<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN"
  "https://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML"
         article-type="research-article" xml:lang="ru" dtd-version="1.2">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">tis</journal-id>
      <journal-title-group><journal-title xml:lang="ru">Телекоммуникации и связь</journal-title><trans-title-group xml:lang="en"><trans-title>Telecommunications and Communications</trans-title></trans-title-group></journal-title-group>
      <issn pub-type="epub">3034-4050</issn>
      <publisher><publisher-name>ФГБУ «16 ЦНИИИ»</publisher-name></publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.21681/3034-4050-2026-4-13-24</article-id>
      <title-group><article-title xml:lang="ru">ЗАЩИТА ОТ СОСТЯЗАТЕЛЬНЫХ АТАК НЕЙРОСЕТЕЙ СИСТЕМЫ УПРАВЛЕНИЯ РОБОТОТЕХНИЧЕСКИМИ КОМПЛЕКСАМИ НА ОСНОВЕ МАРКОВСКИХ ПРОЦЕССОВ</article-title><trans-title-group xml:lang="en"><trans-title>PROTECTION AGAINST ADVERSARIAL ATTACKS OF NEURAL NETWORKS CONTROL SYSTEMS FOR ROBOTIC COMPLEXES BASED ON MARKOV PROCESSES</trans-title></trans-title-group></title-group>
      <contrib-group><contrib contrib-type="author">
        <name><surname>Сацута</surname><given-names>Анатолий Игоревич</given-names></name>
        <aff id="aff1"><institution xml:lang="ru">старший оператор научной роты военной академии связи им. Маршала Советского Союза С. М. Буденного, г. Санкт-Петербург, Россия</institution><institution xml:lang="en">Senior Operator of the Scientific Company of the Military Academy of Communications named after Marshal of the Soviet Union S. M. Budyonny, St. Petersburg, Russia</institution><country>Россия</country></aff>
        <email>toha.satzuta@yandex.ru</email>
      </contrib>
<contrib contrib-type="author">
        <name><surname>Липатников</surname><given-names>Валерий Алексеевич</given-names></name>
        <aff id="aff2"><institution xml:lang="ru">доктор технических наук, профессор, старший научный сотрудник научно-исследовательского центра Военной академии связи им. Маршала Советского Союза С. М. Буденного, Санкт-Петербург</institution><institution xml:lang="en">Dr.Sc. of Technical Sciences, Professor, Senior Researcher of the Research Center of the Military Academy of Communications named after Marshal of the Soviet Union S. M. Budyonny, St. Petersburg</institution><country>Россия</country></aff>
        <email>lipatnikovanl@mail.ru</email>
      </contrib>
      </contrib-group>
      <pub-date><year>2026</year></pub-date>
      <volume>13</volume><issue>4</issue>
      <fpage>13</fpage><lpage>24</lpage>
      <abstract xml:lang="ru"><p>Цель работы: состоит в анализе уязвимостей нейросетевых моделей систем управления робототехническими комплексами к состязательным воздействиям и разработке способа повышения их защиты на основе методов обучения с подкреплением.</p><p>Метод исследования: подход, основанный на формализации процесса генерации состязательных примеров как задачи Марковского процесса принятия решений.</p><p>Результаты исследования: разработан агент, адаптивно генерирующий состязательные примеры путем учета состояния среды и характеристик модели. Предложен способ обучения агента генерации состязательных примеров с последующим их использованием в состязательном обучении. Состояние агента формируется на основе карт признаков модели, градиентной информации и величины искажения входных данных, оцениваемой по норме l2. Действия агента соответствуют выбору параметров атаки типа PGD. Функция награды учитывает как снижение качества детекции, так и ограничение на уровень вносимых искажений.</p><p>Научная новизна: предложена новая функция награды, учитывающая одновременно качество детекции и величину искажения, что обеспечивает баланс между эффективностью атаки и её незаметностью.</p></abstract>
      <abstract xml:lang="en"><p>The purpose of the work: to analyze the vulnerabilities of neural network models of robotic control systems to adversarial influences and to develop a way to increase their protection based on reinforcement learning methods.</p><p>Research method: an approach based on the formalization of the process of generating adversarial examples as a task of the Markov decision-making process.</p><p>Results of the study: an agent has been developed that adaptively generates adversarial examples by taking into account the state of the environment and the characteristics of the model. It is proposed to train the agent to generate adversarial examples with subsequent use in adversarial training. The agent&apos;s state is formed on the basis of model feature maps, gradient information, and the value of input data distortion, estimated according to the l2 norm. The agent&apos;s actions correspond to the choice of PGD attack parameters.</p><p>Scientific novelty: a new reward function is proposed, which takes into account both the quality of detection and the amount of distortion, which provides a balance between the effectiveness of the attack and its stealth.</p></abstract>
      <kwd-group xml:lang="ru"><kwd>безопасность искусственного интеллекта</kwd><kwd>защита моделей машинного обучения</kwd><kwd>состязательное обучение</kwd><kwd>компьютерное зрение</kwd><kwd>распознавание объектов</kwd><kwd>системы управления роботизированными комплексами</kwd></kwd-group>
      <kwd-group xml:lang="en"><kwd>artificial intelligence security</kwd><kwd>protection of machine learning models</kwd><kwd>adversarial learning</kwd><kwd>computer vision</kwd><kwd>object recognition</kwd><kwd>control systems for robotic complexes</kwd></kwd-group>
    </article-meta>
  </front>
  <back><ref-list><title>Список литературы</title><ref id="ref1"><label>1</label><mixed-citation>Akhtar N., Mian A. Threat of adversarial attacks on deep learning in computer vision: A survey // IEEE Access. – 2021. – Vol. 9. – P. 12315–12336. – DOI: 10.1109/ACCESS.2021.3052020.</mixed-citation></ref>
<ref id="ref2"><label>2</label><mixed-citation>Wang Z., Wang X., Liu J., et al. Adversarial attacks on deep learning-based object detection systems: A survey // Neurocomputing. – 2022. – Vol. 493. – P. 1–19. – DOI: 10.1016/j.neucom.2022.03.045.</mixed-citation></ref>
<ref id="ref3"><label>3</label><mixed-citation>Qiu S., Liu Q., Zhou S., Wu C. Review of adversarial attacks and defense strategies in deep learning-based computer vision systems // Applied Sciences. – 2022. – Vol. 12 (15). – Art. 7583. – DOI: 10.3390/app12157583.</mixed-citation></ref>
<ref id="ref4"><label>4</label><mixed-citation>Xu H., Ma Y., Liu H., Deb D., Liu H., Tang J., Jain A. D. Adversarial attacks and defenses in images, graphs and text: A review // International Journal of Automation and Computing. – 2021. – Vol. 18 (2). – P. 151–178. – DOI: 10.1007/ s11633-021-1274-3.</mixed-citation></ref>
<ref id="ref5"><label>5</label><mixed-citation>Li Y., Li X., Wang X., et al. Survey of adversarial machine learning in deep neural networks: attacks, defenses and robustness evaluation // ACM Computing Surveys. – 2023. – Vol. 55 (10). – P. 1–38. – DOI: 10.1145/3562695.</mixed-citation></ref>
<ref id="ref6"><label>6</label><mixed-citation>Pavlitskaya S. et al. Adversarial Vulnerability of Temporal Feature Networks for Object Detection // Sensors. – 2023. – Vol. 23 (23). – DOI: 10.3390/s23239579.</mixed-citation></ref>
