University of Illinois at Urbana-Champaign
Trustworthy machine learning throughout model’s life cycle
Abstract
dc:descriptionMachine learning techniques have been used across a wide variety of applications, including security-sensitive domains. Despite their superior performance, they are vulnerable throughout the life cycle including stages of data collection, training, deployment, and inference. During my Ph.D. studies, I have been working on exploring the trustworthiness of machine learning models, including both attack and defense techniques. The backdoor attack poses potential security risks for machine learning models. In Chapter 3, feature sensitivity analysis with smoothing techniques can identify instances with backdoor triggers from a dataset. On the other hand, in Chapter 4, defenders can adapt the idea of backdoor triggers to create “watermarks” in trained models and leverage this property to protect the intellectual property against model extraction attacks. In Chapter 5, I study the robustness of Visual Question Answering (VQA) systems. With white-box access, it is easy for attackers to craft adversarial examples on all the VQA system variants inspected. I further improve the VQA robustness from the perspectives of causality, consistency regularization, and adversarial training. Chapter 6 and Chapter 7 show that keeping a model black box does not guarantee its safety. By querying the model and getting the hard predictions (e.g., class labels instead of logits), an adversary is able to efficiently craft high-quality adversarial examples against an image classifier.
Degree
thesis:*- Name thesis:degree_name
- Ph.D.
- Level thesis:degree_level
- Dissertation
- Discipline thesis:degree_discipline
- Computer Science
- Grantor
- University of Illinois at Urbana-Champaign
- Year dc:date
- 2023
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Li, Huichen
- Contributors dc:contributor
-
- Li, Bo
- Gunter, Carl A.
- Tong, Hanghang
- Urtasun, Raquel
Subjects
dc:subject × 8Rights
dc:rights- Statement dc:rights
-
- Copyright 2023 Huichen Li
- Language dc:language
- en, eng
Identifiers
dc:identifier.*- Handle dc:identifier
- https://hdl.handle.net/2142/120254