Strategic deception has passed through three generations; the third one takes aim at the reasoning machine, and it changes what deception is for
In the autumn of 1962, at the height of the Cuban Missile Crisis, a United States Navy destroyer positioned itself north of Havana and switched on a device that could conjure an aircraft out of nothing. The device was called Palladium, and it did something conceptually simple and strategically profound: it received a Soviet radar’s signal, delayed it by a precisely calibrated interval, and transmitted it back, so that the radar registered a ghost aircraft racing toward the Cuban capital at a speed and altitude the operators chose. As Soviet and Cuban air defences reacted — scrambling MiGs, activating fire-control radars — National Security Agency technicians listened, learning exactly how sensitive the enemy’s radars were and how small a radar cross-section they could detect. The information fed directly into the design of the stealth aircraft that would follow. When the technicians switched Palladium off, the ghost vanished, leaving a confused adversary chasing a target that had never existed.[1]
Palladium is a useful place to begin because it marks a recognisable species of deception: an operation aimed at a machine’s sensors, conducted to provoke a human response that could be observed and exploited. It was sophisticated, but its logic was legible. Deception has a long lineage, and its practitioners have always understood it as the art of shaping what an adversary perceives. What has changed — twice now — is the target of the shaping. This Signal traces that change through three generations, and argues that the third is different in kind from the first two, because for the first time the thing being deceived is not a human perceiving through a machine, but a machine that reasons on the human’s behalf. The framework is deliberately light; the point is the trajectory, not a taxonomy.
First generation: deceiving the sensor
The first generation of modern strategic deception aimed at the adversary’s sensors and the humans reading them. Palladium is the crisp example, but the broader tradition is older and deeper. The Russian doctrine of maskirovka — literally ‘masking’ — was formalised as Soviet operational art in the 1930s and reached full expression in the Second World War, where large-scale deception contributed to the surprise achieved at Stalingrad, Kursk, and Operation Bagration despite the enormous concentrations of force involved.[2] Its instruments were physical and perceptual: camouflage, decoys and dummies, feints, concealment of the timing and location of an attack. The target was the enemy commander’s picture of the battlefield, assembled from reconnaissance, and the aim was surprise — to make the adversary see strength as weakness, presence as absence, the main axis as a diversion.
What unites Palladium and classical maskirovka is that both operate on perception at the point of collection. They corrupt the inputs — the radar return, the aerial photograph, the scout’s report — so that the human decision-maker, reasoning correctly from false data, reaches a wrong conclusion. The deception is doctrinal in the sense that it is planned centrally, executed against a known collection system, and evaluated by its effect on a human mind. This is deception as most of military history has understood it, and it remains entirely current; the inflatable missile systems and decoy formations of contemporary conflicts are its direct descendants.
Epistemic status: Confirmed. Project Palladium is documented in declassified CIA accounts, including a first-person description by the retired CIA executive who devised it, and in the published history of the A-12/Blackbird programme.[3] The maskirovka lineage and its wartime applications are established in the scholarly literature on Soviet military deception.[4] Nothing in this section is inferred.
Second generation: deceiving the information environment
The second generation widened the target from the sensor to the information environment itself. As information moved faster and reached further, deception ceased to be only about corrupting a specific collection channel and became about shaping the entire perceptual field within which an adversary — military and civilian alike — formed beliefs. The Soviet and later Russian doctrine tracked this shift explicitly: maskirovka broadened from battlefield masking into strategic and political disinformation, the manipulation of facts and perceptions to affect opinion and decision-making well beyond the battlefield.[5] In its contemporary form, often discussed under the heading of information confrontation, it fuses traditional deception with cyber operations, electronic warfare, and psychological influence.[6]
The distinguishing feature of the second generation is that it targets not a single sensor but the process of sense-making across a population. Where the first generation asked ‘what will this radar report’, the second asks ‘what will this society come to believe’. Its instruments are narrative, forgery, amplification, and the exploitation of the media environment’s own structure. The target is still ultimately a human mind, but reached at scale and through the ambient information environment rather than through a discrete collection system. This is the generation most discussed in the past decade, and we treat it briefly here precisely because it is well covered elsewhere; the Signal’s interest is in what comes after it.
Epistemic status: Confirmed as to the doctrinal evolution, which is documented in the literature on Russian military deception and its extension into the information domain.[7] Characterisations of specific contemporary influence operations vary in their evidential quality and attribution confidence; this section deliberately stays at the level of the documented doctrinal shift rather than adjudicating particular episodes, which is a matter for a more forensic treatment than a Signal allows.
Third generation: deceiving the reasoning machine
The third generation is the one that changes the nature of the enterprise, and it is worth stating its novelty precisely. In the first two generations, the ultimate target of deception is a human mind — reached through a corrupted sensor, or through a polluted information environment, but a human mind nonetheless. In the third generation, the target is a machine that reasons: an artificial-intelligence system that itself perceives, classifies, and increasingly recommends or decides, with the human moved further from the point of judgement. Deception against such a system is not deception of perception in the old sense. It is manipulation of an automated reasoning process, exploiting the specific and often non-intuitive ways in which machine-learning systems can be made to fail.
