Specifics of Detecting Training Data Compromise in Artificial Intelligence Systems

DOI: 10.21293/1818-0442-2026-29-1-124-134

Download article in PDF format

JATS xml

Abstract: Relevance. Artificial intelligence systems are currently widely deployed, but many of them are vulnerable to training data poisoning attacks. When attacking, an attacker purposefully introduces malicious instances into the dataset, which leads to a decrease in model accuracy or the emergence of hidden backdoors. Purpose of the study. Development of an approach to analyzing ways of negative impact on training sets. This approach will not only determine the most optimal impacts, but also to quantify their severity (the study proposes developing a system of metrics for quantitatively assessing poisoning attacks and building a model of optimal actions of an attacker based on Markov decision processes). Methods. The following tests were applied: the two-sample Kolmogorov–Smirnov test and the chi-square for comparing feature distributions, the Jensen–Shannon distance to estimate data drift, the Adversarial Validation method, and the value iteration algorithm to find the optimal policy in the Markov decision process (MDP). Novelty. A formal model of the interaction between an attacker and an analyst is proposed as MDP with a reward function that simultaneously accounts for the decrease in model accuracy, the indistinguishability of poisoned data and the degree of their statistical drift relative to a control set. Results. The dependencies of the probability of a successful attack on its scale for various states of analyst trust are obtained. Optimal and suboptimal sequences of attack actions are identified. It is shown that the proposed metrics quantitatively characterize both the effectiveness and stealth of the attack. Practical significance. The proposed approach allows for assessing the susceptibility of datasets to poisoning attacks during the development of artificial intelligence systems and substantiating preventative measures: regular monitoring of JS divergence, checking the distribution of class labels and applying several statistical tests to detect anomalies.

Keywords: network attack, neural network, dataset, feature matrix, activation function, Python programming language, Markov decision processes

For citation:
Vetrov I. A., Satsuta A. I., Podtopelnyy V. V. Specifics of Detecting Training Data Compromise in Artificial Intelligence Systems. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2026, vol. 29, no. 1, pp. 124–134. DOI: 10.21293/1818-0442-2026-29-1-124-134

Authors and copyright holders:

  • Vetrov I. A. , I. Kant Baltic Federal University (Kaliningrad, Russia)
  • Satsuta A. I. , Immanuel Kant Baltic Federal University (Kaliningrad, Russia)
  • Podtopelnyy V. V. , Kaliningrad State Technical University (Kaliningrad, Russia)

  • 1. Namiot D.E. [Schemes of attacks on machine learning models]. International journal of open information technologies, 2023, vol. 11, no. 5, pp. 68–86 (in Russ.).
  • 2. E. Nowroozi, I. Haider, R. M. Conti. Taheri. Federated Learning Under Attack: exposing vulnerabilities through Data Poisoning Attacks in Computer Networks. IEEE Transactions on Network and Service Management, 2025, vol. 22, no.1, pp. 822–831
  • 3. Y. Liu, Z. Li, M. Backes, Y. Shen. Backdoor Attacks Against Dataset Distillation. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, California, USA, 2023, pp. 1–18.
  • 4. M. Jagielski, A. Oprea, B. Biggio [et al.] Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning. Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, IEEE, 2018. pp. 19–35.
  • 5. Alshahrani E., Algazzawi D., Alotaibi R., Rabie O. Adversarial attacks against supervised machine learning based network intrusion detection. PLOS.One, 2022, vol. 17 (10), art. no. e0275971. Available at: https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0275971#sec015 (accessed: 10 September 2024)
  • 6. Awal, M.A. Investigating Adversarial Attacks in Software Analytics via Machine Learning Explainability // Software Quality Journal, 2025, vol. 33, no.3, pp. 1–31.
  • 7. Carminati M., Santini L., M. Polino, Zanero S. Evasion Attacks against Banking Fraud Detection Systems. 23rd International Symposium on Research in Attacks, Intrusions and Defenses: USENIX Association, San Sebastian, Spain, Curran Associates, Inc., 2020, pp. 285–300.
  • 8. Finner, H. Two-Sample Kolmogorov–Smirnov-type tests revisited: old and new tests in terms Of local levels. The Annals of Statistics, 2018, vol, 6A, no. 46, pp. 3014–3037.
  • 9. Pan J., Dorairaj M., Chen H., Lee J. Adversarial Validation Approach to Concept Drift Problem in User Targeting Automation Systems at Uber. Proceedings of the AdKDD '20 Workshop, ACM, 2020, no. 1–6.
  • 10. Gang L., Stone B.L., Johnson M.D. Automating Construction of Machine Learning Models with Clinical Big Data: Proposal Rationale and Methods. JMIR Research Protocols, 2017, vol. 6 (8), art. no. e175. DOI: 10.2196/resprot.7757.
  • 11. Burkov A. Mashinnoye obucheniye bez lishnikh slov [Machine learning without unnecessary words]. St. Petersburg, Peter, 2020, 192 p. (in Russ.).
  • 12. Kohenderfer M., Wheeler T., Ray K. Algoritmy prinyatiya resheniy [Algorithms of decision–making]. Moscow, DMK-Press, 2023, 684 p. (in Russ.).
  • 13. Wang Y. On the use of adversarial validation for quantifying dissimilarity in geospatial machine learning prediction. GIScience and Remote Sensing, 2025, vol. 62, no 1. pp. 1–25.
  • 14. General descriptions and classifications of attack patterns Available at: https://capec.mitre.org, free (accessed: 12 May 2024).
  • 15. NSL-KDD – dataset [Electronic resource]. Available at: https://www.unb.ca/cic/datasets/nsl.html, free (accessed: 21 October 2025).
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates