<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">9</article-id>
      <title-group>
        <article-title>Protection against adversarial attacks based on a dynamically reconfigurable ensemble of machine learning models</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Защита от состязательных атак на базе динамически перестраиваемого ансамбля моделей машинного обучения</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Gavva</surname>
            <given-names>Georgij</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>gavva.gd@edu.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-9732-0099</contrib-id>
          <name>
            <surname>Kalinin</surname>
            <given-names>Maxim</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>max@ibks.spbstu.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-06-09">
        <day>09</day>
        <month>06</month>
        <year>2026</year>
      </pub-date>
      <issue>2</issue>
      <fpage>113</fpage>
      <lpage>120</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/pib_2.pdf"/>
      <abstract xml:lang="en">
        <p>The paper reviews the problem of protecting machine learning models from adversarial attacks. A protection method is presented based on a dynamically reconfigurable ensemble of classifiers with a failure mechanism that combines a random combination of heterogeneous sub-models, online analysis of forecast variance, simulation of a plausible attack response, and a decoy model mechanism. Analysis of the consistency of outputs in the ensemble and failure to issue the most probable output reduces the effectiveness of an attacker when analyzing feedback received from the target model and generating adversarial samples. An experimental evaluation conducted on the UNSW-NB15 dataset showed that the developed method maintains high initial accuracy of the protected model under adversarial attacks (85–95 %) with a minimal decrease of 1–3 percentage points. The method can eliminate up to 98 % of attacks, significantly exceeding the performance of similar widely used methods.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Protection of machine learning</kwd>
        <kwd>ensemble of models</kwd>
        <kwd>classification</kwd>
        <kwd>mechanism for rejecting</kwd>
        <kwd>adversarial attacks</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
