[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86357-en":3,"doc-seo-86357-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86357,687197100911,"Himbo","https://ap-avatar.wpscdn.com/avatar/a000239b6f1da00475?x-image-process=image/resize,m_fixed,w_180,h_180&k=1785132997149421697",8,"Research & Report","Random Walk Learning and the Pac-Man Attack","Random walk–based algorithms are widely used in distributed systems and decentralized learning, but local interactions make them vulnerable to adversarial manipulation. The paper studies the “Pac-Man” attack, where a malicious node probabilistically kills any random walk that visits it, stealthily draining the network of active walkers. It introduces the fully decentralized AVERAGE CROSSING (AC) algorithm that duplicates random walks using only local timing. Results show bounded walker populations and convergence of RW-SGD under AC, with quantified deviation and a phase transition in extinction probability tied to the duplication threshold, validated by extensive experiments.","Random Walk Learning and the Pac-Man Attack  \nXingran Chen, Parimal Parag, Rohit Bhagat, Zonghong Liu, and Salim El Rouayheb  \narXiv :2508 .05663v6 [ stat .ML] 6 Jul 2026  \nAbstract—Random walk (RW)-based algorithms have long been popular in distributed systems due to low overheads and scalability, with recent growing applications in decentralized learning. However, their reliance on local interactions makes them inherently vulnerable to malicious behavior. In this work, we investigate an adversarial threat that we term the “Pac-Man”attack, in which a malicious node probabilistically terminates any RW that visits it. This stealthy behavior gradually eliminates active RWs from the network, effectively halting the decentralized operators without triggering failure alarms. To counter this threat, we propose the AVERAGE CROSSING (AC) algorithm—a fully decentralized mechanism for duplicating RWs to prevent RW extinction in the presence of Pac-Man. Our theoretical analysis establishes that (i) the RW population remains almost surely bounded under AC and (ii) RW-based stochastic gradient descent remains convergent under AC, even in the presence of Pac-Man, with a quantifiable deviation from the true optimum. Furthermore, they uncover a phase transition in the extinction probability as a function of the duplication threshold, which we explain through theoretical analysis of a simplified variant of AC. Our extensive empirical results on both synthetic and public benchmark datasets validate our theoretical findings.  \nI. INTRODUCTION  \nDecentralized algorithms are becoming increasingly important in modern large-scale networked applications. These algorithms enable a network of nodes/agents, each with access only to local data and a limited local view of the connection graph, to collaborate in solving global computational tasks without centralized coordination. Among the most widely studied approaches are random-walk (RW)-based algorithms [1], [2] and gossip-based algorithms [3] .  \nWhile gossip-based methods are powerful, their repeated local broadcasts can lead to large communication overhead in large-scale systems [3] . This motivates the study of RW-based algorithms, which offer a communication-efficient alternative for large networks due to their simplicity and scalability [1],[2] . As a result, RW-based methods have been successfully applied across a wide range of domains [4]–[8] . A particularly compelling application is decentralized machine learning, where RWs are used to aggregate learning on data distributed across networked agents [9], [10] .  \nDespite their advantages, RW learning algorithms are susceptible to security threats [11],[12] . We focus in this work on a particular threat in which certain nodes behave maliciously  \nXingran Chen, Rohit Bhagat, Zonghong Liu, and Salim El Rouayheb are with Department of Electrical and Computer Engineering, Rutgers University, Piscataway Township, NJ 08854, USA (E-mail: [xingranc@ieee.org](xingranc@ieee.org), {rb1395, zl304, [sye8}@scarletmail.rutgers.edu](sye8}@scarletmail.rutgers.edu)).  \nParimal Parag is with the Department of Electrical Communication Engineering, Indian Institute of Science, Bangalore, Karnataka 560012, India (E-mail: [parimal@iisc.ac.in](parimal@iisc.ac.in)).  \nThis paper has been accepted by IEEE ISIT 2026 .  \nby terminating, or “killing”, any random walk that reaches them. We refer to this as the Pac-Man attack, evoking the arcade character known for devouring everything in its path.  \nRecent work by [13] introduced a novel approach based on self-regulating RWs, aimed at enhancing the resilience of RW-based algorithms in a decentralized manner. The main algorithm proposed in this work is called DECAFORK, which operates by maintaining a history of RW visit times at each node. The work in [13] provides theoretical guarantees for catastrophic failure scenarios under idealized assumptions and approximations. The followup work in [14] includes numerical simulations ","cbCaijRO5s0fWIjz","https://ap.wps.com/l/cbCaijRO5s0fWIjz","pdf",3713435,5,1,17,"English","en",105,"# Introduction\n# Pac-Man Attack and Threat Model\n# AVERAGE CROSSING (AC) Algorithm\n## Random-walk duplication based on local timing\n## Theoretical guarantees: boundedness, phase transition, and convergence\n# Experimental Validation","[{\"question\":\"What is the “Pac-Man” attack against random-walk learning?\",\"answer\":\"A malicious node probabilistically terminates (“kills”) any random walk that visits it. This gradually eliminates active random walks while avoiding visible failure alarms.\"},{\"question\":\"How does the AVERAGE CROSSING (AC) algorithm mitigate the Pac-Man attack?\",\"answer\":\"Each benign node duplicates an incoming random walk based on local timing information: if the interval between successive visits exceeds a threshold, the node probabilistically duplicates the currently visiting walk.\"},{\"question\":\"What theoretical results are established for the AC mechanism?\",\"answer\":\"The paper proves the random-walk population is almost surely bounded under AC. It also shows RW-SGD convergence under adversarial Pac-Man behavior and characterizes a phase transition in extinction probability as the duplication threshold changes.\"}]",1784210827,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"random-walk-learning-and-the-pac-man-attack","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/random-walk-learning-and-the-pac-man-attack/86357/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the “Pac-Man” attack against random-walk learning?","Question",{"text":76,"@type":77},"A malicious node probabilistically terminates (“kills”) any random walk that visits it. This gradually eliminates active random walks while avoiding visible failure alarms.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the AVERAGE CROSSING (AC) algorithm mitigate the Pac-Man attack?",{"text":81,"@type":77},"Each benign node duplicates an incoming random walk based on local timing information: if the interval between successive visits exceeds a threshold, the node probabilistically duplicates the currently visiting walk.",{"name":83,"@type":74,"acceptedAnswer":84},"What theoretical results are established for the AC mechanism?",{"text":85,"@type":77},"The paper proves the random-walk population is almost surely bounded under AC. It also shows RW-SGD convergence under adversarial Pac-Man behavior and characterizes a phase transition in extinction probability as the duplication threshold changes.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]