2606004269
  • Open Access
  • Perspective

A Comprehensive AI Security Pipeline: Drift Detection, Adversarial Robustness and Automated ML Testing

  • Siddharth Kumar 1,*,   
  • Siddhanth Harish Bist 2,*

Received: 16 Apr 2026 | Revised: 02 Jun 2026 | Accepted: 16 Jun 2026 | Published: 12 Aug 2026

Abstract

The wide-scale uptake of machine learning applications in safety-sensitive applications renders modern AI deployments prone to adversarial attacks, statistical distribution changes, and various governance reliability issues. Current AI security methodologies generally handle the discussed issues separately, making the current security approaches ineffective in real-world conditions. In this work, an integrated AI security pipeline combining the functionalities of statistical drift detection, adversarial robustness evaluation, governance auditing, and experiment tracking is suggested. The presented system uses Kolmogorov—Smirnov tests, Population Stability Index analysis, and drift detection in data streams via ADWIN in addition to adversarial robustness evaluation through FGSM, PGD, and DeepFool attacks. The Giskard library was used to audit AI models’ performance from the governance perspective. Evaluation of our approach on image and tabular datasets showed the capability of detecting statistically significant drift and significant CNN robustness degradation under increasingly complex adversarial attacks. It turned out that iterative and geometry-aware attack schemes perform significantly better than one-shot perturbations. Drift detection proved effective at spotting statistically significant distribution changes before actual deployment failures.

References 

  • 1.

    Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and Harnessing Adversarial Examples. arXiv 2014. arXiv:1412.6572.

  • 2.

    Madry, A.; Makelov, A.; Schmidt, L.; et al. Towards Deep Learning Models Resistant to Adversarial Attacks. In Proceedings of the International Conference on Learning Representations (ICLR 2018), Vancouver, BC, Canada, 30 April–3 May 2018.

  • 3.

    Moosavi-Dezfooli, S.; Fawzi, A.; Frossard, P. DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR 2016), Las Vegas, NV, USA, 27 June–1 July 2016; pp. 2574–2582.

  • 4.

    Rauber, J.; Brendel, W.; Bethge, M. Foolbox: A Python Toolbox to Benchmark the Robustness of Machine Learning Models. arXiv 2017. arXiv:1707.04131.

  • 5.

    Papernot, N.; Faghri, F.; Carlini, N.; et al. Technical Report on the CleverHans v2.1.0 Adversarial Examples Library. arXiv 2016. arXiv:1610.00768.

  • 6.

    Bifet, A.; Gavalda, R. Learning from Time-Changing Data with Adaptive Windowing. In Proceedings of the Seventh SIAM International Conference on Data Mining, Minneapolis, MN, USA, 26–28 April 2007; pp. 443–448.

  • 7.

    Greco, S.; Vacchetti, B.; Apiletti, D.; et al. Unsupervised Concept Drift Detection from Deep Learning Representations in Real-Time. IEEE Trans. Knowl. Data Eng. 2025, 37, 6232–6245. https://doi.org/10.1109/TKDE.2025.3593123.

  • 8.

    Lundberg, S.; Lee, S.-I. A Unified Approach to Interpreting Model Predictions. In Proceedings of the Annual Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, CA, USA, 4–9 December 2017; pp. 4765–4774.

  • 9.

    Ribeiro, M.; Singh, S.; Guestrin, C. Why Should I Trust You?: Explaining the Predictions of Any Classifier. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA, 13–17 August 2016; pp. 1135–1144.

  • 10.

    Ijiga, O.M.; Idoko, I.P.; Ebiega, G.I.; et al. Harnessing Adversarial Machine Learning for Advanced Threat Detection: AI-Driven Strategies in Cybersecurity Risk Assessment and Fraud Prevention. Open Access Res. J. Sci. Technol. 2024, 11, 1–24.

  • 11.

    Cohen, J.; Rosenfeld, E.; Kolter, Z. Certified Adversarial Robustness via Randomized Smoothing. In Proceedings of the International Conference on Machine Learning (ICML 2019), Long Beach, CA, USA, 9–15 June 2019; pp. 1310–1320.

  • 12.

    Wong, E.; Kolter, J.Z. Provable Defenses Against Adversarial Examples via the Convex Outer Adversarial Polytope. In Proceedings of the International Conference on Machine Learning (ICML 2018), Stockholm, Sweden, 10–15 July 2018; pp. 5283–5292.

  • 13.

    Lyu, S.; Shaikh, S.; Shpilevskiy, F.; et al. Adaptive Randomized Smoothing: Certified Adversarial Robustness for Multi-Step Defences. In Proceedings of the Annual Conference on Neural Information Processing Systems (NeurIPS 2024), Vancouver, BC, Canada, 9–15 December 2024; pp. 134043–134074.

  • 14.

    Giskard Team. Open-Source ML Testing Framework; Giskard: Paris, France, 2023.

  • 15.

    Pepe, F.; Nardone, V.; Mastropaolo, A.; et al. Datasets, Bias, Licenses, and Terms of Use: A Large and Longitudinal Study on the Documentation of Hugging Face Machine Learning Models. Empir. Softw. Eng. 2026, 31, 95. https://doi.org/10.1007/s10664-026-10843-1.

  • 16.

    Cannavale, A.; Pontillo, V.; De Lucia, A.; et al. Understanding Machine Learning Testing in Practice. J. Syst. Softw. 2026, 240, 112925. https://doi.org/10.1016/j.jss.2026.112925.

  • 17.

    Pakina, A.K. Alignment Drift as a Security Threat: Detecting and Mitigating Misaligned AI Behavior in Regulated Systems. Int. J. Innov. Sci. Res. Technol. 2025, 10, 1856–1867. https://doi.org/10.38124/ijisrt/25dec1365.

  • 18.

    Fisher, R.A. The Use of Multiple Measurements in Taxonomic Problems. Ann. Eugen. 1936, 7, 179–188.

  • 19.

    Zhang, J.M.; Harman, M.; Ma, L.; et al. Machine Learning Testing: Survey, Landscapes and Horizons. IEEE Trans. Softw. Eng. 2020, 48, 1–36.

  • 20.

    Patchipala, S.G. Tackling Data and Model Drift in AI: Strategies for Maintaining Accuracy during ML Model Inference. Int. J. Sci. Res. Arch. 2023, 10, 1198–1209. https://doi.org/10.30574/ijsra.2023.10.2.0855.

  • 21.

    Agarwal, A.; Nene, M.J. Advancing Trustworthy AI: A Comparative Evaluation of AI Robustness Toolboxes. SN Comput. Sci. 2025, 6, 234.

  • 22.

    LeCun, Y.; Bottou, L.; Bengio, Y.; et al. Gradient-Based Learning Applied to Document Recognition. Proc. IEEE 1998, 86, 2278–2324.

  • 23.

    Papernot, N.; McDaniel, P.; Sinha, A.; et al. SoK: Security and Privacy in Machine Learning. In Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), London, UK, 24–26 April 2018; pp. 399–414.

  • 24.

    Hulten, G.; Spencer, L.; Domingos, P. Mining Time-Changing Data Streams. In Proceedings of the Seventh ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA, 26–29 August 2001.

Share this article:
How to Cite
Kumar, S.; Bist, S. H. A Comprehensive AI Security Pipeline: Drift Detection, Adversarial Robustness and Automated ML Testing. AI Engineering 2026, 2 (2), 13. https://doi.org/10.53941/aieng.2026.100013.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.