Back to results

University of Tennessee at Chattanooga

An evaluation of the robustness of the natural-adversarial mutual information-based defense and malware classification against adversarial attacks for deep learning

Abstract

dc:description.abstract

In today’s technology driven world, the use of Machine Learning (ML) systems is becoming ubiquitous, albeit often in the background, in many areas of daily life. ML systems are being used to detect malware, control autonomous vehicles, classify images, assist with medical diagnosis, and block internet ads with high precision. Although the use of these ML systems has become widespread in our society, there is the potential for systems used in high-stakes situations to make faulty predictions that can have serious consequences. Recently researchers have shown that even deep neural networks (DNNs) can be “fooled” into misclassifying an input sample that has been minimally modified in a specific way. These modified samples are known as adversarial examples and have been crafted with the goal of causing the target DNN to modify its behavior. It has been shown that adversarial examples can be crafted even when the attacker does not have access to the training parameters and model architecture of the victim DNN. An attack made under this threat model is known as a black-box attack and is made possible due to the transferability of adversarial examples from one model to another. In this dissertation we first present an overview of DNNs and capsule networks, the current known adversarial example crafting methods, defenses against adversarial examples, and possible explanations for the existence of adversarial examples. Next, we explore a novel technique that was recently developed that aims to use mutual information (MI) as an additional feature for the adversarial training of classification models called natural-adversarial mutual information-based defense (NAMID). We will describe our extensive evaluation of NAMID, as well as introduce our novel method for crafting adversarial examples termed MI-Craft. We will also apply NAMID to the domain of malware classification. We will compare MI-Craft to standard projected gradient descent for the creation of adversarial examples, as well as demonstrate the effectiveness of MI-Craft and NAMID under the CIFAR10 and MalImg datasets.

Degree

thesis:*
Grantor dc:publisher
University of Tennessee at Chattanooga

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Schwab, David
Contributors dc:contributor
  • Yang, Li
  • Kizza, Joseph; Xie, Mengjun; Ward, Michael
  • College of Engineering and Computer Science

Subjects

dc:subject × 2

Rights

dc:rights
Language dc:language
English, eng

Identifiers

dc:identifier.*
Repository record dc:identifier
https://scholar.utc.edu/theses/788
OAI identifier oai:identifier
oai:scholar.utc.edu:theses-1962

Chain of custody

source
Harvested from
University of Tennessee - Chattanooga
Base URL
scholar.utc.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Schwab, David. An evaluation of the robustness of the natural-adversarial mutual information-based defense and malware classification against adversarial attacks for deep learning. University of Tennessee at Chattanooga, https://scholar.utc.edu/theses/788