{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/110735"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/110735","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Adversarial methods in machine learning - a federated defense and an attack","abstract":"Deep Neural networks have recently been shown to provide state-of-the-art results for several machine learning tasks, in computer vision and natural language processing applications. These developments make security aspects of machine learning increasingly important. Unfortunately, neural networks are vulnerable to adversarial examples — inputs that are almost indistinguishable from natural data and yet elicit misclassification from the network. The focus of this thesis is to investigate the space of adversarial examples in hitherto novel applications. We first study Adversarial Training(AT) which is a defense against adversarial examples, in a federated learning setup. Federated learning is a paradigm for multi-round model training over a distributed corpus of agent data. We propose FedDynAT, a novel algorithm for performing AT in a federated setting. Through extensive experimentation, we show that FedDynAT significantly improves both natural and adversarial accuracy, as well as model convergence time by reducing model drift. We next formulate an attack against 3D reconstruction models. While adversarial examples for 2D images and Convolutional Neural Networks have been extensively studied, less attention has been paid to attacking 3D reconstruction models. 3D reconstruction models have been widely applied to various domains, such as e-commerce, architecture, CAD, virtual reality, and medical processes. It is thereby of great importance to explore the vulnerabilities of such 3D models, and design methods to improve their robustness in practice. We propose a novel 3D Spatial-Pixel Joint Optimization attack (3D-SPJO) to generate adversarial 2D input against a 3D Reconstruction model, which reconstructs the attacker specified 3D voxelized grid. We conduct extensive ablation studies to evaluate 3D-SPJO on 3D-R2N2 and Pix2Vox models which are state-of-the-art 3D reconstruction models trained on the ShapeNet dataset.","abstract_html":"Deep Neural networks have recently been shown to provide state-of-the-art results for several machine learning tasks, in computer vision and natural language processing applications. These developments make security aspects of machine learning increasingly important. Unfortunately, neural networks are vulnerable to adversarial examples — inputs that are almost indistinguishable from natural data and yet elicit misclassification from the network. The focus of this thesis is to investigate the space of adversarial examples in hitherto novel applications. We first study Adversarial Training(AT) which is a defense against adversarial examples, in a federated learning setup. Federated learning is a paradigm for multi-round model training over a distributed corpus of agent data. We propose FedDynAT, a novel algorithm for performing AT in a federated setting. Through extensive experimentation, we show that FedDynAT significantly improves both natural and adversarial accuracy, as well as model convergence time by reducing model drift. We next formulate an attack against 3D reconstruction models. While adversarial examples for 2D images and Convolutional Neural Networks have been extensively studied, less attention has been paid to attacking 3D reconstruction models. 3D reconstruction models have been widely applied to various domains, such as e-commerce, architecture, CAD, virtual reality, and medical processes. It is thereby of great importance to explore the vulnerabilities of such 3D models, and design methods to improve their robustness in practice. We propose a novel 3D Spatial-Pixel Joint Optimization attack (3D-SPJO) to generate adversarial 2D input against a 3D Reconstruction model, which reconstructs the attacker specified 3D voxelized grid. We conduct extensive ablation studies to evaluate 3D-SPJO on 3D-R2N2 and Pix2Vox models which are state-of-the-art 3D reconstruction models trained on the ShapeNet dataset.","abstract_has_math":false,"creators":["Shah, Devansh"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Li, Bo"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2021,"date_issued":"2021-09-17T02:34:46Z","date_published":"2021-09-17T02:34:46Z","updated_at":"2026-07-22T22:24:52Z","subjects":["Machine Learning","Adversarial Learning","Federated Learning","Computer Vision"],"languages":["en"],"rights":["Copyright 2021 Devansh Shah"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/110735","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Li, Bo"]},{"key":"dc:creator","label":"Author","values":["Shah, Devansh"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2021-09-17T02:34:46Z","2023-09-17T02:34:57Z","2021-04-26","2021-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Machine Learning","Adversarial Learning","Federated Learning","Computer Vision"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2021 Devansh Shah"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/110735"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Deep Neural networks have recently been shown to provide state-of-the-art results for several machine learning tasks, in computer vision and natural language processing applications. These developments make security aspects of machine learning increasingly important. Unfortunately, neural networks are vulnerable to adversarial examples — inputs that are almost indistinguishable from natural data and yet elicit misclassification from the network. The focus of this thesis is to investigate the space of adversarial examples in hitherto novel applications. We first study Adversarial Training(AT) which is a defense against adversarial examples, in a federated learning setup. Federated learning is a paradigm for multi-round model training over a distributed corpus of agent data. We propose FedDynAT, a novel algorithm for performing AT in a federated setting. Through extensive experimentation, we show that FedDynAT significantly improves both natural and adversarial accuracy, as well as model convergence time by reducing model drift. We next formulate an attack against 3D reconstruction models. While adversarial examples for 2D images and Convolutional Neural Networks have been extensively studied, less attention has been paid to attacking 3D reconstruction models. 3D reconstruction models have been widely applied to various domains, such as e-commerce, architecture, CAD, virtual reality, and medical processes. It is thereby of great importance to explore the vulnerabilities of such 3D models, and design methods to improve their robustness in practice. We propose a novel 3D Spatial-Pixel Joint Optimization attack (3D-SPJO) to generate adversarial 2D input against a 3D Reconstruction model, which reconstructs the attacker specified 3D voxelized grid. We conduct extensive ablation studies to evaluate 3D-SPJO on 3D-R2N2 and Pix2Vox models which are state-of-the-art 3D reconstruction models trained on the ShapeNet dataset.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2023-05-01","The student, Devansh Shah, accepted the attached license on 2021-04-23 at 13:33.","The student, Devansh Shah, submitted this Thesis for approval on 2021-04-23 at 13:39.","This Thesis was approved for publication on 2021-04-26 at 15:41.","DSpace SAF Submission Ingestion Package generated from Vireo submission #16530 on 2021-09-16 at 17:05:05","Made available in DSpace on 2021-09-17T02:34:46Z (GMT). No. of bitstreams: 2 SHAH-THESIS-2021.pdf: 4522623 bytes, checksum: 0a8a11813c6d3039de4f9e68404977fc (MD5) LICENSE.txt: 4209 bytes, checksum: c0763174625e303601805b01f27558c5 (MD5) Previous issue date: 2021-04-26","Embargo set by: Seth Robbins for item 118578 Lift date: 2023-09-17T02:34:57Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Adversarial methods in machine learning - a federated defense and an attack"]}]}],"canonical_facts":{"dc:contributor":["Li, Bo"],"dc:creator":["Shah, Devansh"],"dc:date":["2021-09-17T02:34:46Z","2023-09-17T02:34:57Z","2021-04-26","2021-05"],"dc:description":["Deep Neural networks have recently been shown to provide state-of-the-art results for several machine learning tasks, in computer vision and natural language processing applications. These developments make security aspects of machine learning increasingly important. Unfortunately, neural networks are vulnerable to adversarial examples — inputs that are almost indistinguishable from natural data and yet elicit misclassification from the network. The focus of this thesis is to investigate the space of adversarial examples in hitherto novel applications. We first study Adversarial Training(AT) which is a defense against adversarial examples, in a federated learning setup. Federated learning is a paradigm for multi-round model training over a distributed corpus of agent data. We propose FedDynAT, a novel algorithm for performing AT in a federated setting. Through extensive experimentation, we show that FedDynAT significantly improves both natural and adversarial accuracy, as well as model convergence time by reducing model drift. We next formulate an attack against 3D reconstruction models. While adversarial examples for 2D images and Convolutional Neural Networks have been extensively studied, less attention has been paid to attacking 3D reconstruction models. 3D reconstruction models have been widely applied to various domains, such as e-commerce, architecture, CAD, virtual reality, and medical processes. It is thereby of great importance to explore the vulnerabilities of such 3D models, and design methods to improve their robustness in practice. We propose a novel 3D Spatial-Pixel Joint Optimization attack (3D-SPJO) to generate adversarial 2D input against a 3D Reconstruction model, which reconstructs the attacker specified 3D voxelized grid. We conduct extensive ablation studies to evaluate 3D-SPJO on 3D-R2N2 and Pix2Vox models which are state-of-the-art 3D reconstruction models trained on the ShapeNet dataset.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2023-05-01","The student, Devansh Shah, accepted the attached license on 2021-04-23 at 13:33.","The student, Devansh Shah, submitted this Thesis for approval on 2021-04-23 at 13:39.","This Thesis was approved for publication on 2021-04-26 at 15:41.","DSpace SAF Submission Ingestion Package generated from Vireo submission #16530 on 2021-09-16 at 17:05:05","Made available in DSpace on 2021-09-17T02:34:46Z (GMT). No. of bitstreams: 2 SHAH-THESIS-2021.pdf: 4522623 bytes, checksum: 0a8a11813c6d3039de4f9e68404977fc (MD5) LICENSE.txt: 4209 bytes, checksum: c0763174625e303601805b01f27558c5 (MD5) Previous issue date: 2021-04-26","Embargo set by: Seth Robbins for item 118578 Lift date: 2023-09-17T02:34:57Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/110735"],"dc:language":["en"],"dc:rights":["Copyright 2021 Devansh Shah"],"dc:subject":["Machine Learning","Adversarial Learning","Federated Learning","Computer Vision"],"dc:title":["Adversarial methods in machine learning - a federated defense and an attack"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:52Z"}