or2YphGThgrUul1zE+NnqAyngo1LnVSzBOkQ+6xtqcSIaT+bnjomR1bpkTBWtqQhU/X3RIaR1qMosJ0RmoGe9ybif147NeGFn3GZpIZJOlsUpoKYmEz+Jj2uGDViZAlSxe2thA5QITU2nZINoTb/8iLxTquXVf2rFK/ytMowgEcwjHU4BzqcAMN8IBCH57hFd4c4bw4787HrLXg5DP78AfO5w9I41Q</latexit>

✏t

<latexit sha1_base64="RSxk6TusV/Fv1+1J9e4RqUxSIfI=">AB8HicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxgrHFNpTNdtMu3WzC7kQof/CiwcVr/4cb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bg0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqHscpD2I6UCISjKVHrs8NUImqoe9as2tuzOQZeIVpAYFmr3qV7efsCzmCpmkxnQ8N8UgpxoFk3xS6WaGp5SN6IB3LFU05ibIZxdPyIlV+iRKtC2FZKb+nshpbMw4Dm1nTHFoFr2p+J/XyTC6DHKh0gy5YvNFUSYJmT6PukLzRnKsSWUaWFvJWxINWVoQ6rYELzFl5eJf1a/qrt357XGdZFGY7gGE7BgwtowC0wQcGCp7hFd4c47w4787HvLXkFDOH8AfO5w9Gw5DW</latexit><latexit sha1_base64="RSxk6TusV/Fv1+1J9e4RqUxSIfI=">AB8HicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxgrHFNpTNdtMu3WzC7kQof/CiwcVr/4cb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bg0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqHscpD2I6UCISjKVHrs8NUImqoe9as2tuzOQZeIVpAYFmr3qV7efsCzmCpmkxnQ8N8UgpxoFk3xS6WaGp5SN6IB3LFU05ibIZxdPyIlV+iRKtC2FZKb+nshpbMw4Dm1nTHFoFr2p+J/XyTC6DHKh0gy5YvNFUSYJmT6PukLzRnKsSWUaWFvJWxINWVoQ6rYELzFl5eJf1a/qrt357XGdZFGY7gGE7BgwtowC0wQcGCp7hFd4c47w4787HvLXkFDOH8AfO5w9Gw5DW</latexit><latexit sha1_base64="RSxk6TusV/Fv1+1J9e4RqUxSIfI=">AB8HicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUC9S8OKxgrHFNpTNdtMu3WzC7kQof/CiwcVr/4cb/4bt20O2vpg4PHeDPzwlQKg67ZRWVtfWN8qbla3tnd296v7Bg0kyzbjPEpnodkgNl0JxHwVK3k41p3EoeSsc3Uz91hPXRiTqHscpD2I6UCISjKVHrs8NUImqoe9as2tuzOQZeIVpAYFmr3qV7efsCzmCpmkxnQ8N8UgpxoFk3xS6WaGp5SN6IB3LFU05ibIZxdPyIlV+iRKtC2FZKb+nshpbMw4Dm1nTHFoFr2p+J/XyTC6DHKh0gy5YvNFUSYJmT6PukLzRnKsSWUaWFvJWxINWVoQ6rYELzFl5eJf1a/qrt357XGdZFGY7gGE7BgwtowC0wQcGCp7hFd4c47w4787HvLXkFDOH8AfO5w9Gw5DW</latexit>

1 − δ

<latexit sha1_base64="xY/UKVehusCScHupSrlRJwdFqE=">AB7nicbVBNS8NAEN34WetX1aOXxSJ4sSQiqBcpePFYwdpCG8pmM2mXbjZxdyKU0D/hxYOKV3+PN/+N2zYHbX0w8Hhvhpl5QSqFQdf9dpaWV1bX1ksb5c2t7Z3dyt7+g0kyzaHJE5nodsAMSKGgiQIltFMNLA4ktILhzcRvPYE2IlH3OErBj1lfiUhwhlZqe6fdECSyXqXq1twp6CLxClIlBRq9ylc3THgWg0IumTEdz03Rz5lGwSWMy93MQMr4kPWhY6liMRg/n947psdWCWmUaFsK6VT9PZGz2JhRHNjOmOHAzHsT8T+vk2F06edCpRmC4rNFUSYpJnTyPA2FBo5yZAnjWthbKR8wzTjaiMo2BG/+5UXSPKtd1dy782r9ukijRA7JETkhHrkgdXJLGqRJOJHkmbySN+fReXHenY9Z65JTzByQP3A+fwDW1I9d</latexit><latexit sha1_base64="xY/UKVehusCScHupSrlRJwdFqE=">AB7nicbVBNS8NAEN34WetX1aOXxSJ4sSQiqBcpePFYwdpCG8pmM2mXbjZxdyKU0D/hxYOKV3+PN/+N2zYHbX0w8Hhvhpl5QSqFQdf9dpaWV1bX1ksb5c2t7Z3dyt7+g0kyzaHJE5nodsAMSKGgiQIltFMNLA4ktILhzcRvPYE2IlH3OErBj1lfiUhwhlZqe6fdECSyXqXq1twp6CLxClIlBRq9ylc3THgWg0IumTEdz03Rz5lGwSWMy93MQMr4kPWhY6liMRg/n947psdWCWmUaFsK6VT9PZGz2JhRHNjOmOHAzHsT8T+vk2F06edCpRmC4rNFUSYpJnTyPA2FBo5yZAnjWthbKR8wzTjaiMo2BG/+5UXSPKtd1dy782r9ukijRA7JETkhHrkgdXJLGqRJOJHkmbySN+fReXHenY9Z65JTzByQP3A+fwDW1I9d</latexit><latexit sha1_base64="xY/UKVehusCScHupSrlRJwdFqE=">AB7nicbVBNS8NAEN34WetX1aOXxSJ4sSQiqBcpePFYwdpCG8pmM2mXbjZxdyKU0D/hxYOKV3+PN/+N2zYHbX0w8Hhvhpl5QSqFQdf9dpaWV1bX1ksb5c2t7Z3dyt7+g0kyzaHJE5nodsAMSKGgiQIltFMNLA4ktILhzcRvPYE2IlH3OErBj1lfiUhwhlZqe6fdECSyXqXq1twp6CLxClIlBRq9ylc3THgWg0IumTEdz03Rz5lGwSWMy93MQMr4kPWhY6liMRg/n947psdWCWmUaFsK6VT9PZGz2JhRHNjOmOHAzHsT8T+vk2F06edCpRmC4rNFUSYpJnTyPA2FBo5yZAnjWthbKR8wzTjaiMo2BG/+5UXSPKtd1dy782r9ukijRA7JETkhHrkgdXJLGqRJOJHkmbySN+fReXHenY9Z65JTzByQP3A+fwDW1I9d</latexit>

bandit environment attacker bandit algorithm

at

<latexit sha1_base64="n4fYNZoWf+O7SE01lOy5ILQCY/k=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile9rDXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8fvBONoQ=</latexit><latexit sha1_base64="n4fYNZoWf+O7SE01lOy5ILQCY/k=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile9rDXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8fvBONoQ=</latexit><latexit sha1_base64="n4fYNZoWf+O7SE01lOy5ILQCY/k=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile9rDXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8fvBONoQ=</latexit>

rt

<latexit sha1_base64="aJWoNEKSmfY/GuVKx+UT0c8QNVQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile93DXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8f1eiNsg=</latexit><latexit sha1_base64="aJWoNEKSmfY/GuVKx+UT0c8QNVQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile93DXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8f1eiNsg=</latexit><latexit sha1_base64="aJWoNEKSmfY/GuVKx+UT0c8QNVQ=">AB6XicbVBNS8NAEJ3Ur1q/qh69LBbBU0lEUG8FPXisaGyhDWz3bRLN5uwOxFK6E/w4kHFq/Im/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/waJM+6zRCa6HVLDpVDcR4GSt1PNaRxK3gpH1O/9cS1EYl6wHKg5gOlIgEo2ile93DXrXm1t0ZyDLxClKDAs1e9avbT1gWc4VMUmM6nptikFONgk+qXQzw1PKRnTAO5YqGnMT5LNTJ+TEKn0SJdqWQjJTf0/kNDZmHIe2M6Y4NIveVPzP62QYXQa5UGmGXLH5oiTBMy/Zv0heYM5dgSyrSwtxI2pJoytOlUbAje4svLxD+rX9Xdu/Na46ZIowxHcAyn4MEFNOAWmuADgwE8wyu8OdJ5cd6dj3lrySlmDuEPnM8f1eiNsg=</latexit>

