{"id":{"repo_id":"vt","oai_identifier":"oai:vtechworks.lib.vt.edu:10919/140662"},"canonical_url":"https://search.dev.ndltd.org/etd/vt/oai:vtechworks.lib.vt.edu:10919/140662","repository":{"repo_id":"vt","name":"Virginia Tech","base_url":"https://vtechworks.lib.vt.edu/oai/request"},"display":{"title":"Towards Secure and Resilient Machine Learning Systems","abstract":"Over the past decade, Machine Learning (ML) technologies have undergone revolutionary advancements, extending beyond traditional domains such as computer vision (CV) and natural language processing (NLP). One of the most significant breakthroughs is the development of transformer models, which leverage the attention mechanism to achieve state-of-the-art performance across various tasks. Transformers serve as the foundation for commercial large language models (LLMs), such as GPT and Claude, driving progress in natural language understanding and generation. Beyond natural language, transformer architectures have been successfully adapted to source code analysis by pretraining and fine-tuning models on large corpora of programming languages. In parallel, the emergence of Vision Transformers (ViTs) has demonstrated exceptional performance in CV applications, further challenging the dominance of convolutional neural networks (CNNs). Another transformative advancement is Federated Learning (FL), a decentralized learning paradigm that preserves data privacy while enabling collaborative model training across distributed clients. Given its advantages in privacy-sensitive domains, FL provides a compelling foundation for cybersecurity applications, particularly for enhancing Intrusion Detection Systems (IDSs) in IoT networks. Its decentralized nature makes it well-suited for Internet of Things (IoT) ecosystems, where data is generated across diverse devices, offering an effective solution for both privacy protection and robust threat detection. However, integrating ML models into real-world applications exposes them to adversarial threats. These include poisoning attacks in the training phase and evasion attacks during inference, both of which compromise model reliability and accuracy. To enhance the robustness of ML models, this dissertation presents a series of studies that (1) strengthen the resilience of ViTs against evasion attacks, (2) investigate the vulnerabilities of FL to advanced poisoning attacks, (3) develop FL-based IDSs for IoT networks that effectively address performance degradation caused by data heterogeneity, and (4) analyze the robustness of transformer models pretrained on programming languages against code-based evasion attacks and propose effective strategies to strengthen their defenses. Collectively, these contributions aim to improve the security, adaptability, and effectiveness of ML models in real-world deployments.","abstract_html":"Over the past decade, Machine Learning (ML) technologies have undergone revolutionary advancements, extending beyond traditional domains such as computer vision (CV) and natural language processing (NLP). One of the most significant breakthroughs is the development of transformer models, which leverage the attention mechanism to achieve state-of-the-art performance across various tasks. Transformers serve as the foundation for commercial large language models (LLMs), such as GPT and Claude, driving progress in natural language understanding and generation. Beyond natural language, transformer architectures have been successfully adapted to source code analysis by pretraining and fine-tuning models on large corpora of programming languages. In parallel, the emergence of Vision Transformers (ViTs) has demonstrated exceptional performance in CV applications, further challenging the dominance of convolutional neural networks (CNNs). Another transformative advancement is Federated Learning (FL), a decentralized learning paradigm that preserves data privacy while enabling collaborative model training across distributed clients. Given its advantages in privacy-sensitive domains, FL provides a compelling foundation for cybersecurity applications, particularly for enhancing Intrusion Detection Systems (IDSs) in IoT networks. Its decentralized nature makes it well-suited for Internet of Things (IoT) ecosystems, where data is generated across diverse devices, offering an effective solution for both privacy protection and robust threat detection. However, integrating ML models into real-world applications exposes them to adversarial threats. These include poisoning attacks in the training phase and evasion attacks during inference, both of which compromise model reliability and accuracy. To enhance the robustness of ML models, this dissertation presents a series of studies that (1) strengthen the resilience of ViTs against evasion attacks, (2) investigate the vulnerabilities of FL to advanced poisoning attacks, (3) develop FL-based IDSs for IoT networks that effectively address performance degradation caused by data heterogeneity, and (4) analyze the robustness of transformer models pretrained on programming languages against code-based evasion attacks and propose effective strategies to strengthen their defenses. Collectively, these contributions aim to improve the security, adaptability, and effectiveness of ML models in real-world deployments.","abstract_has_math":false,"creators":["Sun, Shihua"],"institution":"Virginia Tech","degree_name":"Doctor