<ref id="ref7"><label>7</label><mixed-citation>Zhou Z., Chen X., Li E., et al. Robustness of deep learning models under real-world corruption: A survey // Pattern Recognition. – 2023. – Vol. 138. – Art. 109386. – DOI: 10.1016/j.patcog.2023.109386.</mixed-citation></ref>
<ref id="ref8"><label>8</label><mixed-citation>Nguyen K. N. T., Zhang W., Lu K., Wu Y.-H., Zheng X., Tan H. L., Zhen L. A Survey and Evaluation of Adversarial Attacks in Object Detection // IEEE Transactions on Neural Networks and Learning Systems. – 2025. – DOI: 10.1109/ TNNLS.2025.3561225. УДК 004.85 СИСТЕМНЫЙ АНАЛИЗ СИСТЕМ ВОЕННОГО НАЗНАЧЕНИЯ</mixed-citation></ref>
<ref id="ref9"><label>9</label><mixed-citation>Thunuguntla A., Tadepalli P., Raffa G. Defenses Against Adversarial Attacks on Object Detection: Methods and Future Directions // Information. – 2025. – Vol. 16 (11). – DOI: 10.3390/info16111003.</mixed-citation></ref>
<ref id="ref10"><label>10</label><mixed-citation>Huang Y., Zhang Y., Wu X., et al. Reinforcement learning for adversarial example generation and defense: A comprehensive survey // IEEE Transactions on Neural Networks and Learning Systems. – 2024. – DOI: 10.1109/ TNNLS.2024.3351123.</mixed-citation></ref>
<ref id="ref11"><label>11</label><mixed-citation>Chen J., Wu Y., Liang J., et al. Robust adversarial reinforcement learning: A survey and taxonomy // Information Sciences. – 2022. – Vol. 608. – P. 1–24. – DOI: 10.1016/j.ins.2022.06.033.</mixed-citation></ref>
<ref id="ref12"><label>12</label><mixed-citation>Domico K., Sheatsley R., Pauley E., Hanna J., McDaniel P. Adversarial Agents: Black-Box Evasion Attacks with Reinforcement Learning // ResearchGate: nauchnaya social&apos;naya set&apos;. – 2025. – DOI: 10.48550/arXiv.2503.01734.</mixed-citation></ref>
<ref id="ref13"><label>13</label><mixed-citation>Schulman J., Wolski F., Dhariwal P., Radford A., Klimov O. Proximal Policy Optimization Algorithms // arXiv.org: ehlektronnyj arhiv. – 2021. – arXiv:1707.06347. – Rezhim dostupa: https://arxiv.org/abs/1707.06347 (data obrashcheniya: 20.04.2026).</mixed-citation></ref>
<ref id="ref14"><label>14</label><mixed-citation>Lipatnikov V. A., Tihonov V. A. Raspoznavanie vtorzhenij narushitelya pri upravlenii kiberbezopasnost&apos;yu infrastruktury integrirovannoj organizacii na osnove nejro-nechetkih setej i kognitivnogo modelirovaniya. V sbornike: Aktual&apos;nye problemy infotelekommunikacij v nauke i obrazovanii (APINO, 2019). sbornik nauchnyh statej VIII Mezhdunarodnoj nauchno-tehnicheskoj i nauchno-metodicheskoj konferencii: v 4 t. – 2019. – S. 659–664.</mixed-citation></ref>
<ref id="ref15"><label>15</label><mixed-citation>Lipatnikov V. A., Parfirov V. A. Metod podderzhki prinyatiya resheniya pri upravlenii set&apos;yu svyazi na osnove tehnologii nejronnyh setej. V sbornike: Aktual&apos;nye problemy infotelekommunikacij v nauke i obrazovanii (APINO, 2024). Materialy XIII Mezhdunarodnoj nauchno-tehnicheskoj i nauchno-metodicheskoj konferencii. Sankt-Peterburg, 2024. – S. 467-472.</mixed-citation></ref>
<ref id="ref16"><label>16</label><mixed-citation>Sindeev M. A., Vasil&apos;ev N. A., Smirnov V. A., Shevchenko A. A., Kosolapov V. S., Lipatnikov V. A., Parfirov V. A. Programmnyj kompleks dlya prognozirovaniya i podderzhki prinyatiya reshenij administratorom seti po parirovaniyu mnogoehtapnoj ataki. Svidetel&apos;stvo o registracii programmy dlya EHVM RU 2022616751, 15.04.2022. Zayavka № 2022615448 ot 29.03.2022.</mixed-citation></ref></ref-list></back>
</article>
