Abstract
dc:description.abstractOver the past decade, Machine Learning (ML) technologies have undergone revolutionary advancements, extending beyond traditional domains such as computer vision (CV) and natural language processing (NLP). One of the most significant breakthroughs is the development of transformer models, which leverage the attention mechanism to achieve state-of-the-art performance across various tasks. Transformers serve as the foundation for commercial large language models (LLMs), such as GPT and Claude, driving progress in natural language understanding and generation. Beyond natural language, transformer architectures have been successfully adapted to source code analysis by pretraining and fine-tuning models on large corpora of programming languages. In parallel, the emergence of Vision Transformers (ViTs) has demonstrated exceptional performance in CV applications, further challenging the dominance of convolutional neural networks (CNNs). Another transformative advancement is Federated Learning (FL), a decentralized learning paradigm that preserves data privacy while enabling collaborative model training across distributed clients. Given its advantages in privacy-sensitive domains, FL provides a compelling foundation for cybersecurity applications, particularly for enhancing Intrusion Detection Systems (IDSs) in IoT networks. Its decentralized nature makes it well-suited for Internet of Things (IoT) ecosystems, where data is generated across diverse devices, offering an effective solution for both privacy protection and robust threat detection. However, integrating ML models into real-world applications exposes them to adversarial threats. These include poisoning attacks in the training phase and evasion attacks during inference, both of which compromise model reliability and accuracy. To enhance the robustness of ML models, this dissertation presents a series of studies that (1) strengthen the resilience of ViTs against evasion attacks, (2) investigate the vulnerabilities of FL to advanced poisoning attacks, (3) develop FL-based IDSs for IoT networks that effectively address performance degradation caused by data heterogeneity, and (4) analyze the robustness of transformer models pretrained on programming languages against code-based evasion attacks and propose effective strategies to strengthen their defenses. Collectively, these contributions aim to improve the security, adaptability, and effectiveness of ML models in real-world deployments.
Degree
thesis:*- Name thesis:degree_name
- Doctor of Philosophy
- Level thesis:degree_level
- doctoral
- Discipline thesis:degree_discipline
- Computer Engineering
- Department dc:contributor.department
- Electrical and Computer Engineering
- Grantor dc:publisher
- Virginia Tech
- Year dc:date.issued
- 2026
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Sun, Shihua
- Chairs dc:contributor.committeechair
-
- Wang, Haining
- Stavrou, Angelos
- Committee members dc:contributor.committeemember
-
- Dhillon, Harpreet Singh
- Jia, Ruoxi
- Lou, Wenjing
Subjects
dc:subject × 3Rights
dc:rights- Statement dc:rights
-
- In Copyright
- Licence dc:rights.uri
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- Dc Identifier Other
- vt_gsexam:45404
- OAI identifier oai:identifier
- oai:vtechworks.lib.vt.edu:10919/140662