of Philosophy","degree_level":"doctoral","degree_discipline":"Computer Engineering","degree_department":"Electrical and Computer Engineering","school":null,"contributors":[],"advisors":[],"committee_chairs":["Wang, Haining","Stavrou, Angelos"],"committee_members":["Dhillon, Harpreet Singh","Jia, Ruoxi","Lou, Wenjing"],"year":2026,"date_issued":"2026-01-07","date_published":"2026-01-07","updated_at":"2026-07-22T22:19:07Z","subjects":["Machine Learning","Security","Internet of Things"],"languages":["en"],"rights":["In Copyright"],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:45404"],"render_values":[{"text":"vt_gsexam:45404","href":null,"code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/10919/140662","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.committeechair","label":"Committee Chair","values":["Wang, Haining","Stavrou, Angelos"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Dhillon, Harpreet Singh","Jia, Ruoxi","Lou, Wenjing"]},{"key":"dc:contributor.department","label":"Department","values":["Electrical and Computer Engineering"]},{"key":"dc:creator","label":"Author","values":["Sun, Shihua"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-01-08T09:00:48Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2026-01-08T09:00:48Z"]},{"key":"dc:date.issued","label":"Date","values":["2026-01-07"]},{"key":"dc:publisher","label":"Institution","values":["Virginia Tech"]},{"key":"dc:type","label":"Dc Type","values":["Dissertation"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Virginia Polytechnic Institute and State University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Machine Learning","Security","Internet of Things"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["In Copyright"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:45404"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10919/140662"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Over the past decade, Machine Learning (ML) technologies have undergone revolutionary advancements, extending beyond traditional domains such as computer vision (CV) and natural language processing (NLP). One of the most significant breakthroughs is the development of transformer models, which leverage the attention mechanism to achieve state-of-the-art performance across various tasks. Transformers serve as the foundation for commercial large language models (LLMs), such as GPT and Claude, driving progress in natural language understanding and generation. Beyond natural language, transformer architectures have been successfully adapted to source code analysis by pretraining and fine-tuning models on large corpora of programming languages. In parallel, the emergence of Vision Transformers (ViTs) has demonstrated exceptional performance in CV applications, further challenging the dominance of convolutional neural networks (CNNs). Another transformative advancement is Federated Learning (FL), a decentralized learning paradigm that preserves data privacy while enabling collaborative model training across distributed clients. Given its advantages in privacy-sensitive domains, FL provides a compelling foundation for cybersecurity applications, particularly for enhancing Intrusion Detection Systems (IDSs) in IoT networks. Its decentralized nature makes it well-suited for Internet of Things (IoT) ecosystems, where data is generated across diverse devices, offering an effective solution for both privacy protection and robust threat detection. However, integrating ML models into real-world applications exposes them to adversarial threats. These include poisoning attacks in the training phase and evasion attacks during inference, both of which compromise model reliability and accuracy. To enhance the robustness of ML models, this dissertation presents a series of studies that (1) strengthen the resilience of ViTs against evasion attacks, (2) investigate the vulnerabilities of FL to advanced poisoning attacks, (3) develop FL-based IDSs for IoT networks that effectively address performance degradation caused by data heterogeneity, and (4) analyze the robustness of transformer models pretrained on programming languages against code-based evasion attacks and propose effective strategies to strengthen their defenses. Collectively, these contributions aim to improve the security, adaptability, and effectiveness of ML models in real-world deployments."]},{"key":"dc:description.abstractgeneral","label":"General Abstract","values":["In recent years, Artificial Intelligence (AI) and Machine Learning (ML) have made significant advancements, revolutionizing fields such as image recognition and language processing, and transforming many aspects of daily life. Beyond traditional applications, ML has also enabled breakthroughs in high-impact domains and is increasingly being integrated into finance, cybersecurity, and autonomous systems, providing sophisticated solutions to complex challenges. However, despite their transformative potential, ML systems are highly vulnerable to cyber threats, much like traditional computing systems. These vulnerabilities can be exploited in various ways, including attacks that disrupt system functionality or extract sensitive information, leading to severe consequences depending on the specific application. For example, an attack on a healthcare AI system could result in incorrect diagnoses. In this research, we systematically investigate the vulnerabilities of ML systems to adversarial attacks designed to disrupt their normal functionality. Furthermore, we focus on enhancing the robustness of these systems, ensuring their resilience in real-world scenarios characterized by diverse and dynamic environments."