{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T03:14:18Z","timestamp":1760238858724,"version":"build-2065373602"},"reference-count":40,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2022,6,5]],"date-time":"2022-06-05T00:00:00Z","timestamp":1654387200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100002261","name":"RFBR","doi-asserted-by":"publisher","award":["20-37-90073"],"award-info":[{"award-number":["20-37-90073"]}],"id":[{"id":"10.13039\/501100002261","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["MAKE"],"abstract":"<jats:p>The actual problem of adversarial attacks on classifiers, mainly implemented using deep neural networks, is considered. This problem is analyzed with a generalization to the case of any classifiers synthesized by machine learning methods. The imperfection of generally accepted criteria for assessing the quality of classifiers, including those used to confirm the effectiveness of protection measures against adversarial attacks, is noted. The reason for the appearance of adversarial examples and other errors of classifiers based on machine learning is investigated. A method for modeling adversarial attacks with a demonstration of the main effects observed during the attack is proposed. It is noted that it is necessary to develop quality criteria for classifiers in terms of potential susceptibility to adversarial attacks. To assess resistance to adversarial attacks, it is proposed to use the multidimensional EDCAP criterion (Excess, Deficit, Coating, Approx, Pref). We also propose a method for synthesizing a new EnAE (Ensemble of Auto-Encoders) multiclass classifier based on an ensemble of quality-controlled one-class classifiers according to EDCAP criteria. The EnAE classification algorithm implements a hard voting approach and can detect anomalous inputs. The proposed criterion, synthesis method and classifier are tested on several data sets with a medium dimension of the feature space.<\/jats:p>","DOI":"10.3390\/make4020024","type":"journal-article","created":{"date-parts":[[2022,6,5]],"date-time":"2022-06-05T10:47:11Z","timestamp":1654426031000},"page":"519-541","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Quality Criteria and Method of Synthesis for Adversarial Attack-Resistant Classifiers"],"prefix":"10.3390","volume":"4","author":[{"given":"Anastasia","family":"Gurina","sequence":"first","affiliation":[{"name":"JSC InfoTeCS, Otradnaya 2B building 1, Moscow 127273, Russia"},{"name":"Department of Control and Intellectual Technologies, National Research University \u201cMoscow Power Engineering Institute\u201d, Krasnokazarmennaya 17, Moscow 111250, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9341-7475","authenticated-orcid":false,"given":"Vladimir","family":"Eliseev","sequence":"additional","affiliation":[{"name":"JSC InfoTeCS, Otradnaya 2B building 1, Moscow 127273, Russia"},{"name":"Department of Control and Intellectual Technologies, National Research University \u201cMoscow Power Engineering Institute\u201d, Krasnokazarmennaya 17, Moscow 111250, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,5]]},"reference":[{"key":"ref_1","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015). Explaining and Harnessing Adversarial Examples. arXiv."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Bispham, M., Agrafiotis, I., and Goldsmith, M. (2019, January 23\u201325). Nonsense Attacks on Google Assistant and Missense Attacks on Amazon Alexa. Proceedings of the 5th International Conference on Information Systems Security and Privacy\u2014ICISSP, Prague, Czech Republic.","DOI":"10.5220\/0007309500750087"},{"key":"ref_3","unstructured":"Ozkan, H., Sen, S., and Can, B. (2022, April 17). Analysis of Adversarial Attacks against Traditional Spam Filters. Available online: https:\/\/www.researchgate.net\/publication\/359137489_Analysis_of_Adversarial_Attacks_against_Traditional_Spam_Filters."},{"key":"ref_4","unstructured":"(2022, May 01). Researchers Find a Malicious Way to Meddle with Autonomous Tech | News | Car and Driver. Available online: https:\/\/www.caranddriver.com\/news\/a15340148\/researchers-find-a-malicious-way-to-meddle-with-autonomous-cars\/."