Zhuocen Dai, Mao Tan, Yin Yang, Xiao Liu, Yi Su, Kang Li
With the growing adoption of reinforcement learning (RL) in Electric Vehicle (EV) charging scheduling, its vulnerability to adversarial attacks remains largely underexplored. These attacks, essentially a form of stealthy false data injection, introduce imperceptible perturbations to observation data, potentially leading to severe performance degradation. In this work, we propose a novel Multi-Criteria Adversarial Attack (MCAA), which goes beyond conventional adversarial methods that merely induce action shifts of agents. Instead, MCAA is designed to strategically deteriorate specific objectives in multi-objective optimization or to mislead the agent into violating physical constraints, according to the attacker’s intent. To counter such threats, we develop an Auto-Shielded Defense (ASD) framework that combines a preemptive Auto-shield module with adversarially robust agents trained via adversarial training. The Auto-shield extracts latent features to mitigate adversarial perturbations, while adversarially robust agents ensure reliable decision-making under attack. Extensive experiments show that ASD consistently outperforms standard RL in objective and system stability under attacks, effectively neutralizing various types and intensities of adversarial attacks.