Back to results

Virginia Tech

Towards Secure and Resilient Machine Learning Systems

Abstract

dc:description.abstract

Over the past decade, Machine Learning (ML) technologies have undergone revolutionary advancements, extending beyond traditional domains such as computer vision (CV) and natural language processing (NLP). One of the most significant breakthroughs is the development of transformer models, which leverage the attention mechanism to achieve state-of-the-art performance across various tasks. Transformers serve as the foundation for commercial large language models (LLMs), such as GPT and Claude, driving progress in natural language understanding and generation. Beyond natural language, transformer architectures have been successfully adapted to source code analysis by pretraining and fine-tuning models on large corpora of programming languages. In parallel, the emergence of Vision Transformers (ViTs) has demonstrated exceptional performance in CV applications, further challenging the dominance of convolutional neural networks (CNNs). Another transformative advancement is Federated Learning (FL), a decentralized learning paradigm that preserves data privacy while enabling collaborative model training across distributed clients. Given its advantages in privacy-sensitive domains, FL provides a compelling foundation for cybersecurity applications, particularly for enhancing Intrusion Detection Systems (IDSs) in IoT networks. Its decentralized nature makes it well-suited for Internet of Things (IoT) ecosystems, where data is generated across diverse devices, offering an effective solution for both privacy protection and robust threat detection. However, integrating ML models into real-world applications exposes them to adversarial threats. These include poisoning attacks in the training phase and evasion attacks during inference, both of which compromise model reliability and accuracy. To enhance the robustness of ML models, this dissertation presents a series of studies that (1) strengthen the resilience of ViTs against evasion attacks, (2) investigate the vulnerabilities of FL to advanced poisoning attacks, (3) develop FL-based IDSs for IoT networks that effectively address performance degradation caused by data heterogeneity, and (4) analyze the robustness of transformer models pretrained on programming languages against code-based evasion attacks and propose effective strategies to strengthen their defenses. Collectively, these contributions aim to improve the security, adaptability, and effectiveness of ML models in real-world deployments.

Degree

thesis:*
Name thesis:degree_name
Doctor of Philosophy
Level thesis:degree_level
doctoral
Discipline thesis:degree_discipline
Computer Engineering
Department dc:contributor.department
Electrical and Computer Engineering
Grantor dc:publisher
Virginia Tech
Year dc:date.issued
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Sun, Shihua
Chairs dc:contributor.committeechair
  • Wang, Haining
  • Stavrou, Angelos
Committee members dc:contributor.committeemember
  • Dhillon, Harpreet Singh
  • Jia, Ruoxi
  • Lou, Wenjing

Subjects

dc:subject × 3

Rights

dc:rights
Statement dc:rights
  • In Copyright
Language dc:language.iso
en

Identifiers

dc:identifier.*
Dc Identifier Other
vt_gsexam:45404
OAI identifier oai:identifier
oai:vtechworks.lib.vt.edu:10919/140662

Chain of custody

source
Harvested from
Virginia Tech
Base URL
vtechworks.lib.vt.edu/oai/request
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Sun, Shihua. Towards Secure and Resilient Machine Learning Systems. doctoral thesis, Virginia Tech, 2026. https://hdl.handle.net/10919/140662