<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">mireabulletin</journal-id><journal-title-group><journal-title xml:lang="ru">Russian Technological Journal</journal-title><trans-title-group xml:lang="en"><trans-title>Russian Technological Journal</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2782-3210</issn><issn pub-type="epub">2500-316X</issn><publisher><publisher-name>RTU MIREA</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.32362/2500-316X-2026-14-5-26-40</article-id><article-id custom-type="edn" pub-id-type="custom">WXRQJG</article-id><article-id custom-type="elpub" pub-id-type="custom">mireabulletin-1657</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ СИСТЕМЫ. ИНФОРМАТИКА. ПРОБЛЕМЫ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION SYSTEMS. COMPUTER SCIENCES. ISSUES OF INFORMATION SECURITY</subject></subj-group></article-categories><title-group><article-title>Классификация угроз безопасности моделей машинного обучения в системах экологического мониторинга и количественная оценка сценариев атак</article-title><trans-title-group xml:lang="en"><trans-title>Taxonomy of security threats to machine learning models in environmental monitoring systems with quantitative assessment of attack scenarios</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-6191-8614</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Козачок</surname><given-names>А. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Kozachok</surname><given-names>A. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Андрей Васильевич Козачок, к. т. н., доцент</p><p>Институт кибербезопасности и цифровых технологий; кафедра КБ-4 «Интеллектуальные системы информационной безопасности», </p><p>119454;  пр-т Вернадского, д. 78; Москва</p></bio><bio xml:lang="en"><p>Andrey V. Kozachok, Cand. Sci. (Eng.), Associate Professor</p><p>Institute of Cybersecurity and Digital Technologies; Department of Intelligent Information Security Systems</p><p>119454; 78, Vernadskogo pr.; Moscow</p></bio><email xlink:type="simple">kozachok@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0003-2019-8536</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ноев</surname><given-names>А. Н.</given-names></name><name name-style="western" xml:lang="en"><surname>Noev</surname><given-names>A. N.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Артем Николаевич Ноев, к. т. н., исполняющий обязанности заведующего кафедрой</p><p>Институт кибербезопасности и цифровых технологий; кафедра КБ-4 «Интеллектуальные системы информационной безопасности»</p><p>119454; пр-т Вернадского, д. 78; Москва</p></bio><bio xml:lang="en"><p>Artem N. Noev, Cand. Sci. (Eng.), Acting Head of the Department</p><p>Institute of Cybersecurity and Digital Technologies; Department of Intelligent Information Security Systems</p><p>119454; 78, Vernadskogo pr.; Moscow</p></bio><email xlink:type="simple">noev_a@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Матюхина</surname><given-names>Е. Н.</given-names></name><name name-style="western" xml:lang="en"><surname>Matyukhina</surname><given-names>E. N.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Екатерина Николаевна Матюхина, к. т. н., доцент</p><p>Институт кибербезопасности и цифровых технологий; кафедра КБ-4 «Интеллектуальные системы информационной безопасности»</p><p>119454; пр-т Вернадского, д. 78; Москва</p></bio><bio xml:lang="en"><p>Ekaterina N. Matyukhina, Cand. Sci. (Eng.), Associate Professor</p><p>Institute of Cybersecurity and Digital Technologies; Department of Intelligent Information Security Systems </p><p>119454; 78, Vernadskogo pr.; Moscow</p></bio><email xlink:type="simple">makaterina_ski@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>МИРЭА – Российский технологический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>MIREA – Russian Technological University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>08</day><month>10</month><year>2026</year></pub-date><volume>14</volume><issue>5</issue><fpage>26</fpage><lpage>40</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Козачок А.В., Ноев А.Н., Матюхина Е.Н., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Козачок А.В., Ноев А.Н., Матюхина Е.Н.