<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">4</article-id>
      <title-group>
        <article-title>Adversarial attacks on intrusion detection systems using LSTM classifier</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Состязательные атаки на системы обнаружения вторжений, использующих LSTM-классификатор</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Kulikov</surname>
            <given-names>D.</given-names>
          </name>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-9899-2778</contrib-id>
          <name>
            <surname>Platonov</surname>
            <given-names>Vladimir</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>plato@ibks.spbstu.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2021-06-03">
        <day>03</day>
        <month>06</month>
        <year>2021</year>
      </pub-date>
      <issue>2</issue>
      <fpage>48</fpage>
      <lpage>56</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2021_2-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>This paper discusses adversarial attacks on machine learning models and their classification. Methods for assessing the resistance of an LSTM classifier to adversarial attacks are investigated. JSMA and FGSM attacks, chosen due to the portability of adversarial examples between machine learning models, are discussed in detail. An attack of “poisoning” of the LSTM classifier is proposed. Methods of protection against the considered adversarial attacks are formulated</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>adversarial attack</kwd>
        <kwd>intrusion detection system</kwd>
        <kwd>neural network</kwd>
        <kwd>LSTM</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
