<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaz29</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Казахстанско-Британского технического университета</journal-title><trans-title-group xml:lang="en"><trans-title>Herald of the Kazakh-British Technical University</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1998-6688</issn><issn pub-type="epub">2959-8109</issn><publisher><publisher-name>Казахстанско-Британский Технический Университет</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.55452/1998-6688-2026-23-3-176-187</article-id><article-id custom-type="elpub" pub-id-type="custom">kaz29-3183</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>КОМПЬЮТЕРНЫЕ НАУКИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>COMPUTER SCIENCE</subject></subj-group></article-categories><title-group><article-title>ПРИМЕНЕНИЕ ГЕНЕРАТИВНЫХ МОДЕЛЕЙ ИИ ДЛЯ АТАК И ЗАЩИТЫ</article-title><trans-title-group xml:lang="en"><trans-title>APPLICATION OF GENERATIVE AI MODELS FOR ATTACKS AND DEFENSE</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0001-6017-1659</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Батырханова</surname><given-names>А. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Batyrkhanova</surname><given-names>A. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>М.т.н., сениор-лектор</p><p>Алматы</p></bio><bio xml:lang="en"><p>M.E.Sc., Senior Lecturer</p><p>Almaty</p></bio><email xlink:type="simple">a.batyrkhanova@iitu.edu.kz</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0004-0319-0636</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Бекмухан</surname><given-names>А. С.</given-names></name><name name-style="western" xml:lang="en"><surname>Bekmukhan</surname><given-names>A. S.</given-names></name></name-alternatives><bio xml:lang="ru"><p>М.т.н., сениор-лектор</p><p>Алматы</p></bio><bio xml:lang="en"><p>M.E.Sc., Senior Lecturer</p><p>Almaty</p></bio><email xlink:type="simple">a.bekmukhan@iitu.edu.kz</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0005-2983-3377</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Абильдаева</surname><given-names>T. T.</given-names></name><name name-style="western" xml:lang="en"><surname>Abildayeva</surname><given-names>T. T.</given-names></name></name-alternatives><bio xml:lang="ru"><p>М.т.н., сениор-лектор</p><p>Алматы</p></bio><bio xml:lang="en"><p>M.E.Sc., Senior Lecturer</p><p>Almaty</p></bio><email xlink:type="simple">t.abildayeva@iitu.edu.kz</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-4270-1908</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ескендирова</surname><given-names>Д. M.</given-names></name><name name-style="western" xml:lang="en"><surname>Yeskendirova</surname><given-names>D. M.</given-names></name></name-alternatives><bio xml:lang="ru"><p>К.т.н., ассоциированный профессор</p><p>Алматы</p></bio><bio xml:lang="en"><p>Cand. Sc. (Tech.), Associate Professor</p><p>Almaty</p></bio><email xlink:type="simple">d.yeskendirova@iitu.edu.kz</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Международный университет информационных технологий</institution><country>Казахстан</country></aff><aff xml:lang="en"><institution>International Information Technologies University</institution><country>Kazakhstan</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>25</day><month>09</month><year>2026</year></pub-date><volume>23</volume><issue>3</issue><fpage>176</fpage><lpage>187</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Батырханова А.А., Бекмухан А.С., Абильдаева T.T., Ескендирова Д.M., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Батырханова А.А., Бекмухан А.С., Абильдаева T.T., Ескендирова Д.M.</copyright-holder><copyright-holder xml:lang="en">Batyrkhanova A.A., Bekmukhan A.S., Abildayeva T.T., Yeskendirova D.M.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://vestnik.kbtu.edu.kz/jour/article/view/3183">https://vestnik.kbtu.edu.kz/jour/article/view/3183</self-uri><abstract><p>В статье рассмотрено двойное применение генеративного искусственного интеллекта в кибербезо­пасности: как инструмент атаки и как элемент защиты. Показано, что генерация правдоподобного текста, изображений и аудио упрощает злоупотребления (фишинг, дипфейки, подмена коммуникаций), а в задачах машинного обучения возникает отдельный риск малые, но целенаправленные возмущения входа. Прак­тическая часть выполнена на воспроизводимом стенде с классификатором рукописных цифр MNIST: на чистых данных модель демонстрировала стабильное распознавание, после чего применялась атака FGSM с варьированием параметра е. Зафиксировано, что визуально почти незаметный шум способен переводить уверенную классификацию в ошибочную (на характерном примере «7» была получена неверная метка «3»). Для противодействия проверены два реконструктивных подхода: обычный автокодировщик (AE) и деноизинговый автокодировщик (DAE), обученный восстанавливать чистый сигнал из зашумленного входа. При росте е DAE снижал долю ошибок заметнее, чем AE, поскольку лучше отделял высокочастотные компонен­ты возмущения от полезных штрихов. Дополнительно введен детектор аномалии по энергии реконструкции E(x), позволяющий не только «очищать» вход, но и фиксировать факт подозрительного воздействия для последующего анализа инцидентов.