Carnegie Mellon University
Browse

Customized Robustness for Machine Learning Models

Download (16.75 MB)
thesis
posted on 2025-10-30, 17:16 authored by Weiran LinWeiran Lin
<p dir="ltr">Evasion attacks perturb inputs of machine-learning models to induce undesired behaviors. Existing metrics commonly evaluate the risks of evasion attacks by untargeted robustness, and these metrics do not correspond to many practical adversarial goals. As a mitigation, we propose customized robustness, a general framework of robustness definitions that corresponds to specific use cases. With such a framework, we identify new definitions of robustness that remain unexplored by existing work, including but not limited to robustness that involves multiple input or output instances and robustness that involves multiple models. We further explore new threat models with these novel definitions, and invent new metrics that better capture the risks. Our new definitions also motivate stronger and more efficient tools to assess robustness in many real world use cases, including various loss functions that more accurately capture adversary goals.</p>

History

Date

2025-08-04

Degree Type

  • Dissertation

Thesis Department

  • Electrical and Computer Engineering

Degree Name

  • Doctor of Philosophy (PhD)

Advisor(s)

Lujo Bauer

Usage metrics

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC