서브메뉴
검색
Adversarial Resilient and Privacy Preserving Deep Learning
Adversarial Resilient and Privacy Preserving Deep Learning
Detailed Information
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260202105542
- ISBN
- 9798263397852
- DDC
- 006
- 저자명
- Wei, Wenqi.
- 서명/저자
- Adversarial Resilient and Privacy Preserving Deep Learning
- 발행사항
- [Sl] : Georgia Institute of Technology, 2022
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2022
- 형태사항
- 332 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 87-05, Section: B.
- 주기사항
- Advisor: Liu, Ling.
- 학위논문주기
- Thesis (Ph.D.)--Georgia Institute of Technology, 2022.
- 초록/해제
- 요약Deep learning is being deployed in the cloud and on edge devices for a wide range of domain-specific applications, ranging from healthcare, cyber-manufacturing, autonomic vehicles, to smart cities and smart planet initiatives. While deep learning creates new opportunities for business, engineering, and scientific discoveries, it also introduces new attack surfaces to the modern computing systems that incorporate deep learning as a core component for algorithmic decision making and cognitive machine intelligence, ranging from data poisoning and model inversion during the training phase and adversarial evasion attacks during model inference phase, aiming to cause the well-trained model to misbehave randomly or purposefully. This dissertation research addresses these problems with dual focuses: First, it aims to provide a fundamental understanding of the security and privacy vulnerabilities inherent in deep neural network training and inference. Second, it develops an adversarial resilient framework and a set of optimization techniques to safeguard the deep learning systems, services, and applications against adversarial manipulations and gradient leakage induced privacy violations, while maintaining the accuracy and convergence performance of deep learning systems. This dissertation research has made three unique contributions towards advancing the knowledge and technological foundation for privacy-preserving deep learning with adversarial robustness against deceptions.The first main contribution is an in-depth investigation into security and privacy threats inherent in deep learning, represented by gradient leakage attacks during both centralized and distributed training, model manipulation with data poisoning during model training, and deception queries to well-trained models at the inference phase, represented by adversarial examples and out-of-distribution inputs. By introducing a principled approach to investigating gradient leakage attacks and different attack optimization methods in both centralized model training and federated learning environments, we provide a comprehensive risk assessment framework for an in-depth analysis of different attack mechanisms and attack surfaces that an adversary may leverage to reconstruct the private training data. Similarly, we take a holistic approach to creating an in-depth understanding of both adversarial examples and out-of-distribution examples in terms of their adversarial transferability and their inherent divergence. We also present a comprehensive study on the data poisoning to reveal its effectiveness and robust statistics under the complication scenarios of federated learning. Our research exposes the root causes for these adversarial vulnerabilities and provides transformative enlightenment on designing mitigation strategies and effective countermeasures.The second main contribution of this dissertation is to develop a cross-layer strategic ensemble verification methodology (XEnsemble) for enhancing the adversarial robustness of DNN model inference in the presence of adversarial examples and out-of-distribution examples. XEnsemble by design has three unique capabilities. (i) XEnsemble builds diverse input denoising verifiers by leveraging different data cleaning techniques. (ii) XEnsemble develops a disagreement-diversity ensemble learning methodology for guarding the output of the prediction model against deception. (iii) XEnsemble provides a suite of algorithms to combine input verification and output verification to protect the DNN prediction models from both adversarial examples and out-of-distribution inputs.The third contribution is the development of gradient leakage attack resilient deep learning for both centralized model training and distributed model training systems with privacy enhancing optimizations. To circumvent gradient leakage attacks, we investigate different strategies to add noise to the intermediate model parameter updates during model training (centralized or federated learning) with dual optimization goals: (i) the amount of noise added should be sufficient to remove the privacy leakages of private training data, and (ii) the amount of noise added should not be too much to hurt the overall accuracy and convergence of the trained model. We provide a theoretical formalization to certify the robustness provided differential privacy noise injection against gradient leakage attack. We also extend the conventional deep learning with differential privacy approach with the fixed privacy parameters for DP controlled noise injection by introducing adaptive privacy parameters to both centralized deep learning with differential privacy and federated deep learning with differential privacy.
- 일반주제명
- Deep learning
- 일반주제명
- Privacy
- 일반주제명
- Defense
- 일반주제명
- Impact analysis
- 일반주제명
- Deception
- 기본자료저록
- Dissertations Abstracts International. 87-05B.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260126s2022 us c eng d■001000017360532
■00520260202105542
■006m o d
■007cr#unu||||||||
■020 ▼a9798263397852
■035 ▼a(MiAaPQ)AAI32315294
■035 ▼a(MiAaPQ)GeorgiaTech72437
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a006
■1001 ▼aWei, Wenqi.
■24510▼aAdversarial Resilient and Privacy Preserving Deep Learning
■260 ▼a[Sl]▼bGeorgia Institute of Technology▼c2022
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2022
■300 ▼a332 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 87-05, Section: B.
■500 ▼aAdvisor: Liu, Ling.
■5021 ▼aThesis (Ph.D.)--Georgia Institute of Technology, 2022.
■520 ▼aDeep learning is being deployed in the cloud and on edge devices for a wide range of domain-specific applications, ranging from healthcare, cyber-manufacturing, autonomic vehicles, to smart cities and smart planet initiatives. While deep learning creates new opportunities for business, engineering, and scientific discoveries, it also introduces new attack surfaces to the modern computing systems that incorporate deep learning as a core component for algorithmic decision making and cognitive machine intelligence, ranging from data poisoning and model inversion during the training phase and adversarial evasion attacks during model inference phase, aiming to cause the well-trained model to misbehave randomly or purposefully. This dissertation research addresses these problems with dual focuses: First, it aims to provide a fundamental understanding of the security and privacy vulnerabilities inherent in deep neural network training and inference. Second, it develops an adversarial resilient framework and a set of optimization techniques to safeguard the deep learning systems, services, and applications against adversarial manipulations and gradient leakage induced privacy violations, while maintaining the accuracy and convergence performance of deep learning systems. This dissertation research has made three unique contributions towards advancing the knowledge and technological foundation for privacy-preserving deep learning with adversarial robustness against deceptions.The first main contribution is an in-depth investigation into security and privacy threats inherent in deep learning, represented by gradient leakage attacks during both centralized and distributed training, model manipulation with data poisoning during model training, and deception queries to well-trained models at the inference phase, represented by adversarial examples and out-of-distribution inputs. By introducing a principled approach to investigating gradient leakage attacks and different attack optimization methods in both centralized model training and federated learning environments, we provide a comprehensive risk assessment framework for an in-depth analysis of different attack mechanisms and attack surfaces that an adversary may leverage to reconstruct the private training data. Similarly, we take a holistic approach to creating an in-depth understanding of both adversarial examples and out-of-distribution examples in terms of their adversarial transferability and their inherent divergence. We also present a comprehensive study on the data poisoning to reveal its effectiveness and robust statistics under the complication scenarios of federated learning. Our research exposes the root causes for these adversarial vulnerabilities and provides transformative enlightenment on designing mitigation strategies and effective countermeasures.The second main contribution of this dissertation is to develop a cross-layer strategic ensemble verification methodology (XEnsemble) for enhancing the adversarial robustness of DNN model inference in the presence of adversarial examples and out-of-distribution examples. XEnsemble by design has three unique capabilities. (i) XEnsemble builds diverse input denoising verifiers by leveraging different data cleaning techniques. (ii) XEnsemble develops a disagreement-diversity ensemble learning methodology for guarding the output of the prediction model against deception. (iii) XEnsemble provides a suite of algorithms to combine input verification and output verification to protect the DNN prediction models from both adversarial examples and out-of-distribution inputs.The third contribution is the development of gradient leakage attack resilient deep learning for both centralized model training and distributed model training systems with privacy enhancing optimizations. To circumvent gradient leakage attacks, we investigate different strategies to add noise to the intermediate model parameter updates during model training (centralized or federated learning) with dual optimization goals: (i) the amount of noise added should be sufficient to remove the privacy leakages of private training data, and (ii) the amount of noise added should not be too much to hurt the overall accuracy and convergence of the trained model. We provide a theoretical formalization to certify the robustness provided differential privacy noise injection against gradient leakage attack. We also extend the conventional deep learning with differential privacy approach with the fixed privacy parameters for DP controlled noise injection by introducing adaptive privacy parameters to both centralized deep learning with differential privacy and federated deep learning with differential privacy.
■590 ▼aSchool code: 0078.
■650 4▼aDeep learning
■650 4▼aPrivacy
■650 4▼aDefense
■650 4▼aImpact analysis
■650 4▼aDeception
■690 ▼a0800
■71020▼aGeorgia Institute of Technology.
■7730 ▼tDissertations Abstracts International▼g87-05B.
■790 ▼a0078
■791 ▼aPh.D.
■792 ▼a2022
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17360532▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.
Preview
Export
ChatGPT Discussion
AI Recommended Related Books
Подробнее информация.
- Бронирование
- не существует
- моя папка
- Первый запрос зрения
- Non-Book Loan Application
- Nighttime Book Loan Application
Available after logging in.