The field that studies this is adversarial machine learning, and it is now formalised to the point of having a national-standards taxonomy. The United States National Institute of Standards and Technology published a formal taxonomy and terminology for adversarial machine learning, distinguishing attacks by the stage at which they strike.[8] Two categories matter most for the deception analogy. Evasion attacks operate at deployment: an adversary makes a small, often humanly imperceptible perturbation to an input — the classic demonstration is that altering an image slightly, sometimes by a single pixel, can cause a deep neural network to misclassify it — so that the system confidently reaches a wrong conclusion.[9] Poisoning attacks operate earlier, at training: an adversary who can influence a subset of the data on which a model is trained can insert corrupted samples or hidden triggers, biasing the model’s future behaviour or embedding a backdoor that activates on a chosen signal.[10]
The strategic significance becomes clear when these techniques are pointed at military systems, and here the analysis has moved from the laboratory into serious defence discussion. A West Point legal-institute analysis frames data poisoning explicitly as a covert weapon: by introducing manipulated data during an adversary’s training phase, an AI system used for reconnaissance or targeting could be biased toward misclassification — an adversary’s autonomous system induced to misidentify vehicles, or to misread battlefield conditions — with the aim not of indiscriminate malfunction but of controlled degradation of the adversary’s decision quality.[11] The defence-technology community has recognised the same vulnerability from the receiving end: adversarial examples that cause a lethal autonomous system to misidentify friendly vehicles as hostile, or satellite imagery to be misread, are understood as a tangible national-security threat precisely because the conditions that trigger them are unintuitive to humans and hard to predict.[12]
Epistemic status: mixed, and the distinctions matter. The techniques — evasion and poisoning attacks — are Confirmed as an established, formally catalogued field, documented in the NIST taxonomy and the peer-reviewed literature.[13] The framing of these techniques as instruments of strategic deception against adversary military AI is a serious and documented line of defence analysis,[14][15] but it describes a capability and an intent, not a roster of confirmed operational uses. Publicly confirmed, well-attributed cases of one state successfully poisoning or evading another state’s fielded military AI in the wild are, as of writing, scarce — which is itself an important finding. We assess this as a maturing capability whose doctrinal significance is real and whose operational track record is not yet publicly established. A reader told that AI-targeting deception is ‘happening’ has been given the true statement that the capability and the intent exist, not the unsupported one that a documented campaign has occurred.
What the third generation changes
Set the three generations side by side and the trajectory is clear: the target of deception has moved from the sensor, to the information environment, to the reasoning process itself. Each generation did not replace its predecessor — Palladium-style sensor spoofing and maskirovka-style narrative deception are both entirely current — but each added a new layer at which perception could be corrupted. The third layer is different in three respects that a reader of current events should hold in mind.
First, the third generation moves the point of attack from perception to cognition. It does not merely feed a decision-maker false data; it corrupts the automated process that turns data into judgement, at a point where no human may be watching closely enough to notice. Second, it can be latent and deferred. A poisoning attack inserted during training may lie dormant until a chosen trigger appears, which means the deception and its effect can be separated by months or years — a property first-generation deception, tied to a live operation, never had. Third, and most consequentially, it exploits failure modes that are unintuitive to the human mind. A commander can imagine how an enemy might be fooled by a decoy, because the commander shares the perceptual apparatus being fooled. Neither the commander nor the adversary shares the machine’s perceptual apparatus, which fails in ways — the single altered pixel, the imperceptible perturbation — that no human would ever be deceived by. This is deception whose mechanism its own victims may be unable to intuit.
For a reader whose task is to interpret current events, the practical implication is a discipline of suspicion applied in a new place. As automated systems move closer to the point of military and intelligence judgement, the question ‘has this decision-maker been deceived’ must be asked not only of the human but of the machine advising the human — and asked knowing that machine deception can be latent, imperceptible, and inserted long before it acts. The first generation taught analysts to distrust the radar return. The second taught them to distrust the information environment. The third asks them to distrust the reasoning of the systems they increasingly rely on to make sense of both. That is a harder discipline, because the failure modes are stranger, and because the systems that would be deceived are often the same ones an organisation has adopted precisely to reduce its dependence on fallible human judgement. The reasoning machine was meant to be the corrective to deception. It is becoming its newest target.
References
First generation — sensor deception
Poteat SE (declassified CIA account), on the conception and operation of Project Palladium; and P.F. Crickmore, Lockheed Blackbird: Beyond the Secret Missions (rev. ed.), describing Palladium as a highly classified programme to test the sensitivity of Soviet radars during the A-12/Oxcart era, including the Cuban Missile Crisis radar-spoofing operation off Havana.
Second generation — information-environment deception
On maskirovka: the scholarly literature on Russian/Soviet military deception, including D. Glantz, Soviet Military Deception in the Second World War; on its wartime application at Stalingrad, Kursk, and Operation Bagration, and its later extension into strategic/political disinformation and information confrontation (informatsionnoye protivoborstvo).
Third generation — adversarial machine learning and its strategic framing
US National Institute of Standards and Technology, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, NIST AI 100-2e2025, distinguishing training-stage poisoning attacks from deployment-stage evasion attacks.
Lieber Institute, US Military Academy at West Point, analysis of data poisoning as a covert instrument against adversary military AI (controlled degradation of decision quality via manipulated training data), 2025.
AFCEA / SIGNAL, on adversarial machine learning as a national-security threat, including adversarial examples causing misclassification in autonomous and image-analysis systems.
