Please use this identifier to cite or link to this item:
https://er.chdtu.edu.ua/handle/ChSTU/10012| Title: | Integration of security testing into QA pipelines using adversarial ML |
| Other Titles: | Інтеграція тестування безпеки в конвеєри контролю якості за допомогою змагального машинного навчання |
| Authors: | Husakovskyi, Anatolii Гусаковський, Анатолій |
| Keywords: | model resilience;algorithm vulnerabilities;resilience metrics;automated testing;model lifecycle;protective mechanisms;стійкість моделей;вразливості алгоритмів;метрики стійкості;автоматизоване тестування;життєвий цикл моделей;захисні механізми |
| Issue Date: | 2026 |
| Publisher: | Вісник Черкаського державного технологічного університету |
| Abstract: | The study aimed to theoretically systematise approaches to improving the resilience of machine learning
systems in cyber defence by integrating resilience testing into the security process. The methodology covered
the systematisation of machine learning areas in cyber defence, analysis of strategies to counter adversarial
attacks, and a case study of integration into quality assurance and machine learning operations. The study found
that the use of machine learning technologies in cyber defence enables the automation of threat detection
and response (network anomalies, behavioural analysis, anti-phishing, anti-fraud, malware classification). The
main advantages are scalability, response speed, predictability, and effectiveness in complex environments,
while the key risks include dependence on data quality, false positives, vulnerability to adversarial and poisoning
attacks, as well as privacy and explainability issues. The study determined that adversarial machine learning
distinguishes between three attack scenarios (white-box, black-box, grey-box) and their classes (evasion, data
poisoning, privacy/inference, model extraction, generative artificial intelligence. The study emphasised that
adversarial machine learning encompasses not only technical but also regulatory and ethical dimensions related
to the principles of privacy, fairness, and transparency in the use of artificial intelligence. Multi-level protection
strategies were presented, integrated into the machine learning model lifecycle at the data level, during training,
after training, at the deployment and inference stages. Practical cases demonstrated the feasibility of applying
machine learning and anti-money laundering in various domains, from network security and security operations
centres to development and operations/continuous integration/continuous delivery, the financial sector, stress
testing machine learning pipelines, as well as quality assurance and machine learning operations. The practical
significance lies in the ability of cybersecurity specialists, financial analysts, and machine learning operations
engineers to use the results to improve the efficiency of security operations centres, integrate adversarial testing,
and ensure the stability of machine learning models in production environments. Метою дослідження була теоретична систематизація підходів до підвищення стійкості машинного навчання систем у кіберзахисті через інтеграцію тестування на стійкість у процесі забезпечення захисту. Методологія охоплювала систематизацію машинного навчання – напрямів у кіберзахисті, аналіз стратегій протидії ворожим атакам та case study інтеграції в забезпечення якості та операції з машинного навчання. Встановлено, що використання технологій машинного навчання у кіберзахисті забезпечує автоматизацію виявлення та реагування на загрози (аномалії у мережах, поведінковий аналіз, антифішинг, антифрод, класифікація malware). Основними перевагами є масштабованість, швидкість реагування, предиктивність та ефективність у складних середовищах, тоді як ключові ризики охоплюють залежність від якості даних, хибні спрацювання, вразливість до adversarial- та poisoning-атак, а також проблеми приватності й пояснюваності. Виявлено, що у змагальному машинному навчання виділено три сценарії атак (white-box, black-box, gray-box) та їх класи, отруєння даних, конфіденційність/висновок, вилучення моделі, генеративний штучний інтелект. Підкреслено, що змагальне машинне навчання охоплює не лише технічний, а й нормативний та етичний виміри, пов’язані з принципами конфіденційності, справедливості та прозорості у використанні штучного інтелекту. Представлено багаторівневі стратегії захисту, інтегровані в життєвий цикл моделей машинного навчання – на рівні даних, під час навчання, після навчання, на етапах розгортання та інференції. Практичні кейси продемонстрували доцільність застосування машинного навчання та протидії відмиванню коштів у різних доменах – від мережевої безпеки та центру операцій безпеки до розроблення та експлуатації / безперервної інтеграції / безперервного постачання, фінансового сектору, стрес-тестування конвеєрів машинного навчання, а також забезпечення якості й експлуатації машинного навчання. Практична значущість полягає в можливості використання отриманих результатів фахівцями з кібербезпеки, фінансовими аналітиками та інженерами з експлуатації машинного навчання для підвищення ефективності центру операцій безпеки, інтеграції змагального тестування та забезпечення стійкості моделей машинного навчання у виробничих середовищах. |
| URI: | https://er.chdtu.edu.ua/handle/ChSTU/10012 |
| ISSN: | 2306-4412 (print) 2708-6070 (online) |
| DOI: | https://doi.org/10.62660/bcstu/1.2026.128 |
| Volume: | 31 |
| Issue: | 1 |
| First Page: | 128 |
| End Page: | 142 |
| Appears in Collections: | том 31, №1/2026 |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| 12.pdf | 926.8 kB | Adobe PDF | ![]() View/Open | |
| зміст.pdf | 149.89 kB | Adobe PDF | ![]() View/Open | |
| титул.pdf | 283.8 kB | Adobe PDF | ![]() View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.


