{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/129712"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/129712","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Domain transferability, model robustness and data privacy in modern machine learning systems","abstract":"Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-05-01","abstract_html":"Submission published under a 24 month embargo labeled &#x27;Closed Access&#x27;, the embargo will last until 2027-05-01","abstract_has_math":false,"creators":["Ma, Evelyn"],"institution":"University of Illinois Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Industrial Engineering","degree_department":null,"school":null,"contributors":["Milenkovic, Olgica","Etesami, Rasoul","Li, Yingying","Wang, Qiong","Dong, Roy"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-04-27","date_published":"2025-04-27","updated_at":"2026-07-22T22:25:05Z","subjects":["Model Robustness","Domain Transferability"],"languages":["en","eng"],"rights":["Copyright © Evelyn Ma, 2025 All rights reserved."],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/129712","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Milenkovic, Olgica","Etesami, Rasoul","Li, Yingying","Wang, Qiong","Dong, Roy"]},{"key":"dc:creator","label":"Author","values":["Ma, Evelyn"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-04-27","2025-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Industrial Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Model Robustness","Domain Transferability"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright © Evelyn Ma, 2025 All rights reserved."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/129712"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-05-01","The student, Evelyn Ma, accepted the attached license on 2025-04-22 at 22:18.","The student, Evelyn Ma, submitted this Dissertation for approval on 2025-04-22 at 22:24.","This Dissertation was approved for publication on 2025-04-27 at 14:18.","DSpace SAF Submission Ingestion Package generated from Vireo submission #21907 on 2025-10-19 at 19:53:46","Developing secure, adaptable, and trustworthy machine learning (ML) systems necessitates a deep understanding of the interactions between Domain Transferability, Model Robustness, and Data Privacy. Despite the individual importance of these factors, their interrelationships remain underexplored, and empirical studies often reveal conflicting trade-offs. For example, techniques that enhance Data Privacy frequently compromise Model Robustness and Domain Transferability. To address these challenges, we systematically investigate these interconnections through three studies, offering both theoretical insights and practical solutions. Our first study challenges the prevailing assumption that Model Robustness inherently enhances Domain Transferability. Our theoretical framework demonstrates that regularization on the model feature extractor, rather than model robustness, is a more fundamental sufficient condition for relative domain transferability. Empirically, we provide counterexamples showing that robustness and generalization can be negatively correlated across different datasets, challenging the prior intuition that more robust models always generalize better. In our second study, we improve Domain Transferability while preserving Data Privacy by proposing FedGTST, a novel transferable federated learning (FL) algorithm. Our theoretical analysis establishes that increasing the averaged Jacobian norm across clients while reducing Jacobian variance provides tight control over the target loss, thereby improving transferability in federated learning. Empirically, FedGTST achieves superior performance over existing baselines, such as FedSR, on public benchmarks, demonstrating its efficacy in enhancing global knowledge transfer. Our third study highlights the often-overlooked risks to Model Robustness in privacy-preserving frameworks by developing data poisoning techniques tailored for FL in reinforcement learning tasks. Our study reveals that Federated Reinforcement Learning (FRL) is highly susceptible to poisoning attacks, inheriting security risks from both FL and RL. We introduce a general poisoning framework that formulates FRL poisoning as an optimization problem and propose a poisoning protocol tailored for policy-based FRL. Empirically, our approach consistently degrades FRL performance across diverse OpenAI Gym environments, outperforming baseline poisoning methods and highlighting critical security challenges in FRL training. Finally, our last work maintains the degraded Model Robustness and Domain Transferability in privacy-preserving frameworks for Large Language Models (LLMs). Specifically, we design GUARD, an LLM unlearning mechanism driven by data attribution to mitigate the robustness degradation associated with unlearning data points that have a high influence on performance over the retained dataset. Our experiments demonstrate that GUARD effectively mitigates unintended forgetting across various LLM unlearning baselines and architectures, highlighting its ability to selectively unlearn requested samples without significantly compromising essential knowledge. Collectively, our research advances the theoretical understanding and practical implementation of robust, transferable, and privacy-preserving ML systems, with applications in federated learning, reinforcement learning, computer vision, and large language models."