[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118544-en":3,"doc-seo-118544-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118544,13056703019662,"Evangeline","https://ap-avatar.wpscdn.com/avatar/be000253a8e92610077?_k=1778726343310543188",8,"Research & Report","Adversarial Machine Learning: Methods for Attacks and Defenses - Dissertation Abstract","Rapid advances in machine learning for real-world systems increase the importance of security. Adversarial machine learning studies malicious behaviors by attackers and builds defenses for threats that arise during training, such as poisoning attacks, and during testing, such as evasion attacks. Despite extensive defensive research, gaps remain, including countermeasures using benign noise, training adaptive defenses for mixed attacks, and discovering underexplored vulnerabilities in training and testing pipelines. This dissertation targets safety challenges through new attack and defense methods, including defenses against poisoning and evasion, a novel poisoning attack on fair models, analysis of adversarial weaknesses in multimodal pre-trained models, and detection/mitigation of hateful multimodal memes using vision-language models.","University of Arkansas, Fayetteville  \nScholarWorks@UARK  \n\n| Graduate Theses and Dissertations | Graduate School and International Education |\n| --- | --- |\n| 5-2025\u003Cbr>Adversarial Machine Learning: Methods for Attacks and Defenses\u003Cbr>Minh Hao Van\u003Cbr>University of Arkansas, Fayetteville\u003Cbr>Follow this and additional works at: [https://scholarworks.uark.edu/etd](https://scholarworks.uark.edu/etd)\u003Cbr> Part of the Artificial Intelligence and Robotics Commons, and the Cybersecurity Commons\u003Cbr>Click here to let us know how this document benefits you. |  |\n\nCitation  \nVan, M. (2025) . Adversarial Machine Learning: Methods for Attacks and Defenses. Graduate Theses and  \nDissertations Retrieved from [https://scholarworks.uark.edu/etd/5674](https://scholarworks.uark.edu/etd/5674)  \nThis Dissertation is brought to you for free and open access by the Graduate School and International Education at ScholarWorks@UARK. It has been accepted for inclusion in Graduate Theses and Dissertations by an authorized administrator of ScholarWorks@UARK. For more information, please contact [uarepos@uark.edu](uarepos@uark.edu).  \nAdversarial Machine Learning: Methods for Attacks and Defenses  \nA dissertation submitted in partial fulfillment  \nof the requirements for the degree of  \nDoctor of Philosophy in Engineering with a concentration in Computer Science  \nby  \nMinh Hao Van  \nUniversity of Technology, VNU-HCM  \nBachelor of Engineering in Computer Science, 2019  \nMay 2025  \nUniversity of Arkansas  \nThis dissertation is approved for recommendation to the Graduate Council.  \n\n| Xintao Wu, Ph.D.\u003Cbr>Committee Chair |\n| --- |\n| Lu Zhang, Ph.D.\u003Cbr>Committee member |\n\nThi Hoang Ngan Le, Ph.D. Committee member  \nHaoming Shen, Ph.D. Committee member  \nABSTRACT  \nWith the rapid development of machine learning in real-world applications, enhancing security plays an important role. Adversarial machine learning focuses on understanding malicious actions from attackers and developing defensive techniques against such threats when deploying machine learning systems. An attack can occur in different scenarios, such as poisoning attacks during the training stage and evasion attacks during the testing stage. Although extensive research has explored defense strategies to deal with these harmful attacks, there is a need for further research into areas such as how to counteract malicious attacks with healthy noise or how to train an adaptive defense against a mixture of attacks. Additionally, developing novel attack methodologies is essential for uncovering underexplored vulnerabilities in the training and testing pipelines, thereby providing defenders with deeper insights into the inherent weaknesses of model architectures. Most adversarial attacks primarily aim to degrade overall classification accuracy; however, there is a notable lack of attack strategies that target models designed for fair prediction or multimodal retrieval. Furthermore, malicious users continuously devise subtle methods to disseminate harmful content on social media, necessitating the development of intelligent systems capable of detecting and mitigating such content. Vision-Language Models, which have been widely used in real-world applications, hold significant potential for fostering safer and more respectful online environments.  \nThe goal of this dissertation is to address critical challenges in ensuring safety in machine learning models, focusing on the development of novel attack and defense methods. We begin by investigating two defenses against specific attack types: poisoning attacks and evasion attacks. Next, we examine the potential threats posed by adversaries targeting the fairness of machine learning models, introducing a novel poisoning attack on fair machine learning systems. We then analyze the vulnerabilities of multimodal pre-trained models under adversarial attacks. Finally, we explore methods for detecting and mitigating hateful content in multimodal memes utilizing Vision-Lan","cbCairZpFEV1SS8e","https://ap.wps.com/l/cbCairZpFEV1SS8e","pdf",12803326,1,141,"English","en",105,"# Abstract\n## Threat models and challenges\n## Proposed attack and defense contributions\n## Dissertation frameworks and algorithms","[{\"question\":\"What kinds of adversarial attacks does the dissertation study?\",\"answer\":\"It examines poisoning attacks during training and evasion attacks during testing, and extends to fairness-focused adversarial attacks and threats against multimodal retrieval and hateful-content pipelines.\"},{\"question\":\"What defenses are proposed against poisoning and evasion attacks?\",\"answer\":\"For poisoning, it develops a defense using influence functions to reduce harmful effects of poisoned training data. For evasion, it introduces adaptive training to make models robust against unseen testing-time attacks.\"},{\"question\":\"How does the dissertation address fairness and multimodal threats?\",\"answer\":\"It proposes a novel poisoning attack that degrades both accuracy and fairness objectives. It also analyzes adversarial vulnerabilities of multimodal pre-trained models and explores hateful meme detection and transformation using vision-language models.\"}]","Adversarial Machine Learning: Methods for Attacks and Defenses - Dissertation Abstract | PDF",1785684074,355,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"adversarial-machine-learning-methods-for-attacks-and-defenses-dissertation-abstract","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/adversarial-machine-learning-methods-for-attacks-and-defenses-dissertation-abstract/118544/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What kinds of adversarial attacks does the dissertation study?","Question",{"text":75,"@type":76},"It examines poisoning attacks during training and evasion attacks during testing, and extends to fairness-focused adversarial attacks and threats against multimodal retrieval and hateful-content pipelines.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What defenses are proposed against poisoning and evasion attacks?",{"text":80,"@type":76},"For poisoning, it develops a defense using influence functions to reduce harmful effects of poisoned training data. For evasion, it introduces adaptive training to make models robust against unseen testing-time attacks.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the dissertation address fairness and multimodal threats?",{"text":84,"@type":76},"It proposes a novel poisoning attack that degrades both accuracy and fairness objectives. It also analyzes adversarial vulnerabilities of multimodal pre-trained models and explores hateful meme detection and transformation using vision-language models.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]