Motivated by reinforcement learning in harsh environments, we consider the problem of learning an optimal policy subject to adversarially corrupted feedback. Specifically, at each time-step, an adversary can perturb both the reward and state observations of the learner following the Huber contamination model. To defend against such data corruption, we propose {\texttt{BR-Async-Q}}: a novel, epoch-based, robust \(Q\)-learning algorithm built upon two key ideas: (i) partitioning the online data stream into batches to reduce variance, and (ii) constructing robust estimates of the Bellman optimality operator using such batched data. We prove a high-probability $\ell_\infty$ error bound for {\texttt{BR-Async-Q}} that matches that for vanilla \(Q\)-learning, up to a small additive term that scales with the fraction of corrupted samples. To our knowledge, this provides the first robustness guarantee for asynchronous \(Q\)-learning subject to both reward and state corruption. Furthermore, when only rewards are corrupted, the dependence of our algorithm's bound on the corruption fraction is minimax optimal.
M. Santos-Pascual, D. Ríos Insuastat.ML cs.LG stat.ME
Decision-making under partial or adversarial observability requires accurate inference of the environment's latent state and its associated uncertainty. This work analyses adversarial attacks on linear state-space models, where the attacker alters observations subject to likelihood constraints that ensure that the perturbations remain statistically consistent with the observation model. We analyse how such adversarial yet plausible observations shift inference about latent states and affect downstream decision-making and the performance of reinforcement learning agents. In addition, we introduce an online Bayesian defence based on directional covariance adaptation, which selectively reduces the influence of observations by comparing their estimated impact with that of the computed most disruptive direction, while preserving information in the remaining orthogonal observation subspace. The proposed framework provides a principled approach to constructing robust inference and decision-making systems, with direct relevance to safety-critical applications such as robotics, where reliable operation under sensor noise, partial failures, and adversarial conditions is essential.