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Domain transferability, model robustness and data privacy in modern machine learning systems"]}]}],"canonical_facts":{"dc:contributor":["Milenkovic, Olgica","Etesami, Rasoul","Li, Yingying","Wang, Qiong","Dong, Roy"],"dc:creator":["Ma, Evelyn"],"dc:date":["2025-04-27","2025-05"],"dc:description":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-05-01","The student, Evelyn Ma, accepted the attached license on 2025-04-22 at 22:18.","The student, Evelyn Ma, submitted this Dissertation for approval on 2025-04-22 at 22:24.","This Dissertation was approved for publication on 2025-04-27 at 14:18.","DSpace SAF Submission Ingestion Package generated from Vireo submission #21907 on 2025-10-19 at 19:53:46","Developing secure, adaptable, and trustworthy machine learning (ML) systems necessitates a deep understanding of the interactions between Domain Transferability, Model Robustness, and Data Privacy. Despite the individual importance of these factors, their interrelationships remain underexplored, and empirical studies often reveal conflicting trade-offs. For example, techniques that enhance Data Privacy frequently compromise Model Robustness and Domain Transferability. To address these challenges, we systematically investigate these interconnections through three studies, offering both theoretical insights and practical solutions. Our first study challenges the prevailing assumption that Model Robustness inherently enhances Domain Transferability. Our theoretical framework demonstrates that regularization on the model feature extractor, rather than model robustness, is a more fundamental sufficient condition for relative domain transferability. Empirically, we provide counterexamples showing that robustness and generalization can be negatively correlated across different datasets, challenging the prior intuition that more robust models always generalize better. In our second study, we improve Domain Transferability while preserving Data Privacy by proposing FedGTST, a novel transferable federated learning (FL) algorithm. Our theoretical analysis establishes that increasing the averaged Jacobian norm across clients while reducing Jacobian variance provides tight control over the target loss, thereby improving transferability in federated learning. Empirically, FedGTST achieves superior performance over existing baselines, such as FedSR, on public benchmarks, demonstrating its efficacy in enhancing global knowledge transfer. Our third study highlights the often-overlooked risks to Model Robustness in privacy-preserving frameworks by developing data poisoning techniques tailored for FL in reinforcement learning tasks. Our study reveals that Federated Reinforcement Learning (FRL) is highly susceptible to poisoning attacks, inheriting security risks from both FL and RL. We introduce a general poisoning framework that formulates FRL poisoning as an optimization problem and propose a poisoning protocol tailored for policy-based FRL. Empirically, our approach consistently degrades FRL performance across diverse OpenAI Gym environments, outperforming baseline poisoning methods and highlighting critical security challenges in FRL training. Finally, our last work maintains the degraded Model Robustness and Domain Transferability in privacy-preserving frameworks for Large Language Models (LLMs). Specifically, we design GUARD, an LLM unlearning mechanism driven by data attribution to mitigate the robustness degradation associated with unlearning data points that have a high influence on performance over the retained dataset. Our experiments demonstrate that GUARD effectively mitigates unintended forgetting across various LLM unlearning baselines and architectures, highlighting its ability to selectively unlearn requested samples without significantly compromising essential knowledge. Collectively, our research advances the theoretical understanding and practical implementation of robust, transferable, and privacy-preserving ML systems, with applications in federated learning, reinforcement learning, computer vision, and large language models."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/129712"],"dc:language":["en","eng"],"dc:rights":["Copyright © Evelyn Ma, 2025 All rights reserved."],"dc:subject":["Model Robustness","Domain Transferability"],"dc:title":["Domain transferability, model robustness and data privacy in modern machine learning systems"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Industrial Engineering"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:05Z"}