{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/117625"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/117625","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Locally optimal detection and randomization defenses against universal adversarial perturbations","abstract":"Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2024-12-01","abstract_html":"Submission published under a 24 month embargo labeled &#x27;U of I Access&#x27;, the embargo will last until 2024-12-01","abstract_has_math":false,"creators":["Goel, Amish"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Moulin, Pierre","Schwing, Alexander","Li, Bo","Raginsky, Maxim","Veeravalli, Venugopal V."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-12","date_published":"2022-12","updated_at":"2026-07-22T22:24:56Z","subjects":["universal adversarial perturbations","deep learning","hypothesis testing","locally optimal test","generalized likelihood ratio test"],"languages":["en","eng"],"rights":["Copyright 2022 Amish Goel"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/117625","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Moulin, Pierre","Schwing, Alexander","Li, Bo","Raginsky, Maxim","Veeravalli, Venugopal V."]},{"key":"dc:creator","label":"Author","values":["Goel, Amish"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2022-12","2022-08-25"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["universal adversarial perturbations","deep learning","hypothesis testing","locally optimal test","generalized likelihood ratio test"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2022 Amish Goel"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/117625"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2024-12-01","The student, Amish Goel, accepted the attached license on 2022-08-19 at 11:12.","The student, Amish Goel, submitted this Dissertation for approval on 2022-08-19 at 11:26.","This Dissertation was approved for publication on 2022-08-25 at 14:33.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18464 on 2023-04-12 at 08:10:24","This thesis investigates a detection-based approach to safeguard a machine-learning based classifier from adversarial perturbations of its input. In particular, we consider input agnostic universal adversarial perturbations which are selected to force the input to a desired target class. The detector is designed by application of fundamental concepts of statistical decision theory, including locally optimal testing. Since locally optimal detectors depend on the input distribution, which is unknown in real-world datasets, a tractable surrogate input distribution is used instead. The thesis also defines several metrics for joint classification and detection, and evaluates them on several image datasets and popular image classifiers. We demonstrate through the experimental results that our detection-based approach is successful and outperforms the prior state of the art. We also show that detector-aware universal adversarial perturbations can be constructed in a way that evades our detector and achieves high target success rate on the classifier. To mitigate this problem, we propose and evaluate several relevant randomization schemes. Among the proposed methods, we observe that randomized smoothing offers better defense against the stronger detector-aware attacks."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Locally optimal detection and randomization defenses against universal adversarial perturbations"]}]}],"canonical_facts":{"dc:contributor":["Moulin, Pierre","Schwing, Alexander","Li, Bo","Raginsky, Maxim","Veeravalli, Venugopal V."],"dc:creator":["Goel, Amish"],"dc:date":["2022-12","2022-08-25"],"dc:description":["Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2024-12-01","The student, Amish Goel, accepted the attached license on 2022-08-19 at 11:12.","The student, Amish Goel, submitted this Dissertation for approval on 2022-08-19 at 11:26.","This Dissertation was approved for publication on 2022-08-25 at 14:33.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18464 on 2023-04-12 at 08:10:24","This thesis investigates a detection-based approach to safeguard a machine-learning based classifier from adversarial perturbations of its input. In particular, we consider input agnostic universal adversarial perturbations which are selected to force the input to a desired target class. The detector is designed by application of fundamental concepts of statistical decision theory, including locally optimal testing. Since locally optimal detectors depend on the input distribution, which is unknown in real-world datasets, a tractable surrogate input distribution is used instead. The thesis also defines several metrics for joint classification and detection, and evaluates them on several image datasets and popular image classifiers. We demonstrate through the experimental results that our detection-based approach is successful and outperforms the prior state of the art. We also show that detector-aware universal adversarial perturbations can be constructed in a way that evades our detector and achieves high target success rate on the classifier. To mitigate this problem, we propose and evaluate several relevant randomization schemes. Among the proposed methods, we observe that randomized smoothing offers better defense against the stronger detector-aware attacks."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/117625"],"dc:language":["en","eng"],"dc:rights":["Copyright 2022 Amish Goel"],"dc:subject":["universal adversarial perturbations","deep learning","hypothesis testing","locally optimal test","generalized likelihood ratio test"],"dc:title":["Locally optimal detection and randomization defenses against universal adversarial perturbations"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:56Z"}