Its still a fully encapsulated set of input and output.
The opponent is never able to change the rule set itself. Motivated attackers will target the AI itself, or its drones.
Effectively autonomous vehicles are not there yet - when the first real war with these things happens, the evolutionary hacking and counter hacking cycle is going to be ridiculous, if they ever get deployed.
i guess you could call it a classifier but it is a complex one that can make some great decisions