We attack the state-of-the-art Go-playing AI system KataGo by training adversarial policies against it, achieving a >97% win rate against KataGo running at superhuman settings. Our adversaries do not win by playing Go well. Instead, they trick KataGo into making serious blunders. Our attack transfers zero-shot to other superhuman Go-playing AIs, and is comprehensible to the extent that human experts can implement it without algorithmic assistance to consistently beat superhuman AIs. The core vulnerability uncovered by our attack persists even in KataGo agents adversarially trained to defend against our attack. Our results demonstrate that even superhuman AI systems may harbor surprising failure modes. Example games are available https://goattack.far.ai/.
翻译:我们通过训练对抗策略攻击最先进的围棋AI系统KataGo,在超人类设置下实现了对其超过97%的胜率。我们的对抗方并非通过高超的棋艺取胜,而是诱导KataGo犯下严重失误。该攻击可零样本迁移至其他超人类围棋AI,且具备足够可解释性——人类专家无需算法辅助即可实现此攻击,持续击败超人类AI。即使在经过对抗训练以防御此类攻击的KataGo智能体中,我们攻击所揭示的核心漏洞依然存在。结果表明,即便是超人类AI系统也可能存在令人惊讶的故障模式。示例对局详见https://goattack.far.ai/。