r0

t

<latexit sha1_base64="M4U/nIcl+4wFd/lEwQX+vN/2DtA=">AB6nicbVBNS8NAEJ3Ur1q/qh69LBbRU0lFUG8FPXisYGyhDWz3bRLd5OwOxFK6F/w4kHFq7/Im/GTZuDtj4YeLw3w8y8IJHCoOt+O6WV1bX1jfJmZWt7Z3evun/waOJUM+6xWMa6E1DpYi4hwIl7ySaUxVI3g7GN7nfuLaiDh6wEnCfUWHkQgFo5hL+rSP/WrNrbszkGXSKEgNCrT61a/eIGap4hEySY3pNtwE/YxqFEzyaWXGp5QNqZD3rU0obP5vdOiUnVhmQMNa2IiQz9fdERpUxExXYTkVxZBa9XPzP6YXvmZiJIUecTmi8JUEoxJ/jgZCM0ZyoklGlhbyVsRDVlaOp2BAaiy8vE+8fl137y9qzdsijTIcwTGcQMuoQl30AIPGIzgGV7hzVHOi/PufMxbS04xcwh/4Hz+ADaTjeM=</latexit><latexit sha1_base64="M4U/nIcl+4wFd/lEwQX+vN/2DtA=">AB6nicbVBNS8NAEJ3Ur1q/qh69LBbRU0lFUG8FPXisYGyhDWz3bRLd5OwOxFK6F/w4kHFq7/Im/GTZuDtj4YeLw3w8y8IJHCoOt+O6WV1bX1jfJmZWt7Z3evun/waOJUM+6xWMa6E1DpYi4hwIl7ySaUxVI3g7GN7nfuLaiDh6wEnCfUWHkQgFo5hL+rSP/WrNrbszkGXSKEgNCrT61a/eIGap4hEySY3pNtwE/YxqFEzyaWXGp5QNqZD3rU0obP5vdOiUnVhmQMNa2IiQz9fdERpUxExXYTkVxZBa9XPzP6YXvmZiJIUecTmi8JUEoxJ/jgZCM0ZyoklGlhbyVsRDVlaOp2BAaiy8vE+8fl137y9qzdsijTIcwTGcQMuoQl30AIPGIzgGV7hzVHOi/PufMxbS04xcwh/4Hz+ADaTjeM=</latexit><latexit sha1_base64="M4U/nIcl+4wFd/lEwQX+vN/2DtA=">AB6nicbVBNS8NAEJ3Ur1q/qh69LBbRU0lFUG8FPXisYGyhDWz3bRLd5OwOxFK6F/w4kHFq7/Im/GTZuDtj4YeLw3w8y8IJHCoOt+O6WV1bX1jfJmZWt7Z3evun/waOJUM+6xWMa6E1DpYi4hwIl7ySaUxVI3g7GN7nfuLaiDh6wEnCfUWHkQgFo5hL+rSP/WrNrbszkGXSKEgNCrT61a/eIGap4hEySY3pNtwE/YxqFEzyaWXGp5QNqZD3rU0obP5vdOiUnVhmQMNa2IiQz9fdERpUxExXYTkVxZBa9XPzP6YXvmZiJIUecTmi8JUEoxJ/jgZCM0ZyoklGlhbyVsRDVlaOp2BAaiy8vE+8fl137y9qzdsijTIcwTGcQMuoQl30AIPGIzgGV7hzVHOi/PufMxbS04xcwh/4Hz+ADaTjeM=</latexit>

✏t

<latexit sha1_base64="C0DSr42QirtGnNmo4v9xBW/bPQ=">AB8HicbVBNS8NAEN3Ur1q/qh69LBbBU0lEUG8FPXisYGyxDWznbRLN5uwOxFK6L/w4kHFqz/Hm/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/wYJMc/B5IhPdDpkBKRT4KFBCO9XA4lBCKxdT/3WE2gjEnWP4xSCmA2UiARnaKXHLqRGyET1sFetuXV3BrpMvILUSIFmr/rV7Sc8i0Ehl8yYjuemGORMo+ASJpVuZiBlfMQG0LFUsRhMkM8untATq/RplGhbCulM/T2Rs9iYcRzazpjh0Cx6U/E/r5NhdBnkQqUZguLzRVEmKSZ0+j7tCw0c5dgSxrWwt1I+ZJpxtCFVbAje4svLxD+rX9Xdu/Na46ZIo0yOyDE5JR65IA1yS5rEJ5wo8kxeyZtjnBfn3fmYt5acYuaQ/IHz+QNIkZDc</latexit><latexit sha1_base64="C0DSr42QirtGnNmo4v9xBW/bPQ=">AB8HicbVBNS8NAEN3Ur1q/qh69LBbBU0lEUG8FPXisYGyxDWznbRLN5uwOxFK6L/w4kHFqz/Hm/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/wYJMc/B5IhPdDpkBKRT4KFBCO9XA4lBCKxdT/3WE2gjEnWP4xSCmA2UiARnaKXHLqRGyET1sFetuXV3BrpMvILUSIFmr/rV7Sc8i0Ehl8yYjuemGORMo+ASJpVuZiBlfMQG0LFUsRhMkM8untATq/RplGhbCulM/T2Rs9iYcRzazpjh0Cx6U/E/r5NhdBnkQqUZguLzRVEmKSZ0+j7tCw0c5dgSxrWwt1I+ZJpxtCFVbAje4svLxD+rX9Xdu/Na46ZIo0yOyDE5JR65IA1yS5rEJ5wo8kxeyZtjnBfn3fmYt5acYuaQ/IHz+QNIkZDc</latexit><latexit sha1_base64="C0DSr42QirtGnNmo4v9xBW/bPQ=">AB8HicbVBNS8NAEN3Ur1q/qh69LBbBU0lEUG8FPXisYGyxDWznbRLN5uwOxFK6L/w4kHFqz/Hm/GbZuDtj4YeLw3w8y8MJXCoOt+O6WV1bX1jfJmZWt7Z3evun/wYJMc/B5IhPdDpkBKRT4KFBCO9XA4lBCKxdT/3WE2gjEnWP4xSCmA2UiARnaKXHLqRGyET1sFetuXV3BrpMvILUSIFmr/rV7Sc8i0Ehl8yYjuemGORMo+ASJpVuZiBlfMQG0LFUsRhMkM8untATq/RplGhbCulM/T2Rs9iYcRzazpjh0Cx6U/E/r5NhdBnkQqUZguLzRVEmKSZ0+j7tCw0c5dgSxrWwt1I+ZJpxtCFVbAje4svLxD+rX9Xdu/Na46ZIo0yOyDE5JR65IA1yS5rEJ5wo8kxeyZtjnBfn3fmYt5acYuaQ/IHz+QNIkZDc</latexit>

Θ(T)

<latexit sha1_base64="IjvIhjFAux8y/9cAGMZWNzR1oU=">AB73icbVBNS8NAEN34WetX1aOXxSLUS0lFUC9S8OKxQmMrbSib7aRdutmE3YlQn+Fw8qXv073vw3btsctPXBwO9GWbmBYkUBl321lZXVvf2CxsFbd3dvf2SweHDyZONQePxzLW7YAZkEKBhwIltBMNLAoktILR7dRvPYE2IlZNHCfgR2ygRCg4Qys9dptDQFZpnvVKZbfqzkCXS0nZKj0St9dfsxTyNQyCUzplNzE/QzplFwCZNiNzWQMD5iA+hYqlgExs9mB0/oqVX6NIy1LYV0pv6eyFhkzDgKbGfEcGgWvan4n9dJMbzyM6GSFEHx+aIwlRjOv2e9oUGjnJsCeNa2FspHzLNONqMijaE2uLy8Q7r15X3fuLcv0mT6NAjskJqZAauSR1ckcaxCOcROSZvJI3RzsvzrvzMW9dcfKZI/IHzucPTd2Pmg=</latexit><latexit sha1_base64="IjvIhjFAux8y/9cAGMZWNzR1oU=">AB73icbVBNS8NAEN34WetX1aOXxSLUS0lFUC9S8OKxQmMrbSib7aRdutmE3YlQn+Fw8qXv073vw3btsctPXBwO9GWbmBYkUBl321lZXVvf2CxsFbd3dvf2SweHDyZONQePxzLW7YAZkEKBhwIltBMNLAoktILR7dRvPYE2IlZNHCfgR2ygRCg4Qys9dptDQFZpnvVKZbfqzkCXS0nZKj0St9dfsxTyNQyCUzplNzE/QzplFwCZNiNzWQMD5iA+hYqlgExs9mB0/oqVX6NIy1LYV0pv6eyFhkzDgKbGfEcGgWvan4n9dJMbzyM6GSFEHx+aIwlRjOv2e9oUGjnJsCeNa2FspHzLNONqMijaE2uLy8Q7r15X3fuLcv0mT6NAjskJqZAauSR1ckcaxCOcROSZvJI3RzsvzrvzMW9dcfKZI/IHzucPTd2Pmg=</latexit><latexit sha1_base64="IjvIhjFAux8y/9cAGMZWNzR1oU=">AB73icbVBNS8NAEN34WetX1aOXxSLUS0lFUC9S8OKxQmMrbSib7aRdutmE3YlQn+Fw8qXv073vw3btsctPXBwO9GWbmBYkUBl321lZXVvf2CxsFbd3dvf2SweHDyZONQePxzLW7YAZkEKBhwIltBMNLAoktILR7dRvPYE2IlZNHCfgR2ygRCg4Qys9dptDQFZpnvVKZbfqzkCXS0nZKj0St9dfsxTyNQyCUzplNzE/QzplFwCZNiNzWQMD5iA+hYqlgExs9mB0/oqVX6NIy1LYV0pv6eyFhkzDgKbGfEcGgWvan4n9dJMbzyM6GSFEHx+aIwlRjOv2e9oUGjnJsCeNa2FspHzLNONqMijaE2uLy8Q7r15X3fuLcv0mT6NAjskJqZAauSR1ckcaxCOcROSZvJI3RzsvzrvzMW9dcfKZI/IHzucPTd2Pmg=</latexit>

