<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-19T07:09:10Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/117625" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/117625</identifier>
        <datestamp>2025-11-07</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_8888</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_8887</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:contributor>Moulin, Pierre</dc:contributor>
          <dc:contributor>Moulin, Pierre</dc:contributor>
          <dc:contributor>Schwing, Alexander</dc:contributor>
          <dc:contributor>Li, Bo</dc:contributor>
          <dc:contributor>Raginsky, Maxim</dc:contributor>
          <dc:contributor>Veeravalli, Venugopal V.</dc:contributor>
          <dc:date>2022-12</dc:date>
          <dc:format>application/pdf</dc:format>
          <dc:language>en</dc:language>
          <dc:type>text</dc:type>
          <dc:description>Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2024-12-01</dc:description>
          <dc:description>The student, Amish Goel, accepted the attached license on 2022-08-19 at 11:12.</dc:description>
          <dc:description>The student, Amish Goel, submitted this Dissertation for approval on 2022-08-19 at 11:26.</dc:description>
          <dc:description>This Dissertation was approved for publication on 2022-08-25 at 14:33.</dc:description>
          <dc:description>DSpace SAF Submission Ingestion Package generated from Vireo submission #18464 on 2023-04-12 at 08:10:24</dc:description>
          <dc:title>Locally optimal detection and randomization defenses against universal adversarial perturbations</dc:title>
          <dc:creator>Goel, Amish</dc:creator>
          <dc:date>2022-08-25</dc:date>
          <dc:subject>universal adversarial perturbations</dc:subject>
          <dc:subject>deep learning</dc:subject>
          <dc:subject>hypothesis testing</dc:subject>
          <dc:subject>locally optimal test</dc:subject>
          <dc:subject>generalized likelihood ratio test</dc:subject>
          <dc:description>This thesis investigates a detection-based approach to safeguard a machine-learning based classifier from adversarial perturbations of its input. In particular, we consider input agnostic universal adversarial perturbations which are selected to force the input to a desired target class. The detector is designed by application of fundamental concepts of statistical decision theory, including locally optimal testing. Since locally optimal detectors depend on the input distribution, which is unknown in real-world datasets, a tractable surrogate input distribution is used instead. The thesis also defines several metrics for joint classification and detection, and evaluates them on several image datasets and popular image classifiers. We demonstrate through the experimental results that our detection-based approach is successful and outperforms the prior state of the art. We also show that detector-aware universal adversarial perturbations can be constructed in a way that evades our detector and achieves high target success rate on the classifier. To mitigate this problem, we propose and evaluate several relevant randomization schemes. Among the proposed methods, we observe that randomized smoothing offers better defense against the stronger detector-aware attacks.</dc:description>
          <dc:type>Thesis</dc:type>
          <dc:language>eng</dc:language>
          <dc:identifier>https://hdl.handle.net/2142/117625</dc:identifier>
          <dc:rights>Copyright 2022 Amish Goel</dc:rights>
          <degree>
            <name>Ph.D.</name>
            <level>Dissertation</level>
            <discipline>Electrical &amp; Computer Engr</discipline>
            <grantor>University of Illinois at Urbana-Champaign</grantor>
            <department>Electrical &amp; Computer Eng</department>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
