<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/oai-pmh.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-09-22T00:43:34Z</responseDate>
  <request identifier="oai:www.ideals.illinois.edu:2142/130183" metadataPrefix="etdms" verb="GetRecord">https://www.ideals.illinois.edu/oai-pmh</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:www.ideals.illinois.edu:2142/130183</identifier>
        <datestamp>2026-02-10</datestamp>
        <setSpec>col_2142_5131</setSpec>
        <setSpec>col_2142_10761</setSpec>
        <setSpec>com_2142_5130</setSpec>
        <setSpec>com_2142_10755</setSpec>
        <setSpec>com_2142_234</setSpec>
      </header>
      <metadata>
        <thesis xmlns="http://www.ndltd.org/standards/metadata/etdms/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.ndltd.org/standards/metadata/etdms/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdms11.xsd http://purl.org/dc/elements/1.1/ http://www.ndltd.org/standards/metadata/etdms/1.1/etdmsdc.xsd">
          <dc:format>application/pdf</dc:format>
          <dc:language>en</dc:language>
          <dc:type>text</dc:type>
          <dc:description>Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2027-08-01</dc:description>
          <dc:description>The student, Qingying Hao, accepted the attached license on 2025-07-14 at 16:47.</dc:description>
          <dc:description>The student, Qingying Hao, submitted this Dissertation for approval on 2025-07-14 at 22:25.</dc:description>
          <dc:description>This Dissertation was approved for publication on 2025-07-15 at 12:53.</dc:description>
          <dc:description>DSpace SAF Submission Ingestion Package generated from Vireo submission #22558 on 2025-10-25 at 15:53:55</dc:description>
          <dc:title>Towards similarity learning in security applications</dc:title>
          <dc:creator>Hao, Qingying</dc:creator>
          <dc:date>2025-07-15</dc:date>
          <dc:contributor>Wang, Gang</dc:contributor>
          <dc:contributor>Wang, Gang</dc:contributor>
          <dc:contributor>Gunter, Carl</dc:contributor>
          <dc:contributor>Li, Bo</dc:contributor>
          <dc:contributor>Chandrasekaran, Varun</dc:contributor>
          <dc:contributor>Conti, Mauro</dc:contributor>
          <dc:subject>Security</dc:subject>
          <dc:subject>Machine Learning</dc:subject>
          <dc:subject>Similarity Learning</dc:subject>
          <dc:language>eng</dc:language>
          <dc:description>In today’s world, large amounts of data remain unlabeled, posing a major challenge, especially in security applications, where acquiring high-quality labels is costly and difficult. Without accurate labels, it is hard to train reliable machine learning (ML) models, which limits their effectiveness in real-world scenarios. Similarity learning provides a promising direction by capturing relationships within the data without requiring explicit labels. Instead, it learns from reference pairs by measuring similarity through distance. While simple distance metrics can be used , similarity learning is often combined with deep learning to learn robust feature representations for comparison using predefined or learned similarity measures. How reliable is similarity learning in real-world security applications, particularly when exposed to adversarial threats? Under what conditions can it enhance model generalization and detection performance? This dissertation evaluates the robustness of similarity-learning applications under a realistic threat model by applying adversarial attacks end-to-end, and shows how similarity learning can improve out-of-distribution (OOD) generalization in graph-structured data. Specifically, Chapter 3 presents adversarial attacks targeting perceptual hashing-based reverse image search engines, which use Hamming distance as the similarity metric. By developing advanced attacks and evaluating them end-to-end on real-world systems, our framework successfully subverts several major reverse image search engines. In Chapter 4, we present attacks on vision-based phishing detectors trained using similarity learning. Our framework generates adversarial logos that preserve original brand semantics while bypassing state-of-the-art visual phishing website detectors. Chapter 5 explores how similarity learning, specifically graph contrastive learning (GCL), can complement supervised learning to improve out-of-distribution generalization in graph neural networks (GNNs) under natural distribution shifts. In summary, these studies show that similarity learning-based applications are vulnerable to adversarial attacks, highlighting the need for stronger defenses under realistic end-to-end threat models. At the same time, similarity learning can complement supervised methods by providing diverse feature representations and decision signals, making it valuable for improving out-of-distribution detection under natural distribution shifts.</dc:description>
          <dc:date>2025-08</dc:date>
          <dc:type>Text</dc:type>
          <dc:identifier>https://hdl.handle.net/2142/130183</dc:identifier>
          <dc:rights>Copyright 2025 Qingying Hao</dc:rights>
          <degree>
            <department>Siebel School Comp &amp; Data Sci</department>
            <discipline>Computer Science</discipline>
            <grantor>University of Illinois Urbana-Champaign</grantor>
            <name>Ph.D.</name>
            <level>Dissertation</level>
          </degree>
        </thesis>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