C(T) =

T

X

t=1

|✏t|

<latexit sha1_base64="Tb5BNAV3Q4MstqYNodlmQoYURQw=">ACXicbVA9SwNBEN3zM8avU0ub1SDEJtyJoBaRQBrLCDkTyMWwt9lLlux9sDsnhEtqG/+KjYWKrf/Azn/jJrlCEx8MPN6bYWaeFwuwLK+jaXldW19dxGfnNre2fX3Nu/U1EiKXNoJCLZ9IhigofMAQ6CNWPJSOAJ1vAG1YnfeGBS8SiswzBm7YD0Qu5zSkBLHfOoWqyf4jJ2VRJ0Uijb4/s6HrksVlxoH/CoYxaskjUFXiR2RgoQ61jfrndiCYBC4EKolTLtmJop0QCp4KN826iWEzogPRYS9OQBEy10+krY3yilS72I6krBDxVf0+kJFBqGHi6MyDQV/PeRPzPayXgX7ZTHsYJsJDOFvmJwBDhS64yWjIaECq5vhXTPpGEgk4vr0Ow519eJM5Z6apk3Z4XKtdZGjl0iI5REdnoAlXQDaohB1H0iJ7RK3oznowX4934mLUuGdnMAfoD4/MHlHOZJg=</latexit><latexit sha1_base64="Tb5BNAV3Q4MstqYNodlmQoYURQw=">ACXicbVA9SwNBEN3zM8avU0ub1SDEJtyJoBaRQBrLCDkTyMWwt9lLlux9sDsnhEtqG/+KjYWKrf/Azn/jJrlCEx8MPN6bYWaeFwuwLK+jaXldW19dxGfnNre2fX3Nu/U1EiKXNoJCLZ9IhigofMAQ6CNWPJSOAJ1vAG1YnfeGBS8SiswzBm7YD0Qu5zSkBLHfOoWqyf4jJ2VRJ0Uijb4/s6HrksVlxoH/CoYxaskjUFXiR2RgoQ61jfrndiCYBC4EKolTLtmJop0QCp4KN826iWEzogPRYS9OQBEy10+krY3yilS72I6krBDxVf0+kJFBqGHi6MyDQV/PeRPzPayXgX7ZTHsYJsJDOFvmJwBDhS64yWjIaECq5vhXTPpGEgk4vr0Ow519eJM5Z6apk3Z4XKtdZGjl0iI5REdnoAlXQDaohB1H0iJ7RK3oznowX4934mLUuGdnMAfoD4/MHlHOZJg=</latexit><latexit sha1_base64="Tb5BNAV3Q4MstqYNodlmQoYURQw=">ACXicbVA9SwNBEN3zM8avU0ub1SDEJtyJoBaRQBrLCDkTyMWwt9lLlux9sDsnhEtqG/+KjYWKrf/Azn/jJrlCEx8MPN6bYWaeFwuwLK+jaXldW19dxGfnNre2fX3Nu/U1EiKXNoJCLZ9IhigofMAQ6CNWPJSOAJ1vAG1YnfeGBS8SiswzBm7YD0Qu5zSkBLHfOoWqyf4jJ2VRJ0Uijb4/s6HrksVlxoH/CoYxaskjUFXiR2RgoQ61jfrndiCYBC4EKolTLtmJop0QCp4KN826iWEzogPRYS9OQBEy10+krY3yilS72I6krBDxVf0+kJFBqGHi6MyDQV/PeRPzPayXgX7ZTHsYJsJDOFvmJwBDhS64yWjIaECq5vhXTPpGEgk4vr0Ow519eJM5Z6apk3Z4XKtdZGjl0iI5REdnoAlXQDaohB1H0iJ7RK3oznowX4934mLUuGdnMAfoD4/MHlHOZJg=</latexit>
slide-11
SLIDE 11

Online model: Oracle attacks

  • Attack against any bandit algorithm
  • Not practical: unknown expectations

✏t = {at 6= a∗}[µat µa∗ + ⇠]+

<latexit sha1_base64="oLjYcq/TgQTxex/C5HtkmBozcWo=">ACK3icbZBNSwMxEIazflu/qh69BIsgLS1bEdSDIHjRm4JVodmWbDrVYDa7JLNiWfYHefGvCOJBxav/w/TjoNYXAg/vzDCZN0yUtOj797E5NT0zOzcfGFhcWl5pbi6dmnj1AhoiFjF5jrkFpTU0ECJCq4TAzwKFVyFd8f9+tU9GCtjfYG9BIKI32jZlYKjs9rFYwaJlcoh0kNapQzhAbPTnGXcOUzHeEh5q8zyJovSdt/Mq0NqlfMKe5Bq9IulvyaPxAdh/oISmSks3bxhXVikUagUShubPuJxhk3KAUCvICSy0kXNzxG2g61DwCG2SDY3O65ZwO7cbGPY104P6cyHhkbS8KXWfE8db+rfXN/2rNFLv7QSZ1kiJoMVzUTRXFmPaTox1pQKDqOeDCSPdXKm654QJdvgUXQv3vyePQ2Kkd1Pz3dLRwSiNObJBNsk2qZM9ckROyBlpEeyTN5I+/ek/fqfXifw9YJbzSzTn7J+/oGvRWnfA=</latexit><latexit sha1_base64="oLjYcq/TgQTxex/C5HtkmBozcWo=">ACK3icbZBNSwMxEIazflu/qh69BIsgLS1bEdSDIHjRm4JVodmWbDrVYDa7JLNiWfYHefGvCOJBxav/w/TjoNYXAg/vzDCZN0yUtOj797E5NT0zOzcfGFhcWl5pbi6dmnj1AhoiFjF5jrkFpTU0ECJCq4TAzwKFVyFd8f9+tU9GCtjfYG9BIKI32jZlYKjs9rFYwaJlcoh0kNapQzhAbPTnGXcOUzHeEh5q8zyJovSdt/Mq0NqlfMKe5Bq9IulvyaPxAdh/oISmSks3bxhXVikUagUShubPuJxhk3KAUCvICSy0kXNzxG2g61DwCG2SDY3O65ZwO7cbGPY104P6cyHhkbS8KXWfE8db+rfXN/2rNFLv7QSZ1kiJoMVzUTRXFmPaTox1pQKDqOeDCSPdXKm654QJdvgUXQv3vyePQ2Kkd1Pz3dLRwSiNObJBNsk2qZM9ckROyBlpEeyTN5I+/ek/fqfXifw9YJbzSzTn7J+/oGvRWnfA=</latexit><latexit sha1_base64="oLjYcq/TgQTxex/C5HtkmBozcWo=">ACK3icbZBNSwMxEIazflu/qh69BIsgLS1bEdSDIHjRm4JVodmWbDrVYDa7JLNiWfYHefGvCOJBxav/w/TjoNYXAg/vzDCZN0yUtOj797E5NT0zOzcfGFhcWl5pbi6dmnj1AhoiFjF5jrkFpTU0ECJCq4TAzwKFVyFd8f9+tU9GCtjfYG9BIKI32jZlYKjs9rFYwaJlcoh0kNapQzhAbPTnGXcOUzHeEh5q8zyJovSdt/Mq0NqlfMKe5Bq9IulvyaPxAdh/oISmSks3bxhXVikUagUShubPuJxhk3KAUCvICSy0kXNzxG2g61DwCG2SDY3O65ZwO7cbGPY104P6cyHhkbS8KXWfE8db+rfXN/2rNFLv7QSZ1kiJoMVzUTRXFmPaTox1pQKDqOeDCSPdXKm654QJdvgUXQv3vyePQ2Kkd1Pz3dLRwSiNObJBNsk2qZM9ckROyBlpEeyTN5I+/ek/fqfXifw9YJbzSzTn7J+/oGvRWnfA=</latexit>

O(log T) ξ > 0 E[Na∗(T)] = T − o(T) O(P

i6=a∗[µi − µa∗ + ξ]+ log T)

