{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/129762"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/129762","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Using adversarial noise for privacy protection: an evaluation of hybrid attacks across application targets","abstract":"Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-05-01","abstract_html":"Submission published under a 24 month embargo labeled &#x27;Closed Access&#x27;, the embargo will last until 2027-05-01","abstract_has_math":false,"creators":["Ghosh, Anusha"],"institution":"University of Illinois Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Wang, Gang"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-05-05","date_published":"2025-05-05","updated_at":"2026-07-22T22:25:05Z","subjects":["adversarial attacks","artificial intelligence","security","privacy"],"languages":["en","eng"],"rights":["Copyright 2025 Anusha Ghosh"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/129762","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Wang, Gang"]},{"key":"dc:creator","label":"Author","values":["Ghosh, Anusha"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-05-05","2025-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["adversarial attacks","artificial intelligence","security","privacy"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2025 Anusha Ghosh"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/129762"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-05-01","The student, Anusha Ghosh, accepted the attached license on 2025-04-30 at 13:43.","The student, Anusha Ghosh, submitted this Thesis for approval on 2025-05-05 at 00:38.","This Thesis was approved for publication on 2025-05-05 at 12:41.","DSpace SAF Submission Ingestion Package generated from Vireo submission #22121 on 2025-10-19 at 19:55:18","The advent of modern artificial intelligence has given birth to new security concerns surrounding data uploaded to the Internet. Images uploaded to public sites like social media can be used for malicious purposes, and a user has no recourse to prevent this from happening after an image has been uploaded. However, previous work on adversarial attacks to protect user privacy have focused on one specific attack scenario. This means that a user is vulnerable to every application besides the one that they have protected themselves against. This work explores possibility of hybrid attacks - attacks designed to work on more than one model task in order to protect users from a variety of different concerns. We focus specifically on facial recognition and AI powered image editing model tasks. We first test different attacks in order to find ones that work well on our chosen models. We then test the cross application of these attacks, and confirm that a attack meant for facial recognition models will not significantly and repeatably impact the performance of image editing models, and vice versa. Finally, we test the performance of layered attacks, where the noise produced from attacks on different models are combined and applied to one image. We find that these hybrid attacks significantly outperform single model attacks in terms of performance on both models and present a viable method of protecting images from more than one model task."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Using adversarial noise for privacy protection: an evaluation of hybrid attacks across application targets"]}]}],"canonical_facts":{"dc:contributor":["Wang, Gang"],"dc:creator":["Ghosh, Anusha"],"dc:date":["2025-05-05","2025-05"],"dc:description":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-05-01","The student, Anusha Ghosh, accepted the attached license on 2025-04-30 at 13:43.","The student, Anusha Ghosh, submitted this Thesis for approval on 2025-05-05 at 00:38.","This Thesis was approved for publication on 2025-05-05 at 12:41.","DSpace SAF Submission Ingestion Package generated from Vireo submission #22121 on 2025-10-19 at 19:55:18","The advent of modern artificial intelligence has given birth to new security concerns surrounding data uploaded to the Internet. Images uploaded to public sites like social media can be used for malicious purposes, and a user has no recourse to prevent this from happening after an image has been uploaded. However, previous work on adversarial attacks to protect user privacy have focused on one specific attack scenario. This means that a user is vulnerable to every application besides the one that they have protected themselves against. This work explores possibility of hybrid attacks - attacks designed to work on more than one model task in order to protect users from a variety of different concerns. We focus specifically on facial recognition and AI powered image editing model tasks. We first test different attacks in order to find ones that work well on our chosen models. We then test the cross application of these attacks, and confirm that a attack meant for facial recognition models will not significantly and repeatably impact the performance of image editing models, and vice versa. Finally, we test the performance of layered attacks, where the noise produced from attacks on different models are combined and applied to one image. We find that these hybrid attacks significantly outperform single model attacks in terms of performance on both models and present a viable method of protecting images from more than one model task."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/129762"],"dc:language":["en","eng"],"dc:rights":["Copyright 2025 Anusha Ghosh"],"dc:subject":["adversarial attacks","artificial intelligence","security","privacy"],"dc:title":["Using adversarial noise for privacy protection: an evaluation of hybrid attacks across application targets"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:05Z"}