[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-128389-en":3,"doc-seo-128389-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},128389,962085564807,"Aurelia","https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8",8,"Research & Report","Evolving Threats and Defenses in Machine Learning - Focus on Model Inversion and Beyond","Machine learning (ML) models are increasingly embedded in mission-critical real-world applications, heightening security, privacy, and trust concerns. This dissertation centers on model inversion (MI) attacks, which can compromise the confidentiality of training data. It studies MI in both image classification and natural language processing, introducing an advanced white-box MI attack, a data-centric defense using augmentation to reshape the loss landscape, and a framework that repurposes MI to mitigate backdoor threats. Extending to large language models, it proposes LLM red-teaming and FASTTRACK for reliable fact tracing that reduces hallucinations while improving accuracy and efficiency.","Evolving Threats and Defenses in Machine Learning: Focus on  \nModel Inversion and Beyond  \nSi Chen  \nDissertation submitted to the Faculty of the  \nVirginia Polytechnic Institute and State University in partial fulfillment of the requirements for the degree of  \nDoctor of Philosophy  \nin  \nComputer Engineering  \nRuoxi Jia, Chair  \nNarendran Ramakrishnan  \nXuan Wang  \nMing Jin  \nAmos L. Abbott  \nApril 22, 2025  \nBlacksburg, Virginia  \nKeywords: Trustworthy ML, Model Inversion Attacks, Data Privacy, LLM Red Teaming,  \nFact Tracing  \nCopyright 2025, Si Chen  \nEvolving Threats and Defenses in Machine Learning: Focus on Model Inversion and Beyond  \nSi Chen  \n(ABSTRACT)  \nMachine learning (ML) models are increasingly integrated into critical real-world applications, raising concerns about security, privacy, and trustworthiness. Among various emerging threats, model inversion (MI) attacks stand out due to their potential to compromise the conﬁdentiality of training data. This dissertation investigates evolving threats in ML, centering on model inversion and its implications across image classiﬁcation and natural language processing domains.  \nInitially, we present an advanced model inversion attack algorithm leveraging knowledgeenriched distributional strategies under white-box conditions, eﬀectively reconstructing private training data from image classiﬁers. To counteract such threats, we develop a novel data-centric defense approach, strategically utilizing augmentation techniques to reshape the model’s loss landscape, thereby mitigating vulnerability to MI attacks.  \nRecognizing the dual nature of threats and defenses, we further demonstrate how MI attacks, conventionally viewed as harmful, can be creatively repurposed to enhance model security. Speciﬁcally, we show MI can detect and neutralize backdoor attacks in image classiﬁcation, enabling eﬀective clean-data-free defense strategies.  \nBroadening the scope beyond vision tasks, this dissertation introduces a proactive redteaming framework designed for large language models (LLMs) . By combining global strategy formation with local adaptive learning, our proposed red-teaming agent systematically identiﬁes vulnerabilities, thus enhancing robustness against adaptive adversarial scenarios.  \nFinally, addressing the critical issue of hallucination in language models, we propose FASTTRACK, a reliable fact-tracing framework. FASTTRACK uniquely integrates recursive clustering with large language model-driven validation, signiﬁcantly surpassing existing methods in accuracy and computational eﬃciency.  \nCollectively, these works illustrate a comprehensive narrativefrom understanding foundational threats to innovating versatile, robust defensesadvancing the ongoing eﬀort toward secure, privacy-preserving, and trustworthy machine learning systems.  \nEvolving Threats and Defenses in Machine Learning: Focus on Model Inversion and Beyond  \nSi Chen  \n(GENERAL AUDIENCE ABSTRACT)  \nMachine learning (ML) involves computer systems learning patterns from data to perform tasks without explicit programming. As ML becomes increasingly prevalent in our daily livesfrom social media and healthcare to autonomous vehiclesit also faces growing security risks. This dissertation explores these risks, focusing especially on one type called model inversion, where an attacker tries to reconstruct sensitive training information by examining how an ML model makes decisions.  \nInitially, the study shows how these attacks can reveal private information from image recognition systems, and then proposes methods to defend against them. Interestingly, it also highlights how the same methods attackers use can be repurposed positively, such as detecting hidden manipulations in models. Moving beyond images, the work tackles security threats against language-based ML models, which power applications like chatbots and virtual assistants. It develops techniques to ﬁnd and ﬁx weaknesses in these systems, ensuring they behave s","cbCaia4Cetgq90Vl","https://ap.wps.com/l/cbCaia4Cetgq90Vl","pdf",7057322,3,1,154,"English","en",105,"# List of Figures\n# List of Tables\n# 1 Introduction\n# 2 Model Inversion Attacks and Defenses in Image Classfication\n## 2.1 Motivation\n## 2.2 Background\n## 2.3 Knowledge-Enriched Distributional Model Inversion Attacks\n## 2.4 Data-centric defense: Shaping loss landscape with augmentations to counter model inversion\n## 2.5 Discussions\n# 3 Transforming Threats into Opportunities\n## 3.1 Motivation\n## 3.2 Background\n## 3.3 Approach\n## 3.4 Experiments\n## 3.5 Discussions\n# 4 Expanding Beyond Model Inversion – Emerging Threats in NLP Models\n## 4.1 Motivation\n## 4.2 Background\n## 4.3 Approach","[{\"question\":\"What is model inversion, and why is it a major threat to machine learning systems?\",\"answer\":\"Model inversion attacks aim to reconstruct sensitive training information by observing how an ML model makes decisions. The risk is especially serious because it can expose confidential training data.\"},{\"question\":\"How does the dissertation defend against model inversion attacks?\",\"answer\":\"It proposes a data-centric defense that uses augmentation to reshape the model’s loss landscape, reducing vulnerability to MI attacks under the studied conditions.\"},{\"question\":\"How can model inversion be repurposed for improving model security?\",\"answer\":\"The work shows MI can detect and neutralize backdoor attacks in image classification, enabling clean-data-free defense strategies.\"}]","Evolving Threats and Defenses in Machine Learning - Focus on Model Inversion and Beyond | PDF",1785947242,388,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"evolving-threats-and-defenses-in-machine-learning-focus-on-model-inversion-and-beyond","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":20},"https://docshare.wps.com/document/research-report/",{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/evolving-threats-and-defenses-in-machine-learning-focus-on-model-inversion-and-beyond/128389/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-25","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is model inversion, and why is it a major threat to machine learning systems?","Question",{"text":76,"@type":77},"Model inversion attacks aim to reconstruct sensitive training information by observing how an ML model makes decisions. The risk is especially serious because it can expose confidential training data.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the dissertation defend against model inversion attacks?",{"text":81,"@type":77},"It proposes a data-centric defense that uses augmentation to reshape the model’s loss landscape, reducing vulnerability to MI attacks under the studied conditions.",{"name":83,"@type":74,"acceptedAnswer":84},"How can model inversion be repurposed for improving model security?",{"text":85,"@type":77},"The work shows MI can detect and neutralize backdoor attacks in image classification, enabling clean-data-free defense strategies.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]