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2017). Adversarial Examples in the Physical World. arXiv.","DOI":"10.1201\/9781351251389-8"},{"key":"ref_6","unstructured":"Hern, A. (2022, March 10). Want to Beat Facial Recognition? Get Some Funky Tortoiseshell Glasses. The Guardian. Available online: https:\/\/www.theguardian.com\/technology\/2016\/nov\/03\/how-funky-tortoiseshell-glasses-can-beat-facial-recognition."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M.K. (2016, January 24\u201328). Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201916, Vienna, Austria.","DOI":"10.1145\/2976749.2978392"},{"key":"ref_8","unstructured":"(2022, April 18). Adversarial Attacks in Machine Learning: What They Are and How to Stop Them. VentureBeat. Available online: https:\/\/venturebeat.com\/2021\/05\/29\/adversarial-attacks-in-machine-learning-what-they-are-and-how-to-stop-them\/."},{"key":"ref_9","unstructured":"Lambert, F. (2016). Understanding the Fatal Tesla Accident on Autopilot and the NHTSA Probe. Electrek, Available online: https:\/\/electrek.co\/2016\/07\/01\/understanding-fatal-tesla-accident-autopilot-nhtsa-probe\/."},{"key":"ref_10","unstructured":"(2022, May 01). Model Hacking ADAS to Pave Safer Roads for Autonomous Vehicles | McAfee Blogs. Available online: https:\/\/www.trellix.com\/en-us\/about\/newsroom\/stories\/threat-labs\/model-hacking-adas-to-pave-safer-roads-for-autonomous-vehicles.html."},{"key":"ref_11","unstructured":"(2022, May 01). Adversarial Machine Learning against Tesla\u2019s Autopilot\u2014Schneier on Security. Available online: https:\/\/www.schneier.com\/blog\/archives\/2019\/04\/adversarial_mac.html."},{"key":"ref_12","unstructured":"(2022, May 01). Three Small Stickers in Intersection Can Cause Tesla Autopilot to Swerve into Wrong Lane. Available online: https:\/\/spectrum.ieee.org\/three-small-stickers-on-road-can-steer-tesla-autopilot-into-oncoming-lane."},{"key":"ref_13","unstructured":"(2022, May 01). UCI Machine Learning Repository: Iris Data Set. Available online: http:\/\/archive.ics.uci.edu\/ml\/datasets\/Iris."},{"key":"ref_14","unstructured":"(2022, May 01). UCI Machine Learning Repository: Seeds Data Set. Available online: http:\/\/archive.ics.uci.edu\/ml\/datasets\/seeds."},{"key":"ref_15","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2014). Intriguing Properties of Neural Networks. arXiv."},{"key":"ref_16","unstructured":"(2022, May 01). Adversarial Attacks with FGSM (Fast Gradient Sign Method)\u2014PyImageSearch. Available online: https:\/\/pyimagesearch.com\/2021\/03\/01\/adversarial-attacks-with-fgsm-fast-gradient-sign-method\/."},{"key":"ref_17","unstructured":"Wiyatno, R., and Xu, A. (2018). Maximal Jacobian-Based Saliency Map Attack. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017). Towards Evaluating the Robustness of Neural Networks. arXiv.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., and Swami, A. (2017, January 2\u20136). Practical Black-Box Attacks against Machine Learning. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, ASIA CCS \u201917, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053009"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One Pixel Attack for Fooling Deep Neural Networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_21","unstructured":"Hu, W., and Tan, Y. (2017). Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN. arXiv."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Zantedeschi, V., Nicolae, M.I., and Rawat, A. (2017, January 3). Efficient Defenses Against Adversarial Attacks. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA. Available online: https:\/\/dl.acm.org\/doi\/10.1145\/3128572.3140449.","DOI":"10.1145\/3128572.3140449"},{"key":"ref_23","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P. (2020). Ensemble Adversarial Training: Attacks and Defenses. arXiv."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 22\u201326). Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., and Qi, Y. (2018, January 18\u201321). Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. Proceedings of the 2018 Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref_26","unstructured":"(2022, May 01). Published Adversarial Example Defenses. Available online: https:\/\/www.robust-ml.org\/defenses\/."