<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">15</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/eatr-5pxb-akt8</article-id>
      <title-group>
        <article-title>Adversarial attacks against a machine learning based intrusion detection system</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Состязательные атаки против системы обнаружения вторжений, основанной на применении методов машинного обучения</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-6562-9008</contrib-id>
          <name>
            <surname>Getman</surname>
            <given-names>Aleksandr</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>ever@ispras.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-0284-690X</contrib-id>
          <name>
            <surname>Goryunov</surname>
            <given-names>Maxim</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>max.gor@mail.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-9557-3765</contrib-id>
          <name>
            <surname>Matskevich</surname>
            <given-names>Andrey</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>mag3d.78@gmail.com</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-4524-655X</contrib-id>
          <name>
            <surname>Rybolovlev</surname>
            <given-names>Dmitry</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>dmitrij-rybolovlev@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-5965-4664</contrib-id>
          <name>
            <surname>Nikolskaya</surname>
            <given-names>Anastasiya</given-names>
          </name>
          <email>nikolskaya.a.g@yandex.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Ivannikov Institute for System Programming of the Russian Academy of Sciences</aff>
      <aff id="aff2">The Academy of Federal Security Guard Service of the Russian Federation</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2023-12-25">
        <day>25</day>
        <month>12</month>
        <year>2023</year>
      </pub-date>
      <issue>4</issue>
      <fpage>156</fpage>
      <lpage>190</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2023_4-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>The paper analyzes relevant sources in the field of implementing modern adversarial attacks against a network intrusion detection system with an analyzer based on machine learning methods. The process of building such a system is summarized; common errors made by developers at each stage, which can be exploited by attackers when implementing various attacks, are indicated. A classification of adversarial attacks against machine learning models is given, and the most well-known adversarial attacks against neural networks and ensembles of decision trees are analyzed. The existing limitations in the use of adversarial attacks against intrusion detection models of the “random forest” type are noted; poisoning and evasion attacks against the object of study are implemented in practice. Possible defense strategies are considered, and the effectiveness of the most common method, adversarial learning, is experimentally assessed. It is concluded that there are no guarantees to ensure the robustness of the used machine learning model to adversarial attacks and there is a need to search for protective strategies that provide such guarantees.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>network intrusion detection system</kwd>
        <kwd>adversarial attack</kwd>
        <kwd>machine learning</kwd>
        <kwd>network traffic</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
