[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117452-en":3,"doc-seo-117452-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117452,1374391975076,"Riley","https://ap-avatar.wpscdn.com/avatar/14000253ca4ec9f6853?x-image-process=image/resize,m_fixed,w_180,h_180&k=1783305029341752051",8,"Research & Report","An Exploration of Machine Learning Security - Doctor of Philosophy Dissertation","Computer science and mathematics research has made it possible for machines to learn complex patterns and abstractions without direct tutoring. At the same time, adversaries have developed threats aimed at machine learning systems that can impact model producers and maintainers, model users, and individuals represented by the training or decision information. This dissertation analyzes machine-learning attacks at the algorithmic level, building a taxonomy and threat model, developing new evasion methods for tree-based models, and proposing exploratory techniques to extract representative training information and victim model parameters.","Dakota State University  \nBeadle Scholar  \nMasters Theses & Doctoral Dissertations  \nFall 12-2024  \nAn Exploration of Machine Learning Security Carson Kendall Grandi Koball  \nFollow this and additional works at: [https://scholar.dsu.edu/theses](https://scholar.dsu.edu/theses)  \nAN EXPLORATION OF MACHINE LEARNING  \nSECURITY  \nA dissertation submitted to Dakota State University in partial fulfillment of the  \nrequirements for the degree of  \nDoctor of Philosophy  \nin  \nComputer Science  \nDecember 10, 2024  \nBy  \nCarson Kendall Grandi Koball  \nDissertation Committee:  \nDr. Yong Wang  \nDr. John Hastings  \nDr. Varghese Vaidyan  \nBeacom College of Computer and Cyber Sciences  \nDocusign Envelope ID: 40AB60DF-3352-49CF-89C5-860B55375E51  \nDISSERTATION APPROVAL FORM  \nThis dissertation is approved as a credible and independent investigation by a candidate for the Doctor of Philosophy degree and is acceptable for meeting the dissertation requirements for this degree. Acceptance of this dissertation does not imply that the conclusions reached by the candidate are necessarily the conclusions of the major department or university.  \nStudent Name:  Carson Koball   \nDissertation Title: An Exploration of Machine Learning Security  \nGraduate Office Verification:  Eve Skajews ki  Date: 12/03/2024   \nDissertation Chair/Co-Chair:   Date:  12/03/2024  Print Name:  Yong Wang   \nDissertation Chair/Co-Chair:   Date:    \nPrint Name:    \nCommittee Member:   Date:  12/03/2024   \nPrint Name:  John Hastings   \nCommittee Member:   Date:  12/04/2024   \nPrint Name:  Varg he se Va idyan   \nCommittee Member:   Date:    \nPrint Name:    \nCommittee Member:   Date:    \nPrint Name:    \nSubmit Form Through DocuSign Only  \nor to Office of Graduate Studies  \nDakota State University  \nACKNOWLEDGMENTS  \nIn a certain view, the completion of this dissertation marks the culmination of over 20 years of continuous education. Such an accomplishment would not have been possible without the assistance of many advisors, mentors, and teachers that dedicated their time to help me mature both as a student and as a person.  \nI would like to first thank my parents, Matthew and Mary, for shaping me into the person that I have grown into. Their many sacrifices, hard work, and constant support have allowed me to be in the position that I am very grateful to be in today. I would also like to thank my siblings, Mary Hanna, Rocco, Cayman, and Briar, for being a source of inspiration to finish this work. Without them, I can say with certainty that my life would be incomplete. Additionally, I extend my appreciation to every other member of my family, including my grandparents, aunts, uncles, cousins, and more.  \nI am especially grateful to Dr. Yong Wang for his gargantuan effort in guiding the creation of this dissertation and for the opportunity to work under his supervision during both my undergraduate and graduate studies. His role in shaping the later years of my academic career cannot be overemphasized. I would also like to thank Dr. John Hastings and Dr. Varghese Vaidyan for their feedback to help complete this document.  \nFinally, I would like to thank every teacher, mentor, and friend that I have ever had-even if not explicitly mentioned here.  \nABSTRACT  \nInnovations in the fields of computer science and mathematics have enabled machines to learn incredibly complicated patterns and abstractions without explicit tutoring. Unfortunately, threats have been developed targeting machine learning systems that may affect large groups of individuals including model producers and maintainers, model users, and individuals who may be implicitly or explicitly represented by the information used by the model. Consequently, it is crucial to understand possible attacks that may be employed on machine learning models at the algorithmic level for better mitigation strategies.  \nThis research seeks to work towards a better understanding of vulnerabilities that exist in the space of machine learning in","cbCaiuFwZqEtPEid","https://ap.wps.com/l/cbCaiuFwZqEtPEid","pdf",2679706,1,89,"English","en",105,"# List of Tables\n# List of Figures\n# Chapter 1: Introd","[{\"question\":\"What problem does the dissertation address in machine learning security?\",\"answer\":\"It addresses threats that target machine learning systems and can affect developers, users, and individuals represented by the model’s information sources. The work focuses on understanding attacks at the algorithmic level to support future defenses.\"},{\"question\":\"What are the three main research contributions described in the abstract?\",\"answer\":\"The dissertation first creates a taxonomy and threat model for existing attacks. It then develops an exploitative evasion attack for tree-based models (single and ensemble). Finally, it proposes an exploratory attack to extract representative information from hypersphere-based training datasets and victim model parameters.\"},{\"question\":\"How are the proposed attacks evaluated?\",\"answer\":\"Victim models are trained on multiple datasets to demonstrate data-agnostic behavior. Multiple metrics are then used to assess the attacks’ effectiveness after the attack procedures are applied.\"}]","An Exploration of Machine Learning Security - Doctor of Philosophy Dissertation | PDF",1785675929,224,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"an-exploration-of-machine-learning-security-doctor-of-philosophy-dissertation","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/an-exploration-of-machine-learning-security-doctor-of-philosophy-dissertation/117452/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the dissertation address in machine learning security?","Question",{"text":75,"@type":76},"It addresses threats that target machine learning systems and can affect developers, users, and individuals represented by the model’s information sources. The work focuses on understanding attacks at the algorithmic level to support future defenses.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are the three main research contributions described in the abstract?",{"text":80,"@type":76},"The dissertation first creates a taxonomy and threat model for existing attacks. It then develops an exploitative evasion attack for tree-based models (single and ensemble). Finally, it proposes an exploratory attack to extract representative information from hypersphere-based training datasets and victim model parameters.",{"name":82,"@type":73,"acceptedAnswer":83},"How are the proposed attacks evaluated?",{"text":84,"@type":76},"Victim models are trained on multiple datasets to demonstrate data-agnostic behavior. Multiple metrics are then used to assess the attacks’ effectiveness after the attack procedures are applied.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]