</copyright-holder><copyright-holder xml:lang="en">Kozachok A.V., Noev A.N., Matyukhina E.N.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.rtj-mirea.ru/jour/article/view/1657">https://www.rtj-mirea.ru/jour/article/view/1657</self-uri><abstract><sec><title>   Цели</title><p>   Цели. Интеграция машинного обучения (machine learning, ML) в экологический мониторинг создает новый спектр киберугроз. Стандарты безопасности искусственного интеллекта (NIST1, OWASP2) носят общий характер и слабо учитывают специфику природоохранного контроля, в частности зависимость систем экологического мониторинга от данных временных рядов и высокий естественный сенсорный шум.</p><p>   Цель работы – разработка специализированной классификации атак на ML-модели и профилирование количественных рисков для автоматизированных систем контроля промышленных выбросов.</p></sec><sec><title>   Методы</title><p>   Методы. Выполнен аналитический обзор более 25 научных публикаций по проблемам состязательного машинного обучения и защиты промышленного интернета вещей (Internet of Things, IoT). Отбор источников проводился в базах IEEE Xplore3, ACM Digital Library4, Scopus5 и arXiv6 по ключевым словам «adversarial ML»7, «data poisoning»8, «evasion attacks»9, «IoT security»10, «environmental monitoring»11 с приоритетом публикаций 2019–2025 гг. Применены методы структурно-функционального анализа жизненного цикла ML-систем. Проведен синтез доступных экспериментальных данных об уязвимостях нейронных сетей и ансамблевых алгоритмов для формирования количественных оценок успешности воздействия и уровня деградации моделей.</p></sec><sec><title>   Результаты</title><p>   Результаты. Предложена трехуровневая классификация угроз (отравление данных, атаки уклонения, инверсия моделей), дополненная матрицей уязвимостей по осям «данные – модель – платформа». Показано, что подмена менее 5 % данных в обучающей выборке приводит к скрытому падению точности глубоких нейронных сетей (deep neural network, DNN) на 85 процентных пунктов, а наиболее мощные атаки уклонения достигают успешности 97–99 % против одиночных DNN. Идентифицирована критическая угроза составных атак, комбинирующих дрейф данных IoT с архитектурными слабостями алгоритмов для манипуляции результатами прогнозирования.</p></sec><sec><title>   Выводы</title><p>   Выводы. Безопасное применение предиктивной аналитики требует обязательного перехода к проактивной архитектуре защиты. Для нейтрализации угроз необходимо использование робастных ансамблевых моделей, регулярного состязательного обучения (adversarial training) и жесткой валидации входящих потоков данных. Определены приоритетные направления дальнейших исследований, центральным элементом которых является разработка эталонных экологических датасетов и метрик киберустойчивости искусственного интеллекта.</p></sec></abstract><trans-abstract xml:lang="en"><sec><title>   Objectives</title><p>   Objectives. The integration of machine learning (ML) into environmental monitoring contexts introduces a new spectrum of cyber threats. The general-purpose nature of current AI security frameworks and guidance (NIST, OWASP) makes them insufficiently tailored to the specific characteristics of environmental monitoring, including time-series data and high inherent sensor noise.</p><p>   The present work therefore set out to develop a specialized classification of attacks on ML models used for automated industrial emissions monitoring systems and provide quantitative risk estimates.</p></sec><sec><title>   Methods</title><p>   Methods. An analytical review of over 25 scientific publications on adversarial machine learning and industrial Internet of Things (IoT) security was carried out. Sources were selected from IEEE Xplore, ACM Digital Library, Scopus, and arXiv prioritizing publications from 2019–2025 using the keywords “adversarial ML”, “data poisoning”, “evasion attacks”, “IoT security”, and “environmental monitoring”. Structural-functional analysis methods were applied to the ML system lifecycle. Available experimental data on neural network and ensemble algorithm vulnerabilities were synthesized to produce quantitative estimates of attack success rates and model degradation levels.