<latexit sha1_base64="TrauIZECVZwyco15V4o+csEf0=">AC9nicbVJNb9NAEF2brxIopHDkMiJBSmlrOb1AD0VFCMQJgpTQSnEardeTeFV719odl0ZW/gXDoC48lu48W9Yu6kELSN5/fbNzuzMm42LTFoKw9+ef+36jZu31m637txdv3e/vfHgo9WlETgSOtPmKOYWM6lwRJIyPCoM8jzO8DA+eVX7D0/RWKnVkBYFTnI+V3ImBSdHTe89YHRhbay3kI/gJfWljkCpZzcghBzlUgCns21kZTmwEUq8RQtcAXd970o03MYbnbB4NwgQaxLlQwTFE18dpwkSFwIi5O4JNLAd3oTL4Iu2BLIRATuw0ywGDb8TmnNI6r18vxu2nFj58ue8PNCezDcEc71A3gTWlcUpNrg9tNejwrUBAmFxcIbQmkbSpzjUwrGSlN+1AnG0d56YjlTvOvmS1XyeR46KHoDVtd8IgbAyugv4KdNjKBtP2ryjRwimSGTc2nE/LGhScUPStb1sRaXFwhXG5zh2UPEc7aRq5raEJ45JYKaN+xRBw/4dUfHc2kUeu5O1Mvayryb/5xuXNHs+qaQqSkIlzi+alRmQhvoRQCKNUy1bOMCFG6sUIFLuJkXuqdQi9C+3fBWMdoO9IPyw2znYW6mxh6x6zH+uwZO2Bv2YCNmPDI+x9b75C/+L/93/cX7U91YxD9k/5v/8A7Vx6OY=</latexit><latexit sha1_base64="TrauIZECVZwyco15V4o+csEf0=">AC9nicbVJNb9NAEF2brxIopHDkMiJBSmlrOb1AD0VFCMQJgpTQSnEardeTeFV719odl0ZW/gXDoC48lu48W9Yu6kELSN5/fbNzuzMm42LTFoKw9+ef+36jZu31m637txdv3e/vfHgo9WlETgSOtPmKOYWM6lwRJIyPCoM8jzO8DA+eVX7D0/RWKnVkBYFTnI+V3ImBSdHTe89YHRhbay3kI/gJfWljkCpZzcghBzlUgCns21kZTmwEUq8RQtcAXd970o03MYbnbB4NwgQaxLlQwTFE18dpwkSFwIi5O4JNLAd3oTL4Iu2BLIRATuw0ywGDb8TmnNI6r18vxu2nFj58ue8PNCezDcEc71A3gTWlcUpNrg9tNejwrUBAmFxcIbQmkbSpzjUwrGSlN+1AnG0d56YjlTvOvmS1XyeR46KHoDVtd8IgbAyugv4KdNjKBtP2ryjRwimSGTc2nE/LGhScUPStb1sRaXFwhXG5zh2UPEc7aRq5raEJ45JYKaN+xRBw/4dUfHc2kUeu5O1Mvayryb/5xuXNHs+qaQqSkIlzi+alRmQhvoRQCKNUy1bOMCFG6sUIFLuJkXuqdQi9C+3fBWMdoO9IPyw2znYW6mxh6x6zH+uwZO2Bv2YCNmPDI+x9b75C/+L/93/cX7U91YxD9k/5v/8A7Vx6OY=</latexit><latexit sha1_base64="TrauIZECVZwyco15V4o+csEf0=">AC9nicbVJNb9NAEF2brxIopHDkMiJBSmlrOb1AD0VFCMQJgpTQSnEardeTeFV719odl0ZW/gXDoC48lu48W9Yu6kELSN5/fbNzuzMm42LTFoKw9+ef+36jZu31m637txdv3e/vfHgo9WlETgSOtPmKOYWM6lwRJIyPCoM8jzO8DA+eVX7D0/RWKnVkBYFTnI+V3ImBSdHTe89YHRhbay3kI/gJfWljkCpZzcghBzlUgCns21kZTmwEUq8RQtcAXd970o03MYbnbB4NwgQaxLlQwTFE18dpwkSFwIi5O4JNLAd3oTL4Iu2BLIRATuw0ywGDb8TmnNI6r18vxu2nFj58ue8PNCezDcEc71A3gTWlcUpNrg9tNejwrUBAmFxcIbQmkbSpzjUwrGSlN+1AnG0d56YjlTvOvmS1XyeR46KHoDVtd8IgbAyugv4KdNjKBtP2ryjRwimSGTc2nE/LGhScUPStb1sRaXFwhXG5zh2UPEc7aRq5raEJ45JYKaN+xRBw/4dUfHc2kUeu5O1Mvayryb/5xuXNHs+qaQqSkIlzi+alRmQhvoRQCKNUy1bOMCFG6sUIFLuJkXuqdQi9C+3fBWMdoO9IPyw2znYW6mxh6x6zH+uwZO2Bv2YCNmPDI+x9b75C/+L/93/cX7U91YxD9k/5v/8A7Vx6OY=</latexit>
slide-12
SLIDE 12

Adaptive attacks by constant Estimation (ACE)

  • where is decreasing in n
  • Pre-attack empirical mean:
  • Attack against any bandit algorithm
  • Adaptive and efficient: estimation
  • How: concentration inequality + union bound

✏t = {at 6= a∗}[ˆ µat(t) ˆ µa∗(t) + (Nat(t)) + (Na∗(t))]+

<latexit sha1_base64="OSMEuliGVNn/M6xCKUHqmWjMJ5k=">ACXicbZHBa9swFMZlb+26tGuz7bDLqKhkLY0OKPQ9RAI7LJeSgdLW4ic8Ky8NKybKTnsWD8T/ZWdtmfMjkJI2v3QPDx+z4h6VOSa+Uoih6D8MXLjc1XW68b2ztvdveab9du6ywEgcy05m9TcChVgYHpEjbW4R0kTjTXL/pfZvfqB1KjPfaZ5jnMKdUVMlgTwaNwuBuVPaS+I9fsIF4U8qLypRgifCZNTjMDoS1VDMgEqRFtW4tqo2HZ6so9FRjY5FgTty7+ZdbKMHMaj43GzFXWixfDnorsSLbaq3HzQUwyWaRoSGpwbtiNcopLsKSkxqohCoc5yHu4w6GXBlJ0cbmop+IHnkz4NLN+GeILur6jhNS5eZr4ZAo0c0+9Gv7PGxY0/RyXyuQFoZHLg6aF5pTxums+URYl6bkXIK3yd+VyBhYk+R9p+BK6T5/8XAw+dc470bfTVv981cYW+8j2WZt12Rnrs6/sig2YZL+CIGgE28HvcDPcCXeX0TBY7XnP/pnwx+X3LOU</latexit><latexit sha1_base64="OSMEuliGVNn/M6xCKUHqmWjMJ5k=">ACXicbZHBa9swFMZlb+26tGuz7bDLqKhkLY0OKPQ9RAI7LJeSgdLW4ic8Ky8NKybKTnsWD8T/ZWdtmfMjkJI2v3QPDx+z4h6VOSa+Uoih6D8MXLjc1XW68b2ztvdveab9du6ywEgcy05m9TcChVgYHpEjbW4R0kTjTXL/pfZvfqB1KjPfaZ5jnMKdUVMlgTwaNwuBuVPaS+I9fsIF4U8qLypRgifCZNTjMDoS1VDMgEqRFtW4tqo2HZ6so9FRjY5FgTty7+ZdbKMHMaj43GzFXWixfDnorsSLbaq3HzQUwyWaRoSGpwbtiNcopLsKSkxqohCoc5yHu4w6GXBlJ0cbmop+IHnkz4NLN+GeILur6jhNS5eZr4ZAo0c0+9Gv7PGxY0/RyXyuQFoZHLg6aF5pTxums+URYl6bkXIK3yd+VyBhYk+R9p+BK6T5/8XAw+dc470bfTVv981cYW+8j2WZt12Rnrs6/sig2YZL+CIGgE28HvcDPcCXeX0TBY7XnP/pnwx+X3LOU</latexit><latexit sha1_base64="OSMEuliGVNn/M6xCKUHqmWjMJ5k=">ACXicbZHBa9swFMZlb+26tGuz7bDLqKhkLY0OKPQ9RAI7LJeSgdLW4ic8Ky8NKybKTnsWD8T/ZWdtmfMjkJI2v3QPDx+z4h6VOSa+Uoih6D8MXLjc1XW68b2ztvdveab9du6ywEgcy05m9TcChVgYHpEjbW4R0kTjTXL/pfZvfqB1KjPfaZ5jnMKdUVMlgTwaNwuBuVPaS+I9fsIF4U8qLypRgifCZNTjMDoS1VDMgEqRFtW4tqo2HZ6so9FRjY5FgTty7+ZdbKMHMaj43GzFXWixfDnorsSLbaq3HzQUwyWaRoSGpwbtiNcopLsKSkxqohCoc5yHu4w6GXBlJ0cbmop+IHnkz4NLN+GeILur6jhNS5eZr4ZAo0c0+9Gv7PGxY0/RyXyuQFoZHLg6aF5pTxums+URYl6bkXIK3yd+VyBhYk+R9p+BK6T5/8XAw+dc470bfTVv981cYW+8j2WZt12Rnrs6/sig2YZL+CIGgE28HvcDPcCXeX0TBY7XnP/pnwx+X3LOU</latexit>

