University of Illinois at Urbana-Champaign
Enhancing the robustness of machine learning models
Abstract
dc:descriptionMachine learning models have recently shown surprisingly good performance in real-world tasks. Therefore, there are growing concerns about whether machine learning models can be robust against different potential threats. In this thesis, we will explore the robustness of machine learning models against adversarial threats in three scenarios that have received relatively less attention from the community. Firstly, we will investigate backdoor attacks, which involve perturbing both the training and evaluation stages. As a countermeasure to such a stealthy and dangerous attack, we present a countermeasure by achieving a binary classification task on neural networks to mitigate this type of threat. Secondly, we will examine the robustness of graph data. We demonstrate the potential threat for discrete edge space manipulation to deceive graph neural networks and make desired actions with stealthy perturbations. We also offer a countermeasure to detect the maliciously injected edges on graph data with an ensemble of multiple models. Finally, we will discuss how model architecture design can provide a robustness guarantee. We present two Lipschitz-constrained models, one for convolution networks and another for Transformer networks. We show that such Lipschitz-constrained models can achieve good certified model robustness. Our work enhances machine learning robustness against various adversarial threats with effective countermeasures.
Degree
thesis:*- Name thesis:degree_name
- Ph.D.
- Level thesis:degree_level
- Dissertation
- Discipline thesis:degree_discipline
- Computer Science
- Grantor
- University of Illinois at Urbana-Champaign
- Year dc:date
- 2023
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Xu, Xiaojun
- Contributors dc:contributor
-
- Gunter, Carl A.
- Li, Bo
- Borisov, Nikita
- Zhang, Ce
Subjects
dc:subject × 1Rights
dc:rights- Statement dc:rights
-
- Copyright 2023 Xiaojun Xu
- Language dc:language
- en, eng
Identifiers
dc:identifier.*- Handle dc:identifier
- https://hdl.handle.net/2142/121313