</p></sec><sec><title>   Results</title><p>   Results. A three-tier threat classification is proposed (data poisoning, evasion attacks, and model inversion), supplemented by a vulnerability matrix along the axes of data–model–platform. It is shown that the substitution of less than 5 % of training data results in a covert accuracy drop of 85 percentage points in deep neural networks (DNNs), while the most powerful evasion attacks achieve a success rate of 97–99% against single DNNs. A critical threat posed by composite attacks that combine IoT data drift with architectural weaknesses of algorithms to manipulate forecasting outputs is identified.</p></sec><sec><title>   Conclusions</title><p>   Conclusions. The secure deployment of predictive analytics requires a mandatory transition to proactive security architecture. To neutralize threats, the use of robust ensemble models, regular adversarial training, and strict validation of incoming data streams becomes necessary. Priority directions for future research involve the development of benchmark environmental datasets and AI cyber-resilience metrics as the central elements.</p></sec></trans-abstract><kwd-group xml:lang="ru"><kwd>машинное обучение</kwd><kwd>экологический мониторинг</kwd><kwd>безопасность искусственного интеллекта</kwd><kwd>классификация угроз</kwd><kwd>отравление данных</kwd><kwd>атаки уклонения</kwd><kwd>инверсия модели</kwd><kwd>состязательное машинное обучение</kwd><kwd>количественная оценка рисков</kwd><kwd>робастность ML-систем</kwd></kwd-group><kwd-group xml:lang="en"><kwd>machine learning</kwd><kwd>environmental monitoring</kwd><kwd>AI security</kwd><kwd>threat classification</kwd><kwd>data poisoning</kwd><kwd>evasion attacks</kwd><kwd>model inversion</kwd><kwd>adversarial machine learning</kwd><kwd>quantitative risk assessment</kwd><kwd>ML robustness</kwd></kwd-group><funding-group><funding-statement xml:lang="ru">Авторы не имеют финансовой заинтересованности в представленных материалах или методах</funding-statement><funding-statement xml:lang="en">The authors have no financial or proprietary interest in any material or method mentioned</funding-statement></funding-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Dalvi N., Domingos P., Sanghai S., Verma D. Adversarial classification. In: Proceedings of the 10&lt;sup&gt;th&lt;/sup&gt; ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2004. Р. 99–108. doi: 10.1145/1014052.1014066</mixed-citation><mixed-citation xml:lang="en">Dalvi N., Domingos P., Sanghai S., Verma D. Adversarial classification. In: Proceedings of the 10&lt;sup&gt;th&lt;/sup&gt; ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2004. Р. 99–108. doi: 10.1145/1014052.1014066</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Barreno M., Nelson B., Sears R., Joseph A.D., Tygar J.D. Can machine learning be secure? In: Proceedings of the 2006 ACM Symposium on Information, Computer and Communications Security. 2006. Р. 16–25. doi: 10.1145/1128817.1128824</mixed-citation><mixed-citation xml:lang="en">Barreno M., Nelson B., Sears R., Joseph A.D., Tygar J.D. Can machine learning be secure? In: Proceedings of the 2006 ACM Symposium on Information, Computer and Communications Security. 2006. Р. 16–25. doi: 10.1145/1128817.1128824</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Langner R. Stuxnet: Dissecting a cyberweapon. IEEE Secur Priv. 2011;9(3):49–51. doi: 10.1109/MSP.2011.67</mixed-citation><mixed-citation xml:lang="en">Langner R. Stuxnet: Dissecting a cyberweapon. IEEE Secur Priv. 2011;9(3):49–51. doi: 10.1109/MSP.2011.67</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Кочергин С.В., Артемова С.В., Бакаев А.А., Митяков Е.С., Вегера Ж.Г., Максимова Е.А. Кибербезопасность смарт-сетей: сравнение подходов машинного обучения для обнаружения аномалий. Russian Technological Journal. 2024;12(6):7–19. doi: 10.32362/2500-316X-2024-12-6-7-19</mixed-citation><mixed-citation xml:lang="en">Kochergin S.V., Artemova S.V., Bakaev A.A., Mityakov E.S., Vegera Zh.G., Maksimova E.A. Cybersecurity of smart grids: comparison of machine learning approaches for anomaly detection. Russian Technological Journal. 2024;12(6):7–19. doi: 10.32362/2500-316X-2024-12-6-7-19</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Fawaz H.I., Forestier G., Weber J., Idoumghar L., Muller P.A. Adversarial attacks on deep neural networks for time series classification. In: Proceedings of the International Joint Conference on Neural Networks (IJCNN). 2019. doi: 10.1109/IJCNN.2019.8851936</mixed-citation><mixed-citation xml:lang="en">Fawaz H.I., Forestier G., Weber J., Idoumghar L., Muller P.A. Adversarial attacks on deep neural networks for time series classification. In: Proceedings of the International Joint Conference on Neural Networks (IJCNN). 2019. doi: 10.1109/IJCNN.2019.8851936</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Karim F., Majumdar S., Darabi H. Adversarial attacks on time series. IEEE Trans. Pattern Anal. Mach. Intell. 2021;43(10): 3309–3320. doi: 10.1109/TPAMI.2020.2986319</mixed-citation><mixed-citation xml:lang="en">Karim F., Majumdar S., Darabi H. Adversarial attacks on time series. IEEE Trans. Pattern Anal. Mach. Intell. 2021;43(10): 3309–3320. doi: 10.1109/TPAMI.2020.2986319</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Wang J., Yang Y., Jiang Y., et al. Cross-modal incongruity aligning and collaborating for multi-modal sarcasm detection. Inf. Fusion. 2024;103:102132. doi: 10.1016/j.inffus.2023.102132</mixed-citation><mixed-citation xml:lang="en">Wang J., Yang Y., Jiang Y., et al. Cross-modal incongruity aligning and collaborating for multi-modal sarcasm detection. Inf. Fusion. 2024;103:102132. doi: 10.1016/j.inffus.2023.102132</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Mothukuri V., Parizi R.M., Pouriyeh S., Huang Y., Dehghantanha A., Srivastava G. A survey on security and privacy of federated learning. Future Gener. Comput. Syst. 2021;115:619–640. doi: 10.1016/j.future.2020.10.007</mixed-citation><mixed-citation xml:lang="en">Mothukuri V., Parizi R.M., Pouriyeh S., Huang Y., Dehghantanha A., Srivastava G. A survey on security and privacy of federated learning. Future Gener. Comput. Syst. 2021;115:619–640. doi: 10.1016/j.future.2020.10.007</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Cinà A.E., Grosse K., Demontis A., Vascon S., Biggio B., Roli F. Wild patterns reloaded: a survey of machine learning security against training-data poisoning. ACM Comput. Surv. 2023;55(13s):294. doi: 10.1145/3585385</mixed-citation><mixed-citation xml:lang="en">Cinà A.E., Grosse K., Demontis A., Vascon S., Biggio B., Roli F. Wild patterns reloaded: a survey of machine learning security against training-data poisoning. ACM Comput. Surv. 2023;55(13s):294. doi: 10.1145/3585385</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Machado G.R., Silva E., Goldschmidt R.R. Adversarial machine learning in image classification: a survey toward the defender’s perspective. ACM Comput. Surv. 2023;55(1):8. doi: 10.1145/3485133</mixed-citation><mixed-citation xml:lang="en">Machado G.R., Silva E., Goldschmidt R.R. Adversarial machine learning in image classification: a survey toward the defender’s perspective. ACM Comput. Surv. 2023;55(1):8. doi: 10.1145/3485133</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Arafat Z., Yudina O.V., Abdulaziz Z.A. Generative adversarial networks in cybersecurity : a literature review. Russian Technological Journal. 2025;13(5):7–24. doi: 10.32362/2500-316X-2025-13-5-7-24</mixed-citation><mixed-citation xml:lang="en">Arafat Z., Yudina O.V., Abdulaziz Z.A. Generative adversarial networks in cybersecurity : a literature review. Russian Technological Journal. 2025;13(5):7–24. doi: 10.32362/2500-316X-2025-13-5-7-24</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Askhatuly A., Berdysheva D., Berdishev A., et al. Adversarial Attacks and Defense Mechanisms in Machine Learning : A Structured Review of Methods, Domains, and Open Challenges. IEEE Access. 2025;13:185145–185168. doi: 10.1109/ACCESS.2025.3624409</mixed-citation><mixed-citation xml:lang="en">Askhatuly A., Berdysheva D., Berdishev A., et al. Adversarial Attacks and Defense Mechanisms in Machine Learning : A Structured Review of Methods, Domains, and Open Challenges. IEEE Access. 