β(n) = r 2σ2 n log π2Kn2 3δ

<latexit sha1_base64="704RSO87BGFrtUlAG+9/YH5whU=">ACKnicbZBNSyNBEIZ73PUrfmxcj16aDYJewiQuqIcF2b0IXiKYVUjHUNOpiU16esbumoUwzP/xsn9lD7sHFa/+EDsfhzX6QsPLU1VU1xtlWjkKw8dg4cPHxaXldXK2vrG5qfq1uefLs2txLZMdWqvInColcE2KdJ4lVmEJNJ4GQ1/jOuXv9A6lZoLGmXYTWBgVKwkEe96ncRIcGe2efuHC3lgoRW5BFUzg1SOC6WRamFDodTLHI1HXzIzxgeijJijLXrUW1sOJ+FvTmJkam6nVq/4V/VTmCRqSGpzrNMKMugVYUlJjWRG5wzkEAbY8dZAgq5bTG4t+a4nfR6n1j9DfEL/nygcW6URL4zAbpx87UxfK/WySk+6hbKZDmhkdNFca45pXwcHO8ri5L0yBuQVvm/cnkDPhTy8VZ8CI35k9+adrN+XA/Pv9ZOjmdprLAd9oXtsQY7ZCfslLVYm0l2x/6we/YQ/A7+BY/B07R1IZjNbLNXCp5fAHNqA0=</latexit><latexit sha1_base64="704RSO87BGFrtUlAG+9/YH5whU=">ACKnicbZBNSyNBEIZ73PUrfmxcj16aDYJewiQuqIcF2b0IXiKYVUjHUNOpiU16esbumoUwzP/xsn9lD7sHFa/+EDsfhzX6QsPLU1VU1xtlWjkKw8dg4cPHxaXldXK2vrG5qfq1uefLs2txLZMdWqvInColcE2KdJ4lVmEJNJ4GQ1/jOuXv9A6lZoLGmXYTWBgVKwkEe96ncRIcGe2efuHC3lgoRW5BFUzg1SOC6WRamFDodTLHI1HXzIzxgeijJijLXrUW1sOJ+FvTmJkam6nVq/4V/VTmCRqSGpzrNMKMugVYUlJjWRG5wzkEAbY8dZAgq5bTG4t+a4nfR6n1j9DfEL/nygcW6URL4zAbpx87UxfK/WySk+6hbKZDmhkdNFca45pXwcHO8ri5L0yBuQVvm/cnkDPhTy8VZ8CI35k9+adrN+XA/Pv9ZOjmdprLAd9oXtsQY7ZCfslLVYm0l2x/6we/YQ/A7+BY/B07R1IZjNbLNXCp5fAHNqA0=</latexit><latexit sha1_base64="704RSO87BGFrtUlAG+9/YH5whU=">ACKnicbZBNSyNBEIZ73PUrfmxcj16aDYJewiQuqIcF2b0IXiKYVUjHUNOpiU16esbumoUwzP/xsn9lD7sHFa/+EDsfhzX6QsPLU1VU1xtlWjkKw8dg4cPHxaXldXK2vrG5qfq1uefLs2txLZMdWqvInColcE2KdJ4lVmEJNJ4GQ1/jOuXv9A6lZoLGmXYTWBgVKwkEe96ncRIcGe2efuHC3lgoRW5BFUzg1SOC6WRamFDodTLHI1HXzIzxgeijJijLXrUW1sOJ+FvTmJkam6nVq/4V/VTmCRqSGpzrNMKMugVYUlJjWRG5wzkEAbY8dZAgq5bTG4t+a4nfR6n1j9DfEL/nygcW6URL4zAbpx87UxfK/WySk+6hbKZDmhkdNFca45pXwcHO8ri5L0yBuQVvm/cnkDPhTy8VZ8CI35k9+adrN+XA/Pv9ZOjmdprLAd9oXtsQY7ZCfslLVYm0l2x/6we/YQ/A7+BY/B07R1IZjNbLNXCp5fAHNqA0=</latexit>

ˆ µa(t)

<latexit sha1_base64="FOsQ3n5fdyAewn4TyIe2bCbMz6U=">AB9HicbVBNS8NAEN34WetX1aOXxSLUS0lE0N4KXjxWMLbQxLZbtqlu5uwO1FK6P/w4kHFqz/Gm/GbZuDtj4YeLw3w8y8KBXcgOt+Oyura+sbm6Wt8vbO7t5+5eDw3iSZpsyniUh0JyKGCa6YDxwE6SaERkJ1o5G1O/ci04Ym6g3HKQkGisecErDSQzAkAcym/RIDc56lapbd2fAy8QrSBUVaPUqX0E/oZlkCqgxnQ9N4UwJxo4FWxSDjLDUkJHZMC6lioimQnz2dUTfGqVPo4TbUsBnqm/J3IijRnLyHZKAkOz6E3F/7xuBvFVmHOVZsAUnS+KM4EhwdMIcJ9rRkGMLSFUc3srpkOiCQUbVNmG4C2+vEz83qj7t5eVJuNIo0SOkYnqIY8dIma6Aa1kI8o0ugZvaI358l5cd6dj3nrilPMHKE/cD5/AK/VkiQ=</latexit><latexit sha1_base64="FOsQ3n5fdyAewn4TyIe2bCbMz6U=">AB9HicbVBNS8NAEN34WetX1aOXxSLUS0lE0N4KXjxWMLbQxLZbtqlu5uwO1FK6P/w4kHFqz/Gm/GbZuDtj4YeLw3w8y8KBXcgOt+Oyura+sbm6Wt8vbO7t5+5eDw3iSZpsyniUh0JyKGCa6YDxwE6SaERkJ1o5G1O/ci04Ym6g3HKQkGisecErDSQzAkAcym/RIDc56lapbd2fAy8QrSBUVaPUqX0E/oZlkCqgxnQ9N4UwJxo4FWxSDjLDUkJHZMC6lioimQnz2dUTfGqVPo4TbUsBnqm/J3IijRnLyHZKAkOz6E3F/7xuBvFVmHOVZsAUnS+KM4EhwdMIcJ9rRkGMLSFUc3srpkOiCQUbVNmG4C2+vEz83qj7t5eVJuNIo0SOkYnqIY8dIma6Aa1kI8o0ugZvaI358l5cd6dj3nrilPMHKE/cD5/AK/VkiQ=</latexit><latexit sha1_base64="FOsQ3n5fdyAewn4TyIe2bCbMz6U=">AB9HicbVBNS8NAEN34WetX1aOXxSLUS0lE0N4KXjxWMLbQxLZbtqlu5uwO1FK6P/w4kHFqz/Gm/GbZuDtj4YeLw3w8y8KBXcgOt+Oyura+sbm6Wt8vbO7t5+5eDw3iSZpsyniUh0JyKGCa6YDxwE6SaERkJ1o5G1O/ci04Ym6g3HKQkGisecErDSQzAkAcym/RIDc56lapbd2fAy8QrSBUVaPUqX0E/oZlkCqgxnQ9N4UwJxo4FWxSDjLDUkJHZMC6lioimQnz2dUTfGqVPo4TbUsBnqm/J3IijRnLyHZKAkOz6E3F/7xuBvFVmHOVZsAUnS+KM4EhwdMIcJ9rRkGMLSFUc3srpkOiCQUbVNmG4C2+vEz83qj7t5eVJuNIo0SOkYnqIY8dIma6Aa1kI8o0ugZvaI358l5cd6dj3nrilPMHKE/cD5/AK/VkiQ=</latexit>

δ ∈ (0, 1) P(E) > 1 − δ E = {∀a ∈ A, ∀t : |ˆ µa(t) − µa| < β(Na(t))}.

<latexit sha1_base64="Nl2m4SV9jCXSC3fsuykBKdXy1JA=">ACgHicbVFdi9NAFJ1k/VjrV1cfRlshATamOyLu4vKiqz4IFLBugudUm6mt9thZ5IwM1FKNv/D3+Wbf0acpBV01wsDh3PuYe49NyulMDZJfnr+zo2bt27v3undvXf/wcP+3qMvpqg0xwkvZKHPMjAoRY4TK6zEs1IjqEziaXbxtVPv6I2osg/23WJMwXnuVgKDtZR8/73D6gU0DSm7wpNA7ZAaYGJPEyGaRQMHaPArKsHjfhSfQ6HW06nPJthRp7QXBCX1FWs2WhQUraejsLB1m/aYb0j2CP6CVbga2Zqpo5hDaiI+rwHC7pS8oytB+7PiINXEQzPuDJE6otdBugUDsq3xvP+DLQpeKcwtl2DMNE1KO6tBW8ElNj1WGSyBX8A5Th3MQaGZ1V2CDX3mAV1o7qXW9qxfztqUMasVeY62+XMVa0l/6dNK7s8mNUiLyuLOd98tKxcHAVtz0EXQiO3cu0AcC3crJSvQAO37mg9F0J6deXrYLIfH8bJp/3B8eE2jV3yhDwlIUnJC3JM3pMxmRBOfnmBN/Jif8eP/Od+umn1va3nMfmn/KPfPAG7Pw=</latexit><latexit sha1_base64="Nl2m4SV9jCXSC3fsuykBKdXy1JA=">ACgHicbVFdi9NAFJ1k/VjrV1cfRlshATamOyLu4vKiqz4IFLBugudUm6mt9thZ5IwM1FKNv/D3+Wbf0acpBV01wsDh3PuYe49NyulMDZJfnr+zo2bt27v3undvXf/wcP+3qMvpqg0xwkvZKHPMjAoRY4TK6zEs1IjqEziaXbxtVPv6I2osg/23WJMwXnuVgKDtZR8/73D6gU0DSm7wpNA7ZAaYGJPEyGaRQMHaPArKsHjfhSfQ6HW06nPJthRp7QXBCX1FWs2WhQUraejsLB1m/aYb0j2CP6CVbga2Zqpo5hDaiI+rwHC7pS8oytB+7PiINXEQzPuDJE6otdBugUDsq3xvP+DLQpeKcwtl2DMNE1KO6tBW8ElNj1WGSyBX8A5Th3MQaGZ1V2CDX3mAV1o7qXW9qxfztqUMasVeY62+XMVa0l/6dNK7s8mNUiLyuLOd98tKxcHAVtz0EXQiO3cu0AcC3crJSvQAO37mg9F0J6deXrYLIfH8bJp/3B8eE2jV3yhDwlIUnJC3JM3pMxmRBOfnmBN/Jif8eP/Od+umn1va3nMfmn/KPfPAG7Pw=</latexit><latexit sha1_base64="Nl2m4SV9jCXSC3fsuykBKdXy1JA=">ACgHicbVFdi9NAFJ1k/VjrV1cfRlshATamOyLu4vKiqz4IFLBugudUm6mt9thZ5IwM1FKNv/D3+Wbf0acpBV01wsDh3PuYe49NyulMDZJfnr+zo2bt27v3undvXf/wcP+3qMvpqg0xwkvZKHPMjAoRY4TK6zEs1IjqEziaXbxtVPv6I2osg/23WJMwXnuVgKDtZR8/73D6gU0DSm7wpNA7ZAaYGJPEyGaRQMHaPArKsHjfhSfQ6HW06nPJthRp7QXBCX1FWs2WhQUraejsLB1m/aYb0j2CP6CVbga2Zqpo5hDaiI+rwHC7pS8oytB+7PiINXEQzPuDJE6otdBugUDsq3xvP+DLQpeKcwtl2DMNE1KO6tBW8ElNj1WGSyBX8A5Th3MQaGZ1V2CDX3mAV1o7qXW9qxfztqUMasVeY62+XMVa0l/6dNK7s8mNUiLyuLOd98tKxcHAVtz0EXQiO3cu0AcC3crJSvQAO37mg9F0J6deXrYLIfH8bJp/3B8eE2jV3yhDwlIUnJC3JM3pMxmRBOfnmBN/Jif8eP/Od+umn1va3nMfmn/KPfPAG7Pw=</latexit>
slide-13
SLIDE 13