</p></abstract><trans-abstract xml:lang="en"><p>This paper examines the dual role of generative artificial intelligence in cybersecurity: as an enabler of attacks and as a practical defense component. It is shown that realistic generation of text, images, and audio lowers the barrier for abuse (phishing, deepfakes, impersonation), while machine learning systems face a distinct risk class­small but targeted input perturbations. The practical part is implemented as a reproducible benchmark around an MNIST handwritten-digit classifier. After verifying stable performance on clean inputs, adversarial examples were generated using FGSM with multiple values of e. The results confirm that a visually subtle perturbation can flip a confident prediction to an incorrect class (in a representative case, a “7” was forced to be classified as “3”). Two reconstruction-based defenses were then compared: a standard autoencoder (AE) and a denoising autoencoder (DAE) trained to recover clean signals from noisy inputs. As e increases, DAE reduces the misclassification rate more noticeably than AE, which is consistent with its training objective of separating high-frequency noise from meaningful strokes. To make the defense actionable in an operational setting, a simple anomaly detector based on reconstruction energy E(x) was also introduced. This adds a second layer: the DAE attempts to restore the input for correct classification, while E(x) provides an explicit alert signal suitable for logging and incident review.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>generative AI</kwd><kwd>cybersecurity</kwd><kwd>adversarial examples</kwd><kwd>FGSM</kwd><kwd>MNIST</kwd><kwd>autoencoder</kwd><kwd>denoising autoencoder</kwd><kwd>anomaly detection</kwd><kwd>reconstruction error</kwd></kwd-group><kwd-group xml:lang="en"><kwd>generative AI</kwd><kwd>cybersecurity</kwd><kwd>adversarial examples</kwd><kwd>FGSM</kwd><kwd>MNIST</kwd><kwd>autoencoder</kwd><kwd>denoising autoencoder</kwd><kwd>anomaly detection</kwd><kwd>reconstruction error</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y. Generative adversarial nets. Advances in Neural Information Processing Systems, 27, 2672–2680 (2014).</mixed-citation><mixed-citation xml:lang="en">Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y. Generative adversarial nets. Advances in Neural Information Processing Systems, 27, 2672–2680 (2014).</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Hu, W., and Tan, Y. Generating adversarial malware examples for black-box attacks based on GAN. arXiv preprint (2017). arXiv:1702.05983.</mixed-citation><mixed-citation xml:lang="en">Hu, W., and Tan, Y. Generating adversarial malware examples for black-box attacks based on GAN. arXiv preprint (2017). arXiv:1702.05983.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Xiao, C., Li, B., Zhu, J.-Y., He, W., Liu, M., and Song, D. Generating adversarial examples with adversarial networks. Proceedings of the 27th International Joint Conference on Artificial Intelligence (IJCAI) (2018), pp. 3905–3911.</mixed-citation><mixed-citation xml:lang="en">Xiao, C., Li, B., Zhu, J.-Y., He, W., Liu, M., and Song, D. Generating adversarial examples with adversarial networks. Proceedings of the 27th International Joint Conference on Artificial Intelligence (IJCAI) (2018), pp. 3905–3911.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Lin, Z., Shi, Y., and Xue, Z. IDSGAN: Generative adversarial networks for attack generation against intrusion detection. PAKDD 2022, LNCS 13282 (2022), pp. 79–91.</mixed-citation><mixed-citation xml:lang="en">Lin, Z., Shi, Y., and Xue, Z. IDSGAN: Generative adversarial networks for attack generation against intrusion detection. PAKDD 2022, LNCS 13282 (2022), pp. 79–91.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Lakshmanan, R. WormGPT: New AI tool allows cybercriminals to launch sophisticated cyber attacks. The Hacker News (15 July 2023).</mixed-citation><mixed-citation xml:lang="en">Lakshmanan, R. WormGPT: New AI tool allows cybercriminals to launch sophisticated cyber attacks. The Hacker News (15 July 2023).</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Haidar, A. Kazakhstan pushes nationwide AI rollout amid cybersecurity risks and skills shortages. The Times of Central Asia (18 August 2025).</mixed-citation><mixed-citation xml:lang="en">Haidar, A. Kazakhstan pushes nationwide AI rollout amid cybersecurity risks and skills shortages. The Times of Central Asia (18 August 2025).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Afane, K., Wei, W., Mao, Y., Farooq, J., and Chen, J. Next-generation phishing: How LLM agents empower cyber attackers. arXiv preprint (2024). arXiv:2411.13874.</mixed-citation><mixed-citation xml:lang="en">Afane, K., Wei, W., Mao, Y., Farooq, J., and Chen, J. Next-generation phishing: How LLM agents empower cyber attackers. arXiv preprint (2024). arXiv:2411.13874.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Roy, S.S., Thota, P., Naragam, K.V., and Nilizadeh, S. From chatbots to phishbots? Phishing scam generation in commercial large language models. Proceedings of IEEE Symposium on Security and Privacy (2024), p. 221.