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["Doctor of Philosophy"]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["ETD"]},{"key":"dc:title","label":"Title","values":["Towards Secure and Resilient Machine Learning Systems"]}]}],"canonical_facts":{"dc:contributor.committeechair":["Wang, Haining","Stavrou, Angelos"],"dc:contributor.committeemember":["Dhillon, Harpreet Singh","Jia, Ruoxi","Lou, Wenjing"],"dc:contributor.department":["Electrical and Computer Engineering"],"dc:creator":["Sun, Shihua"],"dc:date.accessioned":["2026-01-08T09:00:48Z"],"dc:date.available":["2026-01-08T09:00:48Z"],"dc:date.issued":["2026-01-07"],"dc:description.abstract":["Over the past decade, Machine Learning (ML) technologies have undergone revolutionary advancements, extending beyond traditional domains such as computer vision (CV) and natural language processing (NLP). One of the most significant breakthroughs is the development of transformer models, which leverage the attention mechanism to achieve state-of-the-art performance across various tasks. Transformers serve as the foundation for commercial large language models (LLMs), such as GPT and Claude, driving progress in natural language understanding and generation. Beyond natural language, transformer architectures have been successfully adapted to source code analysis by pretraining and fine-tuning models on large corpora of programming languages. In parallel, the emergence of Vision Transformers (ViTs) has demonstrated exceptional performance in CV applications, further challenging the dominance of convolutional neural networks (CNNs). Another transformative advancement is Federated Learning (FL), a decentralized learning paradigm that preserves data privacy while enabling collaborative model training across distributed clients. Given its advantages in privacy-sensitive domains, FL provides a compelling foundation for cybersecurity applications, particularly for enhancing Intrusion Detection Systems (IDSs) in IoT networks. Its decentralized nature makes it well-suited for Internet of Things (IoT) ecosystems, where data is generated across diverse devices, offering an effective solution for both privacy protection and robust threat detection. However, integrating ML models into real-world applications exposes them to adversarial threats. These include poisoning attacks in the training phase and evasion attacks during inference, both of which compromise model reliability and accuracy. To enhance the robustness of ML models, this dissertation presents a series of studies that (1) strengthen the resilience of ViTs against evasion attacks, (2) investigate the vulnerabilities of FL to advanced poisoning attacks, (3) develop FL-based IDSs for IoT networks that effectively address performance degradation caused by data heterogeneity, and (4) analyze the robustness of transformer models pretrained on programming languages against code-based evasion attacks and propose effective strategies to strengthen their defenses. Collectively, these contributions aim to improve the security, adaptability, and effectiveness of ML models in real-world deployments."],"dc:description.abstractgeneral":["In recent years, Artificial Intelligence (AI) and Machine Learning (ML) have made significant advancements, revolutionizing fields such as image recognition and language processing, and transforming many aspects of daily life. Beyond traditional applications, ML has also enabled breakthroughs in high-impact domains and is increasingly being integrated into finance, cybersecurity, and autonomous systems, providing sophisticated solutions to complex challenges. However, despite their transformative potential, ML systems are highly vulnerable to cyber threats, much like traditional computing systems. These vulnerabilities can be exploited in various ways, including attacks that disrupt system functionality or extract sensitive information, leading to severe consequences depending on the specific application. For example, an attack on a healthcare AI system could result in incorrect diagnoses. In this research, we systematically investigate the vulnerabilities of ML systems to adversarial attacks designed to disrupt their normal functionality. Furthermore, we focus on enhancing the robustness of these systems, ensuring their resilience in real-world scenarios characterized by diverse and dynamic environments."],"dc:description.degree":["Doctor of Philosophy"],"dc:format.medium":["ETD"],"dc:identifier.other":["vt_gsexam:45404"],"dc:identifier.uri":["https://hdl.handle.net/10919/140662"],"dc:language.iso":["en"],"dc:publisher":["Virginia Tech"],"dc:rights":["In Copyright"],"dc:rights.uri":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:subject":["Machine Learning","Security","Internet of Things"],"dc:title":["Towards Secure and Resilient Machine Learning Systems"],"dc:type":["Dissertation"],"thesis:degree_discipline":["Computer Engineering"],"thesis:degree_level":["doctoral"],"thesis:degree_name":["Doctor of Philosophy"],"thesis:institution_name":["Virginia Polytechnic Institute and State University"]},"updated_at":"2026-07-22T22:19:07Z"}