Online model: ACE attacks

✏t = {at 6= a∗}[ˆ µat(t) ˆ µa∗(t) + (Nat(t)) + (Na∗(t))]+

<latexit sha1_base64="OSMEuliGVNn/M6xCKUHqmWjMJ5k=">ACXicbZHBa9swFMZlb+26tGuz7bDLqKhkLY0OKPQ9RAI7LJeSgdLW4ic8Ky8NKybKTnsWD8T/ZWdtmfMjkJI2v3QPDx+z4h6VOSa+Uoih6D8MXLjc1XW68b2ztvdveab9du6ywEgcy05m9TcChVgYHpEjbW4R0kTjTXL/pfZvfqB1KjPfaZ5jnMKdUVMlgTwaNwuBuVPaS+I9fsIF4U8qLypRgifCZNTjMDoS1VDMgEqRFtW4tqo2HZ6so9FRjY5FgTty7+ZdbKMHMaj43GzFXWixfDnorsSLbaq3HzQUwyWaRoSGpwbtiNcopLsKSkxqohCoc5yHu4w6GXBlJ0cbmop+IHnkz4NLN+GeILur6jhNS5eZr4ZAo0c0+9Gv7PGxY0/RyXyuQFoZHLg6aF5pTxums+URYl6bkXIK3yd+VyBhYk+R9p+BK6T5/8XAw+dc470bfTVv981cYW+8j2WZt12Rnrs6/sig2YZL+CIGgE28HvcDPcCXeX0TBY7XnP/pnwx+X3LOU</latexit><latexit sha1_base64="OSMEuliGVNn/M6xCKUHqmWjMJ5k=">ACXicbZHBa9swFMZlb+26tGuz7bDLqKhkLY0OKPQ9RAI7LJeSgdLW4ic8Ky8NKybKTnsWD8T/ZWdtmfMjkJI2v3QPDx+z4h6VOSa+Uoih6D8MXLjc1XW68b2ztvdveab9du6ywEgcy05m9TcChVgYHpEjbW4R0kTjTXL/pfZvfqB1KjPfaZ5jnMKdUVMlgTwaNwuBuVPaS+I9fsIF4U8qLypRgifCZNTjMDoS1VDMgEqRFtW4tqo2HZ6so9FRjY5FgTty7+ZdbKMHMaj43GzFXWixfDnorsSLbaq3HzQUwyWaRoSGpwbtiNcopLsKSkxqohCoc5yHu4w6GXBlJ0cbmop+IHnkz4NLN+GeILur6jhNS5eZr4ZAo0c0+9Gv7PGxY0/RyXyuQFoZHLg6aF5pTxums+URYl6bkXIK3yd+VyBhYk+R9p+BK6T5/8XAw+dc470bfTVv981cYW+8j2WZt12Rnrs6/sig2YZL+CIGgE28HvcDPcCXeX0TBY7XnP/pnwx+X3LOU</latexit><latexit sha1_base64="OSMEuliGVNn/M6xCKUHqmWjMJ5k=">ACXicbZHBa9swFMZlb+26tGuz7bDLqKhkLY0OKPQ9RAI7LJeSgdLW4ic8Ky8NKybKTnsWD8T/ZWdtmfMjkJI2v3QPDx+z4h6VOSa+Uoih6D8MXLjc1XW68b2ztvdveab9du6ywEgcy05m9TcChVgYHpEjbW4R0kTjTXL/pfZvfqB1KjPfaZ5jnMKdUVMlgTwaNwuBuVPaS+I9fsIF4U8qLypRgifCZNTjMDoS1VDMgEqRFtW4tqo2HZ6so9FRjY5FgTty7+ZdbKMHMaj43GzFXWixfDnorsSLbaq3HzQUwyWaRoSGpwbtiNcopLsKSkxqohCoc5yHu4w6GXBlJ0cbmop+IHnkz4NLN+GeILur6jhNS5eZr4ZAo0c0+9Gv7PGxY0/RyXyuQFoZHLg6aF5pTxums+URYl6bkXIK3yd+VyBhYk+R9p+BK6T5/8XAw+dc470bfTVv981cYW+8j2WZt12Rnrs6/sig2YZL+CIGgE28HvcDPcCXeX0TBY7XnP/pnwx+X3LOU</latexit>

∈ (0, 0.5) O(log T) 1 − 1 − 2 a⇤ Na∗(T) Na∗(T) = T − o(T)

T

X

t=1

|✏t| ≤ O @ X

a6=a∗

  • [µa − µa∗]+ + 4(1)
  • log T

1 A .

<latexit sha1_base64="RQZ0po+IMsBjYIReuZ3L0pc3t0=">ADwHicfVJLb9NAEHYTHiW8WjhyGVEjJTSN7AoEPRQVQhOtEgJrVSn0Xg9sVdr93dcVFI8ye5IP4N6ySH0laM5NF45t5fDNxqaTlIPiz0mjeuXv/uqD1sNHj58XVt/9t0WlRE0EIUqzHGMlpTUNGDJio5LQ5jHio7is/06fnRBxspC93lS0jDHVMuxFMjONVpf+d3PqDCUQ9iDz/KCNKCegB8lpBgjqdtBN+i97fhdQGurnIAzZKcIYtSJZECVFkZylgOKTNIFWZcB/IN2pIoU+h0fDKWGOKi0gn8cFAoTRFjLJXkCbhsitAy+OHWoqrfg6P/obaXsO68jY/7n1yUZyRgXHhaLG3t8cFlAon8yCjSV1LaHLw8fS1D9K1/HU0dfasXfMifbBVuJbDHxlSjsQn+rqGFdqKzU6TwlClHlUKmZNkPiMJy/dbkSNuNOXdcHbav4yotFI57vkSIkXncOD0mNsLEa64F2oKy3cJ1FejXCr1vP6w9N2IQ3UyM7bATGZlm3IEF2cu/nis6WtsIesFc4KYRLo0NbymHo7VfUVK4EUizUG7XJ2FQ8nCKhqVQNGtFlaXSTYUpnThToyNoOJ1f4AxeOU9Ss+8+zTD3Xn0xdzaSR47ZI6c2eux2nlb7KTi8fvhVOqyYtJiUWhcqXqZ9TlDIg0JVhNnoHB7lgJEhgYFu6NvORLC6yPfNAbvZ1e8G17Y29nycaq98J76bW90Hvn7XlfvENv4InGh0bSyBu6ud+UzaJ5voA2VpZvnv/SPnX9hK0o=</latexit><latexit sha1_base64="RQZ0po+IMsBjYIReuZ3L0pc3t0=">ADwHicfVJLb9NAEHYTHiW8WjhyGVEjJTSN7AoEPRQVQhOtEgJrVSn0Xg9sVdr93dcVFI8ye5IP4N6ySH0laM5NF45t5fDNxqaTlIPiz0mjeuXv/uqD1sNHj58XVt/9t0WlRE0EIUqzHGMlpTUNGDJio5LQ5jHio7is/06fnRBxspC93lS0jDHVMuxFMjONVpf+d3PqDCUQ9iDz/KCNKCegB8lpBgjqdtBN+i97fhdQGurnIAzZKcIYtSJZECVFkZylgOKTNIFWZcB/IN2pIoU+h0fDKWGOKi0gn8cFAoTRFjLJXkCbhsitAy+OHWoqrfg6P/obaXsO68jY/7n1yUZyRgXHhaLG3t8cFlAon8yCjSV1LaHLw8fS1D9K1/HU0dfasXfMifbBVuJbDHxlSjsQn+rqGFdqKzU6TwlClHlUKmZNkPiMJy/dbkSNuNOXdcHbav4yotFI57vkSIkXncOD0mNsLEa64F2oKy3cJ1FejXCr1vP6w9N2IQ3UyM7bATGZlm3IEF2cu/nis6WtsIesFc4KYRLo0NbymHo7VfUVK4EUizUG7XJ2FQ8nCKhqVQNGtFlaXSTYUpnThToyNoOJ1f4AxeOU9Ss+8+zTD3Xn0xdzaSR47ZI6c2eux2nlb7KTi8fvhVOqyYtJiUWhcqXqZ9TlDIg0JVhNnoHB7lgJEhgYFu6NvORLC6yPfNAbvZ1e8G17Y29nycaq98J76bW90Hvn7XlfvENv4InGh0bSyBu6ud+UzaJ5voA2VpZvnv/SPnX9hK0o=</latexit><latexit sha1_base64="RQZ0po+IMsBjYIReuZ3L0pc3t0=">ADwHicfVJLb9NAEHYTHiW8WjhyGVEjJTSN7AoEPRQVQhOtEgJrVSn0Xg9sVdr93dcVFI8ye5IP4N6ySH0laM5NF45t5fDNxqaTlIPiz0mjeuXv/uqD1sNHj58XVt/9t0WlRE0EIUqzHGMlpTUNGDJio5LQ5jHio7is/06fnRBxspC93lS0jDHVMuxFMjONVpf+d3PqDCUQ9iDz/KCNKCegB8lpBgjqdtBN+i97fhdQGurnIAzZKcIYtSJZECVFkZylgOKTNIFWZcB/IN2pIoU+h0fDKWGOKi0gn8cFAoTRFjLJXkCbhsitAy+OHWoqrfg6P/obaXsO68jY/7n1yUZyRgXHhaLG3t8cFlAon8yCjSV1LaHLw8fS1D9K1/HU0dfasXfMifbBVuJbDHxlSjsQn+rqGFdqKzU6TwlClHlUKmZNkPiMJy/dbkSNuNOXdcHbav4yotFI57vkSIkXncOD0mNsLEa64F2oKy3cJ1FejXCr1vP6w9N2IQ3UyM7bATGZlm3IEF2cu/nis6WtsIesFc4KYRLo0NbymHo7VfUVK4EUizUG7XJ2FQ8nCKhqVQNGtFlaXSTYUpnThToyNoOJ1f4AxeOU9Ss+8+zTD3Xn0xdzaSR47ZI6c2eux2nlb7KTi8fvhVOqyYtJiUWhcqXqZ9TlDIg0JVhNnoHB7lgJEhgYFu6NvORLC6yPfNAbvZ1e8G17Y29nycaq98J76bW90Hvn7XlfvENv4InGh0bSyBu6ud+UzaJ5voA2VpZvnv/SPnX9hK0o=</latexit>
  • Tight to oracle attack (with some additive constant)
slide-14
SLIDE 14

Simulation results: offline model

  • Gaussian distributions with random drawn expectations
  • Parameters:
  • Poisoning effort ratio:

K = 5, σ = 0.1, T = 1000, δ = 0.05

<latexit sha1_base64="9G7fT/AM9IFlTRbSQzBX9+VOSZ8=">AC3icbVBPS8MwHE39O+e/qUcvxU3wMEY6GLrDYOBF8DJhdYO1jDRNt7A0LUkqjLIP4MWv4sWDile/gDe/jenWg24+CHm8934kv+fFjEoF4bextr6xubVd2Cnu7u0fHJaOju9lAhMbByxSPQ9JAmjnNiKkb6sSAo9BjpeZPrzO89ECFpxLtqGhM3RCNOA4qR0tKwVK7cthpVR9JRiFqwZlW7LQtCWHV8wlSmwEZFp/Q9h7lKrJyUQY7OsPTl+BFOQsIVZkjKgQVj5aZIKIoZmRWdRJIY4QkakYGmHIVEul8mZl5rhXfDCKhD1fmXP09kaJQymno6WSI1Fgue5n4nzdIVHDlpTHiSIcLx4KEmaqyMyaMX0qCFZsqgnCguq/mniMBMJK91fUJVjLK68Su15r1uBdvdxu5m0UwCk4AxfApegDW5AB9gAg0fwDF7Bm/FkvBjvxsciumbkMyfgD4zPH/lKl0s=</latexit><latexit sha1_base64="9G7fT/AM9IFlTRbSQzBX9+VOSZ8=">AC3icbVBPS8MwHE39O+e/qUcvxU3wMEY6GLrDYOBF8DJhdYO1jDRNt7A0LUkqjLIP4MWv4sWDile/gDe/jenWg24+CHm8934kv+fFjEoF4bextr6xubVd2Cnu7u0fHJaOju9lAhMbByxSPQ9JAmjnNiKkb6sSAo9BjpeZPrzO89ECFpxLtqGhM3RCNOA4qR0tKwVK7cthpVR9JRiFqwZlW7LQtCWHV8wlSmwEZFp/Q9h7lKrJyUQY7OsPTl+BFOQsIVZkjKgQVj5aZIKIoZmRWdRJIY4QkakYGmHIVEul8mZl5rhXfDCKhD1fmXP09kaJQymno6WSI1Fgue5n4nzdIVHDlpTHiSIcLx4KEmaqyMyaMX0qCFZsqgnCguq/mniMBMJK91fUJVjLK68Su15r1uBdvdxu5m0UwCk4AxfApegDW5AB9gAg0fwDF7Bm/FkvBjvxsciumbkMyfgD4zPH/lKl0s=</latexit><latexit sha1_base64="9G7fT/AM9IFlTRbSQzBX9+VOSZ8=">AC3icbVBPS8MwHE39O+e/qUcvxU3wMEY6GLrDYOBF8DJhdYO1jDRNt7A0LUkqjLIP4MWv4sWDile/gDe/jenWg24+CHm8934kv+fFjEoF4bextr6xubVd2Cnu7u0fHJaOju9lAhMbByxSPQ9JAmjnNiKkb6sSAo9BjpeZPrzO89ECFpxLtqGhM3RCNOA4qR0tKwVK7cthpVR9JRiFqwZlW7LQtCWHV8wlSmwEZFp/Q9h7lKrJyUQY7OsPTl+BFOQsIVZkjKgQVj5aZIKIoZmRWdRJIY4QkakYGmHIVEul8mZl5rhXfDCKhD1fmXP09kaJQymno6WSI1Fgue5n4nzdIVHDlpTHiSIcLx4KEmaqyMyaMX0qCFZsqgnCguq/mniMBMJK91fUJVjLK68Su15r1uBdvdxu5m0UwCk4AxfApegDW5AB9gAg0fwDF7Bm/FkvBjvxsciumbkMyfgD4zPH/lKl0s=</latexit>

||~ ✏||2 ||~ r||2 = sP

a∈A ||~

✏a||2

2

P

a∈A ||~

ra||2

2

<latexit sha1_base64="eilBeCWCEGLnbPDIoUbGpDLZuY=">ACeHicfVFNT+MwEHUCuwtlPwoc4ZDdiv24VGmFByQFw4gkQBqS7RxJ2AheME20GqnPwHfhs3/gXLjhtV0BZ7UiWnt+8GY/fxLng2oThg+fPzX/4+GlhsbH0+cvXb83lVOdFYphj2UiU+cxaBRcYs9wI/A8VwhpLPAsvj6o82e3qDTP5IkZ5ThI4VLyhDMwjoqadzRwGxZ0ltklmKuchkVZRt/rLqsl1l+obZeykgOoijSxQLmkK5oqBsPtVNdsmgrK86Nat/qtXL8IqarbCdjiO4D3oTEGLTOMoat7TYcaKFKVhArTud8LcDCwow5nAqkELjTmwa7jEvoMSUtQDO3auCjYcMwySTLkjTBmX1dYSLUepbFT1mPr2VxN/ivXL0yPbBc5oVBySYPJYUITBbUawiGXCEzYuQAMXdrAG7AuesctqOBM6s19+D3rd9k47PN5s7e1M3Vga+QH+U06ZIvskUNyRHqEkUdv3dvwfnpP/nf/l/9nIvW9ac0qeRN+9xlI8cbZ</latexit><latexit sha1_base64="eilBeCWCEGLnbPDIoUbGpDLZuY=">ACeHicfVFNT+MwEHUCuwtlPwoc4ZDdiv24VGmFByQFw4gkQBqS7RxJ2AheME20GqnPwHfhs3/gXLjhtV0BZ7UiWnt+8GY/fxLng2oThg+fPzX/4+GlhsbH0+cvXb83lVOdFYphj2UiU+cxaBRcYs9wI/A8VwhpLPAsvj6o82e3qDTP5IkZ5ThI4VLyhDMwjoqadzRwGxZ0ltklmKuchkVZRt/rLqsl1l+obZeykgOoijSxQLmkK5oqBsPtVNdsmgrK86Nat/qtXL8IqarbCdjiO4D3oTEGLTOMoat7TYcaKFKVhArTud8LcDCwow5nAqkELjTmwa7jEvoMSUtQDO3auCjYcMwySTLkjTBmX1dYSLUepbFT1mPr2VxN/ivXL0yPbBc5oVBySYPJYUITBbUawiGXCEzYuQAMXdrAG7AuesctqOBM6s19+D3rd9k47PN5s7e1M3Vga+QH+U06ZIvskUNyRHqEkUdv3dvwfnpP/nf/l/9nIvW9ac0qeRN+9xlI8cbZ</latexit><latexit sha1_base64="eilBeCWCEGLnbPDIoUbGpDLZuY=">ACeHicfVFNT+MwEHUCuwtlPwoc4ZDdiv24VGmFByQFw4gkQBqS7RxJ2AheME20GqnPwHfhs3/gXLjhtV0BZ7UiWnt+8GY/fxLng2oThg+fPzX/4+GlhsbH0+cvXb83lVOdFYphj2UiU+cxaBRcYs9wI/A8VwhpLPAsvj6o82e3qDTP5IkZ5ThI4VLyhDMwjoqadzRwGxZ0ltklmKuchkVZRt/rLqsl1l+obZeykgOoijSxQLmkK5oqBsPtVNdsmgrK86Nat/qtXL8IqarbCdjiO4D3oTEGLTOMoat7TYcaKFKVhArTud8LcDCwow5nAqkELjTmwa7jEvoMSUtQDO3auCjYcMwySTLkjTBmX1dYSLUepbFT1mPr2VxN/ivXL0yPbBc5oVBySYPJYUITBbUawiGXCEzYuQAMXdrAG7AuesctqOBM6s19+D3rd9k47PN5s7e1M3Vga+QH+U06ZIvskUNyRHqEkUdv3dvwfnpP/nf/l/9nIvW9ac0qeRN+9xlI8cbZ</latexit>

Poisoning effort ratio

0.02 0.04 0.06 0.08 0.1

Number of trials

20 40 60 80 100 120 140 160 180

Success rate =100%

Poisoning effort ratio

0.005 0.01 0.015 0.02 0.025

Number of trials

20 40 60 80 100 120

Success rate =100%

Poisoning effort ratio

0.015 0.02 0.025 0.03 0.035 0.04 0.045 0.05

Number of trials

20 40 60 80 100 120 140

Success rate =100%

Epsilon-greedy

UCB Thompson Sampling

slide-15
SLIDE 15

Simulation results: online model

  • Gaussian distributions with random drawn expectations
  • Parameters:
  • 3 cases:
  • Jun’s attack is optimized if the bandit algo. is known (esp. deterministic).