</mixed-citation><mixed-citation xml:lang="en">Roy, S.S., Thota, P., Naragam, K.V., and Nilizadeh, S. From chatbots to phishbots? Phishing scam generation in commercial large language models. Proceedings of IEEE Symposium on Security and Privacy (2024), p. 221.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Croitoru, A., Ionescu, R.T., Khan, F.S., Shah, M., et al. Deepfake media generation and detection in the generative AI era: A survey and outlook. arXiv preprint (2024). arXiv:2411.19537.</mixed-citation><mixed-citation xml:lang="en">Croitoru, A., Ionescu, R.T., Khan, F.S., Shah, M., et al. Deepfake media generation and detection in the generative AI era: A survey and outlook. arXiv preprint (2024). arXiv:2411.19537.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Saeed, U., Jan, S.U., Ahmad, J., Shah, S.A., Alshehri, M.S., Ghadi, Y.Y., Pitropakis, N., and Buchanan, W.J. Generative adversarial networks-enabled anomaly detection systems: A survey. Expert Systems with Applications, 296, 128978 (2026). https://doi.org/10.1016/j.eswa.2025.128978</mixed-citation><mixed-citation xml:lang="en">Saeed, U., Jan, S.U., Ahmad, J., Shah, S.A., Alshehri, M.S., Ghadi, Y.Y., Pitropakis, N., and Buchanan, W.J. Generative adversarial networks-enabled anomaly detection systems: A survey. Expert Systems with Applications, 296, 128978 (2026). https://doi.org/10.1016/j.eswa.2025.128978</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Samangouei, P., Kabkab, M., and Chellappa, R. Defense-GAN: Protecting classifiers against adversarial attacks using generative models. Proceedings of ICLR (2018).</mixed-citation><mixed-citation xml:lang="en">Samangouei, P., Kabkab, M., and Chellappa, R. Defense-GAN: Protecting classifiers against adversarial attacks using generative models. Proceedings of ICLR (2018).</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Heiding, F., Schneier, B., Vishwanath, A., Bernstein, J., and Park, P.S. Devising and detecting phishing emails using large language models. IEEE Access, 12, 42131–42146 (2024). https://doi.org/10.1109/ACCESS.2024.3375882</mixed-citation><mixed-citation xml:lang="en">Heiding, F., Schneier, B., Vishwanath, A., Bernstein, J., and Park, P.S. Devising and detecting phishing emails using large language models. IEEE Access, 12, 42131–42146 (2024). https://doi.org/10.1109/ACCESS.2024.3375882</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Heiding, F., Lermen, S., Kao, A., Schneier, B., and Vishwanath, A. Evaluating large language models’ capability to launch fully automated spear phishing campaigns: Validated on human subjects. arXiv preprint (2024). arXiv:2412.00586.</mixed-citation><mixed-citation xml:lang="en">Heiding, F., Lermen, S., Kao, A., Schneier, B., and Vishwanath, A. Evaluating large language models’ capability to launch fully automated spear phishing campaigns: Validated on human subjects. arXiv preprint (2024). arXiv:2412.00586.</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">SlashNext. WormGPT: The new generative AI tool used by cybercriminals to launch business email compromise attacks (2023).</mixed-citation><mixed-citation xml:lang="en">SlashNext. WormGPT: The new generative AI tool used by cybercriminals to launch business email compromise attacks (2023).</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Europol Innovation Lab. ChatGPT: The impact on law enforcement (2023).</mixed-citation><mixed-citation xml:lang="en">Europol Innovation Lab. ChatGPT: The impact on law enforcement (2023).</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Rössler, A., Cozzolino, D., Verdoliva, L., Riess, C., Thies, J., and Nießner, M. FaceForensics++: Learning to detect manipulated facial images. Proceedings of IEEE/CVF International Conference on Computer Vision (ICCV) (2019).</mixed-citation><mixed-citation xml:lang="en">Rössler, A., Cozzolino, D., Verdoliva, L., Riess, C., Thies, J., and Nießner, M. FaceForensics++: Learning to detect manipulated facial images. Proceedings of IEEE/CVF International Conference on Computer Vision (ICCV) (2019).</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. Intriguing properties of neural networks. arXiv preprint (2013). arXiv:1312.6199.</mixed-citation><mixed-citation xml:lang="en">Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. Intriguing properties of neural networks. arXiv preprint (2013). arXiv:1312.6199.</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Goodfellow, I.J., Shlens, J., and Szegedy, C. Explaining and harnessing adversarial examples. arXiv preprint (2015). arXiv:1412.6572.</mixed-citation><mixed-citation xml:lang="en">Goodfellow, I.J., Shlens, J., and Szegedy, C. Explaining and harnessing adversarial examples. arXiv preprint (2015). arXiv:1412.6572.</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">Vincent, P., Larochelle, H., Lajoie, I., Bengio, Y., and Manzagol, P.-A. Extracting and composing robust features with denoising autoencoders. Proceedings of the 25th International Conference on Machine Learning (ICML) (2008), pp. 1096–1103.</mixed-citation><mixed-citation xml:lang="en">Vincent, P., Larochelle, H., Lajoie, I., Bengio, Y., and Manzagol, P.-A. Extracting and composing robust features with denoising autoencoders. Proceedings of the 25th International Conference on Machine Learning (ICML) (2008), pp. 1096–1103.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
