{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/121953"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/121953","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Certifiably trustworthy deep learning systems at scale","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2024-03-01 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2024-03-01 without embargo terms","abstract_has_math":false,"creators":["Li, Linyi"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Li, Bo","Xie, Tao","Gunter, Carl A.","Kolter, J. Zico"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-12","date_published":"2023-12","updated_at":"2026-07-22T22:25:00Z","subjects":["Deep Learning","Certification","Verification","Trustworthy Machine Learning","Machine Learning Security"],"languages":["en","eng"],"rights":["Copyright 2023 Linyi Li"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/121953","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Li, Bo","Xie, Tao","Gunter, Carl A.","Kolter, J. Zico"]},{"key":"dc:creator","label":"Author","values":["Li, Linyi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2023-12","2023-10-10"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Deep Learning","Certification","Verification","Trustworthy Machine Learning","Machine Learning Security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2023 Linyi Li"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/121953"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2024-03-01 without embargo terms","The student, Linyi Li, accepted the attached license on 2023-10-06 at 02:58.","The student, Linyi Li, submitted this Dissertation for approval on 2023-10-06 at 03:18.","This Dissertation was approved for publication on 2023-10-10 at 16:17.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19844 on 2024-03-01 at 13:13:43","Great advances in deep learning (DL) have led to state-of-the-art performance on a wide range of challenging tasks. However, along with the rapid deployment of DL systems, several trustworthy threats arise, such as weak robustness against stealthy noise perturbations and natural transformations, bias across different subgroups, and lack of numerical reliability. These trustworthy threats have raised great concerns, especially when deploying DL systems in safety-critical scenarios such as autonomous driving and facial recognition for safeguarding. To defend against these common trustworthy threats, this thesis systematically proposes or enhances certification approaches and certified training approaches for DL systems, especially for large-scale DL systems. A certification approach can guarantee some properties of the DL system under some trustworthiness properties. For instance, the robustness certification approach can guarantee the worst-case test accuracy when the attacker imposes any input perturbations or transformations within some bounded range. A certified training approach can improve the DL system’s guaranteed trustworthiness under a certain property by training the DL model, e.g., improving the guaranteed test accuracy above. This thesis begins with a systematic taxonomy of certification and certified training approaches. Then for several critical trustworthiness properties, this thesis proposes the corresponding certification and certified training approaches that lead to state-of-the-art tightness and scalability. These approaches are motivated by a few core principles, including dual problem analysis for randomized smoothing, general cutting planes for bound propagation, stratified sampling, subpopulation decomposition, and abstract interpretation. The effectiveness of the proposed approaches is supported by both theoretical analyses and empirical evaluations. The thesis is concluded with a discussion of limitations, challenges, and future directions towards achieving fully certifiable, reliable, and scalable machine learning. In summary, this thesis enables certification of various trustworthy properties for DL systems up to millions of parameters, representing a major step in certified deep learning, an important research topic in machine learning, computer security, and software engineering."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Certifiably trustworthy deep learning systems at scale"]}]}],"canonical_facts":{"dc:contributor":["Li, Bo","Xie, Tao","Gunter, Carl A.","Kolter, J. Zico"],"dc:creator":["Li, Linyi"],"dc:date":["2023-12","2023-10-10"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2024-03-01 without embargo terms","The student, Linyi Li, accepted the attached license on 2023-10-06 at 02:58.","The student, Linyi Li, submitted this Dissertation for approval on 2023-10-06 at 03:18.","This Dissertation was approved for publication on 2023-10-10 at 16:17.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19844 on 2024-03-01 at 13:13:43","Great advances in deep learning (DL) have led to state-of-the-art performance on a wide range of challenging tasks. However, along with the rapid deployment of DL systems, several trustworthy threats arise, such as weak robustness against stealthy noise perturbations and natural transformations, bias across different subgroups, and lack of numerical reliability. These trustworthy threats have raised great concerns, especially when deploying DL systems in safety-critical scenarios such as autonomous driving and facial recognition for safeguarding. To defend against these common trustworthy threats, this thesis systematically proposes or enhances certification approaches and certified training approaches for DL systems, especially for large-scale DL systems. A certification approach can guarantee some properties of the DL system under some trustworthiness properties. For instance, the robustness certification approach can guarantee the worst-case test accuracy when the attacker imposes any input perturbations or transformations within some bounded range. A certified training approach can improve the DL system’s guaranteed trustworthiness under a certain property by training the DL model, e.g., improving the guaranteed test accuracy above. This thesis begins with a systematic taxonomy of certification and certified training approaches. Then for several critical trustworthiness properties, this thesis proposes the corresponding certification and certified training approaches that lead to state-of-the-art tightness and scalability. These approaches are motivated by a few core principles, including dual problem analysis for randomized smoothing, general cutting planes for bound propagation, stratified sampling, subpopulation decomposition, and abstract interpretation. The effectiveness of the proposed approaches is supported by both theoretical analyses and empirical evaluations. The thesis is concluded with a discussion of limitations, challenges, and future directions towards achieving fully certifiable, reliable, and scalable machine learning. In summary, this thesis enables certification of various trustworthy properties for DL systems up to millions of parameters, representing a major step in certified deep learning, an important research topic in machine learning, computer security, and software engineering."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/121953"],"dc:language":["en","eng"],"dc:rights":["Copyright 2023 Linyi Li"],"dc:subject":["Deep Learning","Certification","Verification","Trustworthy Machine Learning","Machine Learning Security"],"dc:title":["Certifiably trustworthy deep learning systems at scale"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:00Z"}