{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/120254"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/120254","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Trustworthy machine learning throughout model’s life cycle","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-09-01 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2023-09-01 without embargo terms","abstract_has_math":false,"creators":["Li, Huichen"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Li, Bo","Gunter, Carl A.","Tong, Hanghang","Urtasun, Raquel"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-05","date_published":"2023-05","updated_at":"2026-07-22T22:24:57Z","subjects":["Machine Learning","Trustworthy","Robustness","Adversarial Attack And Defense","Backdoor Attack Detection","Watermark","Whitebox Attack","Blackbox Attack"],"languages":["en","eng"],"rights":["Copyright 2023 Huichen Li"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/120254","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Li, Bo","Gunter, Carl A.","Tong, Hanghang","Urtasun, Raquel"]},{"key":"dc:creator","label":"Author","values":["Li, Huichen"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2023-05","2023-04-14"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Machine Learning","Trustworthy","Robustness","Adversarial Attack And Defense","Backdoor Attack Detection","Watermark","Whitebox Attack","Blackbox Attack"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2023 Huichen Li"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/120254"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-09-01 without embargo terms","The student, Huichen Li, accepted the attached license on 2023-04-12 at 10:19.","The student, Huichen Li, submitted this Dissertation for approval on 2023-04-12 at 10:55.","This Dissertation was approved for publication on 2023-04-14 at 13:17.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18959 on 2023-09-01 at 17:08:15","Machine learning techniques have been used across a wide variety of applications, including security-sensitive domains. Despite their superior performance, they are vulnerable throughout the life cycle including stages of data collection, training, deployment, and inference. During my Ph.D. studies, I have been working on exploring the trustworthiness of machine learning models, including both attack and defense techniques. The backdoor attack poses potential security risks for machine learning models. In Chapter 3, feature sensitivity analysis with smoothing techniques can identify instances with backdoor triggers from a dataset. On the other hand, in Chapter 4, defenders can adapt the idea of backdoor triggers to create “watermarks” in trained models and leverage this property to protect the intellectual property against model extraction attacks. In Chapter 5, I study the robustness of Visual Question Answering (VQA) systems. With white-box access, it is easy for attackers to craft adversarial examples on all the VQA system variants inspected. I further improve the VQA robustness from the perspectives of causality, consistency regularization, and adversarial training. Chapter 6 and Chapter 7 show that keeping a model black box does not guarantee its safety. By querying the model and getting the hard predictions (e.g., class labels instead of logits), an adversary is able to efficiently craft high-quality adversarial examples against an image classifier."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Trustworthy machine learning throughout model’s life cycle"]}]}],"canonical_facts":{"dc:contributor":["Li, Bo","Gunter, Carl A.","Tong, Hanghang","Urtasun, Raquel"],"dc:creator":["Li, Huichen"],"dc:date":["2023-05","2023-04-14"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-09-01 without embargo terms","The student, Huichen Li, accepted the attached license on 2023-04-12 at 10:19.","The student, Huichen Li, submitted this Dissertation for approval on 2023-04-12 at 10:55.","This Dissertation was approved for publication on 2023-04-14 at 13:17.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18959 on 2023-09-01 at 17:08:15","Machine learning techniques have been used across a wide variety of applications, including security-sensitive domains. Despite their superior performance, they are vulnerable throughout the life cycle including stages of data collection, training, deployment, and inference. During my Ph.D. studies, I have been working on exploring the trustworthiness of machine learning models, including both attack and defense techniques. The backdoor attack poses potential security risks for machine learning models. In Chapter 3, feature sensitivity analysis with smoothing techniques can identify instances with backdoor triggers from a dataset. On the other hand, in Chapter 4, defenders can adapt the idea of backdoor triggers to create “watermarks” in trained models and leverage this property to protect the intellectual property against model extraction attacks. In Chapter 5, I study the robustness of Visual Question Answering (VQA) systems. With white-box access, it is easy for attackers to craft adversarial examples on all the VQA system variants inspected. I further improve the VQA robustness from the perspectives of causality, consistency regularization, and adversarial training. Chapter 6 and Chapter 7 show that keeping a model black box does not guarantee its safety. By querying the model and getting the hard predictions (e.g., class labels instead of logits), an adversary is able to efficiently craft high-quality adversarial examples against an image classifier."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/120254"],"dc:language":["en","eng"],"dc:rights":["Copyright 2023 Huichen Li"],"dc:subject":["Machine Learning","Trustworthy","Robustness","Adversarial Attack And Defense","Backdoor Attack Detection","Watermark","Whitebox Attack","Blackbox Attack"],"dc:title":["Trustworthy machine learning throughout model’s life cycle"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:57Z"}