2025;13:185145–185168. doi: 10.1109/ACCESS.2025.3624409</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Mansouri T., Sadeghi Moghadam M.R., Monshizadeh F., Zareravasan A. IoT data quality issues and potential solutions : A literature review. Comput. J. 2023;66(3):615–625. doi: 10.1093/comjnl/bxab183</mixed-citation><mixed-citation xml:lang="en">Mansouri T., Sadeghi Moghadam M.R., Monshizadeh F., Zareravasan A. IoT data quality issues and potential solutions : A literature review. Comput. J. 2023;66(3):615–625. doi: 10.1093/comjnl/bxab183</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Biggio B., Nelson B., Laskov P. Poisoning attacks against support vector machines. In: Proceedings of the 29&lt;sup&gt;th&lt;/sup&gt; International Conference on Machine Learning (ICML’12). 2012. Р. 1467–1474. doi: 10.48550/arXiv.1206.6389</mixed-citation><mixed-citation xml:lang="en">Biggio B., Nelson B., Laskov P. Poisoning attacks against support vector machines. In: Proceedings of the 29&lt;sup&gt;th&lt;/sup&gt; International Conference on Machine Learning (ICML’12). 2012. Р. 1467–1474. doi: 10.48550/arXiv.1206.6389</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Chen X., Liu C., Li B., Lu K., Song D. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint. arXiv:1712.05526; 2017. https://arxiv.org/abs/1712.05526</mixed-citation><mixed-citation xml:lang="en">Chen X., Liu C., Li B., Lu K., Song D. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint. arXiv:1712.05526; 2017. https://arxiv.org/abs/1712.05526</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Goodfellow I., Shlens J., Szegedy C. Explaining and harnessing adversarial examples. arXiv preprint. arXiv:1412.6572; 2015. https://arxiv.org/abs/1412.6572</mixed-citation><mixed-citation xml:lang="en">Goodfellow I., Shlens J., Szegedy C. Explaining and harnessing adversarial examples. arXiv preprint. arXiv:1412.6572; 2015. https://arxiv.org/abs/1412.6572</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Madry A., Makelov A., Schmidt L., Tsipras D., Vladu A. Towards deep learning models resistant to adversarial attacks. arXiv preprint. arXiv:1706.06083; 2018. https://arxiv.org/abs/1706.06083</mixed-citation><mixed-citation xml:lang="en">Madry A., Makelov A., Schmidt L., Tsipras D., Vladu A. Towards deep learning models resistant to adversarial attacks. arXiv preprint. arXiv:1706.06083; 2018. https://arxiv.org/abs/1706.06083</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Carlini N., Wagner D. Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (S&amp;P). 2017. https://arxiv.org/abs/1608.04644</mixed-citation><mixed-citation xml:lang="en">Carlini N., Wagner D. Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (S&amp;P). 2017. https://arxiv.org/abs/1608.04644</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">Harford S., Karim F., Darabi H. Adversarial attacks on multivariate time series. arXiv preprint. arXiv:2004.00410; 2020. https://arxiv.org/abs/2004.00410</mixed-citation><mixed-citation xml:lang="en">Harford S., Karim F., Darabi H. Adversarial attacks on multivariate time series. arXiv preprint. arXiv:2004.00410; 2020. https://arxiv.org/abs/2004.00410</mixed-citation></citation-alternatives></ref><ref id="cit20"><label>20</label><citation-alternatives><mixed-citation xml:lang="ru">Ren K., Zheng T., Qin Z., Liu X. Adversarial attacks and defenses in deep learning. Engineering. 2020;6(3):346–360. doi: 10.1016/j.eng.2019.12.012</mixed-citation><mixed-citation xml:lang="en">Ren K., Zheng T., Qin Z., Liu X. Adversarial attacks and defenses in deep learning. Engineering. 2020;6(3):346–360. doi: 10.1016/j.eng.2019.12.012</mixed-citation></citation-alternatives></ref><ref id="cit21"><label>21</label><citation-alternatives><mixed-citation xml:lang="ru">Fredrikson M., Jha S., Ristenpart T. Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22&lt;sup&gt;nd&lt;/sup&gt; ACM SIGSAC Conference on Computer and Communications Security (CCS). 2015. Р. 1322–1333. doi: 10.1145/2810103.2813677</mixed-citation><mixed-citation xml:lang="en">Fredrikson M., Jha S., Ristenpart T. Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22&lt;sup&gt;nd&lt;/sup&gt; ACM SIGSAC Conference on Computer and Communications Security (CCS). 