Preview

Russian Technological Journal

Advanced search

Taxonomy of security threats to machine learning models in environmental monitoring systems with quantitative assessment of attack scenarios

https://doi.org/10.32362/2500-316X-2026-14-5-26-40

EDN: WXRQJG

Abstract

   Objectives. The integration of machine learning (ML) into environmental monitoring contexts introduces a new spectrum of cyber threats. The general-purpose nature of current AI security frameworks and guidance (NIST, OWASP) makes them insufficiently tailored to the specific characteristics of environmental monitoring, including time-series data and high inherent sensor noise.

   The present work therefore set out to develop a specialized classification of attacks on ML models used for automated industrial emissions monitoring systems and provide quantitative risk estimates.

   Methods. An analytical review of over 25 scientific publications on adversarial machine learning and industrial Internet of Things (IoT) security was carried out. Sources were selected from IEEE Xplore, ACM Digital Library, Scopus, and arXiv prioritizing publications from 2019–2025 using the keywords “adversarial ML”, “data poisoning”, “evasion attacks”, “IoT security”, and “environmental monitoring”. Structural-functional analysis methods were applied to the ML system lifecycle. Available experimental data on neural network and ensemble algorithm vulnerabilities were synthesized to produce quantitative estimates of attack success rates and model degradation levels.

   Results. A three-tier threat classification is proposed (data poisoning, evasion attacks, and model inversion), supplemented by a vulnerability matrix along the axes of data–model–platform. It is shown that the substitution of less than 5 % of training data results in a covert accuracy drop of 85 percentage points in deep neural networks (DNNs), while the most powerful evasion attacks achieve a success rate of 97–99% against single DNNs. A critical threat posed by composite attacks that combine IoT data drift with architectural weaknesses of algorithms to manipulate forecasting outputs is identified.

   Conclusions. The secure deployment of predictive analytics requires a mandatory transition to proactive security architecture. To neutralize threats, the use of robust ensemble models, regular adversarial training, and strict validation of incoming data streams becomes necessary. Priority directions for future research involve the development of benchmark environmental datasets and AI cyber-resilience metrics as the central elements.

About the Authors

A. V. Kozachok
MIREA – Russian Technological University
Russian Federation

Andrey V. Kozachok, Cand. Sci. (Eng.), Associate Professor

Institute of Cybersecurity and Digital Technologies; Department of Intelligent Information Security Systems

119454; 78, Vernadskogo pr.; Moscow


Competing Interests:

The authors declare that there is no conflict of interest.



A. N. Noev
MIREA – Russian Technological University
Russian Federation

Artem N. Noev, Cand. Sci. (Eng.), Acting Head of the Department

Institute of Cybersecurity and Digital Technologies; Department of Intelligent Information Security Systems

119454; 78, Vernadskogo pr.; Moscow


Competing Interests:

The authors declare that there is no conflict of interest.



E. N. Matyukhina
MIREA – Russian Technological University
Russian Federation

Ekaterina N. Matyukhina, Cand. Sci. (Eng.), Associate Professor

Institute of Cybersecurity and Digital Technologies; Department of Intelligent Information Security Systems 

119454; 78, Vernadskogo pr.; Moscow


Competing Interests:

The authors declare that there is no conflict of interest.



References

1. Dalvi N., Domingos P., Sanghai S., Verma D. Adversarial classification. In: Proceedings of the 10<sup>th</sup> ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2004. Р. 99–108. doi: 10.1145/1014052.1014066

2. Barreno M., Nelson B., Sears R., Joseph A.D., Tygar J.D. Can machine learning be secure? In: Proceedings of the 2006 ACM Symposium on Information, Computer and Communications Security. 2006. Р. 16–25. doi: 10.1145/1128817.1128824

3. Langner R. Stuxnet: Dissecting a cyberweapon. IEEE Secur Priv. 2011;9(3):49–51. doi: 10.1109/MSP.2011.67

4. Kochergin S.V., Artemova S.V., Bakaev A.A., Mityakov E.S., Vegera Zh.G., Maksimova E.A. Cybersecurity of smart grids: comparison of machine learning approaches for anomaly detection. Russian Technological Journal. 2024;12(6):7–19. doi: 10.32362/2500-316X-2024-12-6-7-19

5. Fawaz H.I., Forestier G., Weber J., Idoumghar L., Muller P.A. Adversarial attacks on deep neural networks for time series classification. In: Proceedings of the International Joint Conference on Neural Networks (IJCNN). 2019. doi: 10.1109/IJCNN.2019.8851936

6. Karim F., Majumdar S., Darabi H. Adversarial attacks on time series. IEEE Trans. Pattern Anal. Mach. Intell. 2021;43(10): 3309–3320. doi: 10.1109/TPAMI.2020.2986319

7. Wang J., Yang Y., Jiang Y., et al. Cross-modal incongruity aligning and collaborating for multi-modal sarcasm detection. Inf. Fusion. 2024;103:102132. doi: 10.1016/j.inffus.2023.102132

8. Mothukuri V., Parizi R.M., Pouriyeh S., Huang Y., Dehghantanha A., Srivastava G. A survey on security and privacy of federated learning. Future Gener. Comput. Syst. 2021;115:619–640. doi: 10.1016/j.future.2020.10.007

9. Cinà A.E., Grosse K., Demontis A., Vascon S., Biggio B., Roli F. Wild patterns reloaded: a survey of machine learning security against training-data poisoning. ACM Comput. Surv. 2023;55(13s):294. doi: 10.1145/3585385

10. Machado G.R., Silva E., Goldschmidt R.R. Adversarial machine learning in image classification: a survey toward the defender’s perspective. ACM Comput. Surv. 2023;55(1):8. doi: 10.1145/3485133

11. Arafat Z., Yudina O.V., Abdulaziz Z.A. Generative adversarial networks in cybersecurity : a literature review. Russian Technological Journal. 2025;13(5):7–24. doi: 10.32362/2500-316X-2025-13-5-7-24

12. Askhatuly A., Berdysheva D., Berdishev A., et al. Adversarial Attacks and Defense Mechanisms in Machine Learning : A Structured Review of Methods, Domains, and Open Challenges. IEEE Access. 2025;13:185145–185168. doi: 10.1109/ACCESS.2025.3624409

13. Mansouri T., Sadeghi Moghadam M.R., Monshizadeh F., Zareravasan A. IoT data quality issues and potential solutions : A literature review. Comput. J. 2023;66(3):615–625. doi: 10.1093/comjnl/bxab183

14. Biggio B., Nelson B., Laskov P. Poisoning attacks against support vector machines. In: Proceedings of the 29<sup>th</sup> International Conference on Machine Learning (ICML’12). 2012. Р. 1467–1474. doi: 10.48550/arXiv.1206.6389

15. Chen X., Liu C., Li B., Lu K., Song D. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint. arXiv:1712.05526; 2017. https://arxiv.org/abs/1712.05526

16. Goodfellow I., Shlens J., Szegedy C. Explaining and harnessing adversarial examples. arXiv preprint. arXiv:1412.6572; 2015. https://arxiv.org/abs/1412.6572

17. Madry A., Makelov A., Schmidt L., Tsipras D., Vladu A. Towards deep learning models resistant to adversarial attacks. arXiv preprint. arXiv:1706.06083; 2018. https://arxiv.org/abs/1706.06083

18. Carlini N., Wagner D. Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (S&P). 2017. https://arxiv.org/abs/1608.04644

19. Harford S., Karim F., Darabi H. Adversarial attacks on multivariate time series. arXiv preprint. arXiv:2004.00410; 2020. https://arxiv.org/abs/2004.00410

20. Ren K., Zheng T., Qin Z., Liu X. Adversarial attacks and defenses in deep learning. Engineering. 2020;6(3):346–360. doi: 10.1016/j.eng.2019.12.012

21. Fredrikson M., Jha S., Ristenpart T. Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22<sup>nd</sup> ACM SIGSAC Conference on Computer and Communications Security (CCS). 2015. Р. 1322–1333. doi: 10.1145/2810103.2813677

22. Shokri R., Stronati M., Song C., Shmatikov V. Membership inference attacks against machine learning models. In: IEEE Symposium on Security and Privacy (S&P). 2017. Р. 3–18.

23. Papernot N., McDaniel P., Goodfellow I., Kolter Z., Mądry A., Song D. Practical black-box attacks against machine learning. In: Proceedings of the ACM Asia Conference on Computer and Communications Security. 2017. Р. 506–519. doi: 10.1145/3052973.3053009

24. Feurer M., Hutter F. Hyperparameter optimization. In: Hutter F., Kotthoff L., Vanschoren J. (Eds.). Automated Machine Leaning: Methods, Systems, Challenges. Springer; 2019. Р. 3–33. doi: 10.1007/978-3-030-05318-5_1

25. Wang P., Xiao S., Liu X., et al. Research on missing value imputation to improve the validity of air quality data evaluation on the Qinghai-Tibetan Plateau. Atmosphere. 2023;14(12):1821. doi: 10.3390/atmos14121821

26. Nicolae M.I., Sinn M., Tran M.N., Buesser B., Rawat A., et al. Adversarial Robustness Toolbox v1.0.0. arXiv preprint. arXiv:1807.01069; 2018. https://arxiv.org/abs/1807.01069

27. Abadi M., Chu A., Goodfellow I., McMahan H.B., Mironov I., Talwar K., et al. Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS). 2016. Р. 308–318. doi: 10.1145/2976749.2978318

28. McMahan B., Moore E., Ramage D., Hampson S., Arcas B.A. Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20<sup>th</sup> International Conference on Artificial Intelligence and Statistics (AISTATS). 2017. Р. 1273–1282. http://proceedings.mlr.press/v54/mcmahan17a/mcmahan17a.pdf


Review

For citations:


Kozachok A.V., Noev A.N., Matyukhina E.N. Taxonomy of security threats to machine learning models in environmental monitoring systems with quantitative assessment of attack scenarios. Russian Technological Journal. 2026;14(5):26-40. https://doi.org/10.32362/2500-316X-2026-14-5-26-40. EDN: WXRQJG

Views: 63

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2782-3210 (Print)
ISSN 2500-316X (Online)