Epsilon-greedy

UCB Thompson Sampling

Time

100 101 102 103 104 105

Cost

1 2 3 4 5 6 7 8 9 10

ACE,∆=1 Jun,∆=1 ACE,∆=0.5 Jun,∆=0.5 ACE,∆=0.2 Jun,∆=0.2

Time

100 101 102 103 104 105

Cost

50 100 150 200 250

ACE,∆=1 Jun,∆=1 ACE,∆=0.5 Jun,∆=0.5 ACE,∆=0.2 Jun,∆=0.2

Time

100 101 102 103 104 105

Cost

1 2 3 4 5 6

ACE,∆=1 ACE,∆=0.5 ACE,∆=0.2

K = 2, σ = 0.1, T = 105, δ = 0.05

<latexit sha1_base64="cFEu3+MjER9GgdnCxz2WN7vM4GE=">AC3icbVBPS8MwHE3nvzn/T16CW6ChzHawdAdBgMvgpcJqxusdaRptoUlbUlSYZR9AC9+FS8eVLz6Bbz5bUy3HnTzQcjvfcj+T0vYlQq0/w2cmvrG5tb+e3Czu7e/kHx8OhOhrHAxMYhC0XPQ5IwGhBbUcVILxIEcY+Rrje5Sv3uAxGShkFHTSPicjQK6JBipLQ0KJbKN81axZF0xFHTrFqVTtMy7+sVxydMpYpZL+uUvueAq8TKSAlkaA+KX4f4piTQGpOxbZqTcBAlFMSOzghNLEiE8QSPS1zRAnEg3mS8zg2da8eEwFPoECs7V3xMJ4lJOuaeTHKmxXPZS8T+vH6vhpZvQIoVCfDioWHMoAph2gz0qSBYsakmCAuq/wrxGAmEle6voEuwldeJXat2qiat7VSq5G1kQcn4BScAwtcgBa4Bm1gAwewTN4BW/Gk/FivBsfi2jOyGaOwR8Ynz9EUZd7</latexit><latexit sha1_base64="cFEu3+MjER9GgdnCxz2WN7vM4GE=">AC3icbVBPS8MwHE3nvzn/T16CW6ChzHawdAdBgMvgpcJqxusdaRptoUlbUlSYZR9AC9+FS8eVLz6Bbz5bUy3HnTzQcjvfcj+T0vYlQq0/w2cmvrG5tb+e3Czu7e/kHx8OhOhrHAxMYhC0XPQ5IwGhBbUcVILxIEcY+Rrje5Sv3uAxGShkFHTSPicjQK6JBipLQ0KJbKN81axZF0xFHTrFqVTtMy7+sVxydMpYpZL+uUvueAq8TKSAlkaA+KX4f4piTQGpOxbZqTcBAlFMSOzghNLEiE8QSPS1zRAnEg3mS8zg2da8eEwFPoECs7V3xMJ4lJOuaeTHKmxXPZS8T+vH6vhpZvQIoVCfDioWHMoAph2gz0qSBYsakmCAuq/wrxGAmEle6voEuwldeJXat2qiat7VSq5G1kQcn4BScAwtcgBa4Bm1gAwewTN4BW/Gk/FivBsfi2jOyGaOwR8Ynz9EUZd7</latexit><latexit sha1_base64="cFEu3+MjER9GgdnCxz2WN7vM4GE=">AC3icbVBPS8MwHE3nvzn/T16CW6ChzHawdAdBgMvgpcJqxusdaRptoUlbUlSYZR9AC9+FS8eVLz6Bbz5bUy3HnTzQcjvfcj+T0vYlQq0/w2cmvrG5tb+e3Czu7e/kHx8OhOhrHAxMYhC0XPQ5IwGhBbUcVILxIEcY+Rrje5Sv3uAxGShkFHTSPicjQK6JBipLQ0KJbKN81axZF0xFHTrFqVTtMy7+sVxydMpYpZL+uUvueAq8TKSAlkaA+KX4f4piTQGpOxbZqTcBAlFMSOzghNLEiE8QSPS1zRAnEg3mS8zg2da8eEwFPoECs7V3xMJ4lJOuaeTHKmxXPZS8T+vH6vhpZvQIoVCfDioWHMoAph2gz0qSBYsakmCAuq/wrxGAmEle6voEuwldeJXat2qiat7VSq5G1kQcn4BScAwtcgBa4Bm1gAwewTN4BW/Gk/FivBsfi2jOyGaOwR8Ynz9EUZd7</latexit>

µ1 = ∆, µ2 = 0

<latexit sha1_base64="+U8w8q3tk39MeA+1DqOVBo9yz0w=">AB/nicbVDLSsNAFJ3UV62vqODGzWAruJCSdKNdFAq6cFnB2EITwmQ6aYfOJGFmIpTYhb/ixoWKW7/DnX/jpM1CWw9cOHPOvcy9J0gYlcqyvo3Syura+kZ5s7K1vbO7Z+4f3Ms4FZg4OGax6AVIEkYj4iqGOklgiAeMNINxle530gQtI4ulOThHgcDSMaUoyUlnzqOby1Ldb7jVhCp3nj0bLqvlm1apbM8BlYhekCgp0fPLHcQ45SRSmCEp+7aVKC9DQlHMyLTipIkCI/RkPQ1jRAn0stm+0/hqVYGMIyFrkjBmfp7IkNcygkPdCdHaiQXvVz8z+unKrz0MholqSIRn8UpgyqGOZhwAEVBCs20QRhQfWuEI+QFjpyCo6BHvx5GXiNOrNunXbqLabRplcAxOwBmwQVogxvQAQ7A4BE8g1fwZjwZL8a78TFvLRnFzCH4A+PzBwBClFA=</latexit><latexit sha1_base64="+U8w8q3tk39MeA+1DqOVBo9yz0w=">AB/nicbVDLSsNAFJ3UV62vqODGzWAruJCSdKNdFAq6cFnB2EITwmQ6aYfOJGFmIpTYhb/ixoWKW7/DnX/jpM1CWw9cOHPOvcy9J0gYlcqyvo3Syura+kZ5s7K1vbO7Z+4f3Ms4FZg4OGax6AVIEkYj4iqGOklgiAeMNINxle530gQtI4ulOThHgcDSMaUoyUlnzqOby1Ldb7jVhCp3nj0bLqvlm1apbM8BlYhekCgp0fPLHcQ45SRSmCEp+7aVKC9DQlHMyLTipIkCI/RkPQ1jRAn0stm+0/hqVYGMIyFrkjBmfp7IkNcygkPdCdHaiQXvVz8z+unKrz0MholqSIRn8UpgyqGOZhwAEVBCs20QRhQfWuEI+QFjpyCo6BHvx5GXiNOrNunXbqLabRplcAxOwBmwQVogxvQAQ7A4BE8g1fwZjwZL8a78TFvLRnFzCH4A+PzBwBClFA=</latexit><latexit sha1_base64="+U8w8q3tk39MeA+1DqOVBo9yz0w=">AB/nicbVDLSsNAFJ3UV62vqODGzWAruJCSdKNdFAq6cFnB2EITwmQ6aYfOJGFmIpTYhb/ixoWKW7/DnX/jpM1CWw9cOHPOvcy9J0gYlcqyvo3Syura+kZ5s7K1vbO7Z+4f3Ms4FZg4OGax6AVIEkYj4iqGOklgiAeMNINxle530gQtI4ulOThHgcDSMaUoyUlnzqOby1Ldb7jVhCp3nj0bLqvlm1apbM8BlYhekCgp0fPLHcQ45SRSmCEp+7aVKC9DQlHMyLTipIkCI/RkPQ1jRAn0stm+0/hqVYGMIyFrkjBmfp7IkNcygkPdCdHaiQXvVz8z+unKrz0MholqSIRn8UpgyqGOZhwAEVBCs20QRhQfWuEI+QFjpyCo6BHvx5GXiNOrNunXbqLabRplcAxOwBmwQVogxvQAQ7A4BE8g1fwZjwZL8a78TFvLRnFzCH4A+PzBwBClFA=</latexit>
slide-16
SLIDE 16
  • Negative results: bandits are vulnerable!

§ Algorithm-specific attacks on 3 popular bandits in offline model § Adaptive attacks on any bandit in online model

  • Any hope to build a robust world?
  • Crack the model

§ Encrypt decision § Replicate reward records

  • Detect by distribution outlier detection

Conclusions and discussions

slide-17
SLIDE 17

Thanks!

End