2015. Р. 1322–1333. doi: 10.1145/2810103.2813677</mixed-citation></citation-alternatives></ref><ref id="cit22"><label>22</label><citation-alternatives><mixed-citation xml:lang="ru">Shokri R., Stronati M., Song C., Shmatikov V. Membership inference attacks against machine learning models. In: IEEE Symposium on Security and Privacy (S&amp;P). 2017. Р. 3–18.</mixed-citation><mixed-citation xml:lang="en">Shokri R., Stronati M., Song C., Shmatikov V. Membership inference attacks against machine learning models. In: IEEE Symposium on Security and Privacy (S&amp;P). 2017. Р. 3–18.</mixed-citation></citation-alternatives></ref><ref id="cit23"><label>23</label><citation-alternatives><mixed-citation xml:lang="ru">Papernot N., McDaniel P., Goodfellow I., Kolter Z., Mądry A., Song D. Practical black-box attacks against machine learning. In: Proceedings of the ACM Asia Conference on Computer and Communications Security. 2017. Р. 506–519. doi: 10.1145/3052973.3053009</mixed-citation><mixed-citation xml:lang="en">Papernot N., McDaniel P., Goodfellow I., Kolter Z., Mądry A., Song D. Practical black-box attacks against machine learning. In: Proceedings of the ACM Asia Conference on Computer and Communications Security. 2017. Р. 506–519. doi: 10.1145/3052973.3053009</mixed-citation></citation-alternatives></ref><ref id="cit24"><label>24</label><citation-alternatives><mixed-citation xml:lang="ru">Feurer M., Hutter F. Hyperparameter optimization. In: Hutter F., Kotthoff L., Vanschoren J. (Eds.). Automated Machine Leaning: Methods, Systems, Challenges. Springer; 2019. Р. 3–33. doi: 10.1007/978-3-030-05318-5_1</mixed-citation><mixed-citation xml:lang="en">Feurer M., Hutter F. Hyperparameter optimization. In: Hutter F., Kotthoff L., Vanschoren J. (Eds.). Automated Machine Leaning: Methods, Systems, Challenges. Springer; 2019. Р. 3–33. doi: 10.1007/978-3-030-05318-5_1</mixed-citation></citation-alternatives></ref><ref id="cit25"><label>25</label><citation-alternatives><mixed-citation xml:lang="ru">Wang P., Xiao S., Liu X., et al. Research on missing value imputation to improve the validity of air quality data evaluation on the Qinghai-Tibetan Plateau. Atmosphere. 2023;14(12):1821. doi: 10.3390/atmos14121821</mixed-citation><mixed-citation xml:lang="en">Wang P., Xiao S., Liu X., et al. Research on missing value imputation to improve the validity of air quality data evaluation on the Qinghai-Tibetan Plateau. Atmosphere. 2023;14(12):1821. doi: 10.3390/atmos14121821</mixed-citation></citation-alternatives></ref><ref id="cit26"><label>26</label><citation-alternatives><mixed-citation xml:lang="ru">Nicolae M.I., Sinn M., Tran M.N., Buesser B., Rawat A., et al. Adversarial Robustness Toolbox v1.0.0. arXiv preprint. arXiv:1807.01069; 2018. https://arxiv.org/abs/1807.01069</mixed-citation><mixed-citation xml:lang="en">Nicolae M.I., Sinn M., Tran M.N., Buesser B., Rawat A., et al. Adversarial Robustness Toolbox v1.0.0. arXiv preprint. arXiv:1807.01069; 2018. https://arxiv.org/abs/1807.01069</mixed-citation></citation-alternatives></ref><ref id="cit27"><label>27</label><citation-alternatives><mixed-citation xml:lang="ru">Abadi M., Chu A., Goodfellow I., McMahan H.B., Mironov I., Talwar K., et al. Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS). 2016. Р. 308–318. doi: 10.1145/2976749.2978318</mixed-citation><mixed-citation xml:lang="en">Abadi M., Chu A., Goodfellow I., McMahan H.B., Mironov I., Talwar K., et al. Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS). 2016. Р. 308–318. doi: 10.1145/2976749.2978318</mixed-citation></citation-alternatives></ref><ref id="cit28"><label>28</label><citation-alternatives><mixed-citation xml:lang="ru">McMahan B., Moore E., Ramage D., Hampson S., Arcas B.A. Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20&lt;sup&gt;th&lt;/sup&gt; International Conference on Artificial Intelligence and Statistics (AISTATS). 2017. Р. 1273–1282. http://proceedings.mlr.press/v54/mcmahan17a/mcmahan17a.pdf</mixed-citation><mixed-citation xml:lang="en">McMahan B., Moore E., Ramage D., Hampson S., Arcas B.A. Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20&lt;sup&gt;th&lt;/sup&gt; International Conference on Artificial Intelligence and Statistics (AISTATS). 2017. Р. 1273–1282. http://proceedings.mlr.press/v54/mcmahan17a/mcmahan17a.pdf</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