},{"key":"ref_27","unstructured":"Zhang, M., Li, H., Kuang, X., Pang, L., and Wu, Z. (2019). Neuron Selecting: Defending Against Adversarial Examples in Deep Neural Networks. Proceedings of the In Information and Communications Security: 21st International Conference, ICICS 2019, Beijing, China, 15\u201317 December 2019, Springer. Revised Selected Papers."},{"key":"ref_28","first-page":"1365","article-title":"Defend Against Adversarial Samples by Using Perceptual Hash","volume":"62","author":"Liu","year":"2020","journal-title":"Comput. Mater. Contin."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Pedraza, A., Deniz, O., and Bueno, G. (2020). Approaching Adversarial Example Classification with Chaos Theory. Entropy, 22.","DOI":"10.3390\/e22111201"},{"key":"ref_30","unstructured":"Shafahi, A., Huang, W.R., Studer, C., Feizi, S., and Goldstein, T. (2020). Are Adversarial Examples Inevitable?. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"953","DOI":"10.1109\/TDSC.2020.3014390","article-title":"Defending Against Adversarial Attack Towards Deep Neural Networks Via Collaborative Multi-Task Training","volume":"19","author":"Wang","year":"2022","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_32","unstructured":"Papernot, N., McDaniel, P., and Goodfellow, I. (2016). Transferability in Machine Learning: From Phenomena to Black-Box Attacks Using Adversarial Samples. arXiv."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Zhou, Z.-H. (2012). Ensemble Methods: Foundations and Algorithms, Chapman & Hall\/CRC. [1st ed.].","DOI":"10.1201\/b12207"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3969","DOI":"10.1016\/j.patcog.2015.06.001","article-title":"On the Usefulness of One-Class Classifier Ensembles for Decomposition of Multi-Class Problems","volume":"48","author":"Krawczyk","year":"2015","journal-title":"Pattern Recogn."},{"key":"ref_35","unstructured":"Prosak, A., Gangopadhyay, A., and Garg, H. (2019). A New Machine Learning Approach for Anomaly Detection Using Metadata for Model Training, EasyChair. EasyChair Preprint no. 829."},{"key":"ref_36","unstructured":"Gurina, A., and Eliseev, V. Empiricheskij kriterij kachestva odnoklassovogo klassifikatora. [Empirical criterion for the quality of a one-class classifier]. Sbornik Materialov XXVII Mezhdunarodnoj Nauchno-Tekhnicheskoj Konferencii, Nizhegorodskij Gosudarstvennyj Tehnicheskij Universitet  im. R.E. Alekseeva (Nizhnij Novgorod). (In Russian)."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"012009","DOI":"10.1088\/1742-6596\/2134\/1\/012009","article-title":"Dynamic Classification Approach Using Scalable Ensemble of Auto-encoders to Classify Data with Drift","volume":"2134","author":"Gurina","year":"2021","journal-title":"J. Phys. Conf. Ser."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"98","DOI":"10.24160\/1993-6982-2022-1-98-110","article-title":"Kriterij ocenki kachestva klassifikacii za predelami obuchayushchej vyborki. [Criteria for assessing the quality of classification outside the training dataset]","volume":"1","author":"Gurina","year":"2022","journal-title":"Vestnik MEI"},{"key":"ref_39","unstructured":"(2022, May 20). Ensemble Methods. Voting Classifier. Available online: https:\/\/scikit-learn.org\/stable\/modules\/ensemble.html."},{"key":"ref_40","unstructured":"(2022, May 01). UCI Machine Learning Repository: Wine Data Set. Available online: https:\/\/archive.ics.uci.edu\/ml\/datasets\/wine."}],"container-title":["Machine Learning and Knowledge Extraction"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-4990\/4\/2\/24\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:24:40Z","timestamp":1760138680000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-4990\/4\/2\/24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,5]]},"references-count":40,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["make4020024"],"URL":"https:\/\/doi.org\/10.3390\/make4020024","relation":{},"ISSN":["2504-4990"],"issn-type":[{"type":"electronic","value":"2504-4990"}],"subject":[],"published":{"date-parts":[[2022,6,5]]}}}