<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">10</article-id>
      <title-group>
        <article-title>Protection of AI/ML federated learning systems from poisoning attacks</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Защита систем федеративного обучения AI/ML от атак отравления</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-9659-1244</contrib-id>
          <name>
            <surname>Poltavtseva</surname>
            <given-names>Maria</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>potavtseva@ibks.spbstu.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0007-3203-6007</contrib-id>
          <name>
            <surname>Vasilyeva</surname>
            <given-names>Anastasia</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>vamp.be.live@gmail.com</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-06-09">
        <day>09</day>
        <month>06</month>
        <year>2026</year>
      </pub-date>
      <issue>2</issue>
      <fpage>121</fpage>
      <lpage>137</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/pib_2.pdf"/>
      <abstract xml:lang="en">
        <p>Federated artificial intelligence learning systems are susceptible to attacks that allow an attacker to change their behavior, just like conventional AI/ML solutions. The most effective of such attacks today is the poisoning attack. At the same time, the protection of federated learning systems is complicated by the possibility of collusion between the participants. In such circumstances, it becomes especially difficult to detect and prevent attacks. The solution of this problem is the purpose of the presented work. The study suggests a method to ensure the protection of federated learning systems from poisoning attacks using collusion, based on a combination of known and proven protection methods. The selected methods of filtering and reliable aggregation have been modified to take into account possible collusion of the training participants. The correctness and effectiveness of the proposed method is confirmed by practical experiments, which make it possible not only to prove its effectiveness, but also to identify the limitations of the developed solution.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Information security</kwd>
        <kwd>artificial intelligence</kwd>
        <kwd>machine learning</kwd>
        <kwd>supply chains</kwd>
        <kwd>poisoning attacks</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
