[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121903-en":3,"doc-seo-121903-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121903,4398048949847,"Eliana","https://ap-avatar.wpscdn.com/avatar/400002536579ef2da7f?_k=1778318612642679267",8,"Research & Report","METHODS FOR COMPUTING EFFECTIVE PERTURBATIONS IN ADVERSARIAL MACHINE LEARNING ATTACKS - Thesis Abstract and Contents Overview","Machine Learning is widely used in complex information technology systems, prompting research on security and reliability of ML methods. Adversarial Machine Learning (AML) studies how an attacker can craft perturbations that force a classifier to output an attacker-desired result while preserving the original data’s intent. Real-world perturbations must also satisfy constraints on permissible input manipulations, a requirement often overlooked. This thesis addresses effective perturbation generation with two applications: deceiving an e-health prescription system via forged binary clinical features, and attacking online social network spam detection through a black-box optimization preserving correlation and semantic dependencies.","Dottorato di Ricerca in INFORMATION AND COMMUNICATION TECHNOLOGIES  \nDipartimento di Ingegneria  \nSSD: ING-INF/05  \nMETHODS FOR COMPUTING EFFECTIVE PERTURBATIONS IN ADVERSARIAL MACHINE LEARNING ATTACKS  \nIL DOTTORE IL COORDINATORE  \nAndrea Giammanco [Ch.ma](Ch.ma) Prof.ssa Ilenia Tinnirello  \nIL TUTOR IL CO-TUTOR  \n[Ch.mo](Ch.mo) Prof. Salvatore Gaglio [Ch.mo](Ch.mo) Prof. Giuseppe Lo Re  \nCICLO XXXVI  \nANNO CONSEGUIMENTO TITOLO: 2024  \nAbstract  \nIn recent years, the widespread adoption of Machine Learning (ML) at the core of complex information technology systems has driven researchers to investigate the security and reliability of ML techniques. A very specific kind of threats concerns the adversary mechanisms through which an attacker could induce a classification algorithm to provide the desired output. Such strategies, known as Adversarial Machine Learning (AML), have a twofold purpose: to calculate a perturbation to be applied to the classifier’s input such that the outcome is subverted, while maintaining the underlying intent of the original data. Although any manipulation that accomplishes these goals is theoretically acceptable, in real scenarios perturbations must correspond to a set of permissible manipulations of the input, which is rarely considered in the literature.  \nIn this thesis, two different problems are considered related to the matter of generating effective perturbations in an AML attack. First, an e-health scenario is addressed, in which an automatic system for prescriptions can be deceived by inputs forged to subvert the model’s prediction. Patients clinical records are typically based on binary features representing the presence/absence of certain symptoms. In this work it is presented an algorithm capable of generating a precise sequence of moves, that the adversary has to take in order to elude the automatic prescription service  \nSecondly, this thesis outlines an AML technique specifically designed to fool the spam account detection system of an Online Social Network (OSN) . The proposed black-box evasion attack is formulated as an optimization problem that computes the adversarial sample while maintaining two important properties of the feature space, namely statistical correlation and semantic dependency.  \nAcknowledgments  \nI would like to thank my advisor, Prof. Salvatore Gaglio, and all of the professors of the NDSLAB research group, Prof. Giuseppe Lo Re, Prof. Alessandra De Paola, for having dedicated time in sharing their knowledge with me.  \nThanks in particular to Prof. Marco Morana for having closely followed this work since the beginning.  \nThanks to Prof. Marco Ortolani for our collaboration.  \nI am grateful to my colleagues of the lab for having shared many memories together: Pierluca, Vincenzo, Federico (also for our close collaboration), Antonio.  \nThanks in particular to Marlo and Salvatore who have become close friends. Special thanks to my dear friend Claudio whose presence has been inestimable.  \nFinally, I am grateful to my parents for their support in the most crucial moments.  \nContents  \nAbstract i  \nAcknowledgments ii  \nGlossary ix  \n1 Introduction 1  \n1. 1 Motivations and Goals . . . . . . . . . . . . . . . . . . . . . . . . . 3  \n1.2 Contributions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4  \n1.3 Dissertation Outline . . . . . . . . . . . . . . . . . . . . . . . . . . 6  \n1.4 Publications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6  \n2 Background and Related Works 8  \n3 Binary Perturbations in e-Health Prescription Classification 20  \n3. 1 Scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21  \n3.2 Threat Model . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21  \n3.3 Methodology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23  \n3.4 Experimental Analysis . . . . . . . . . . . . . . . . . . . . . . . . . 26  \n3.4. 1 The classification network . . . . . . . . . . . . . . . . . . . 27  \n","cbCaiqw3rqR1rYnC","https://ap.wps.com/l/cbCaiqw3rqR1rYnC","pdf",1718867,1,85,"English","en",105,"# Introduction\n## Motivations and Goals\n## Contributions\n## Dissertation Outline\n## Publications\n# Background and Related Works\n# Binary Perturbations in e-Health Prescription Classification\n## Scenario\n## Threat Model\n## Methodology\n## Experimental Analysis\n# Correlations-Aware Perturbations in Spam Account Detection\n## Scenario\n## Threat Model\n## Methodology\n## Experimental Analysis\n# Conclusions\n# Bibliography","[{\"question\":\"What is the core goal of adversarial machine learning described in this thesis?\",\"answer\":\"The thesis focuses on computing perturbations that subvert a classifier’s prediction toward an attacker-desired output while maintaining the underlying intent of the original data.\"},{\"question\":\"How does the thesis apply AML to an e-health prescription system?\",\"answer\":\"It presents an algorithm that generates a precise sequence of permissible moves to deceive an automatic prescription service, using forged inputs based on binary clinical features of symptoms.\"},{\"question\":\"What is the key idea behind the AML approach for OSN spam account detection?\",\"answer\":\"The proposed black-box evasion attack is formulated as an optimization problem that computes adversarial samples while preserving statistical correlation and semantic dependency in the feature space.\"}]","METHODS FOR COMPUTING EFFECTIVE PERTURBATIONS IN ADVERSARIAL MACHINE LEARNING ATTACKS - Thesis Abstract and Contents Overview | PDF",1785807657,214,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"methods-for-computing-effective-perturbations-in-adversarial-machine-learning-attacks-thesis-abstract-and-contents-overview","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/methods-for-computing-effective-perturbations-in-adversarial-machine-learning-attacks-thesis-abstract-and-contents-overview/121903/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the core goal of adversarial machine learning described in this thesis?","Question",{"text":75,"@type":76},"The thesis focuses on computing perturbations that subvert a classifier’s prediction toward an attacker-desired output while maintaining the underlying intent of the original data.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the thesis apply AML to an e-health prescription system?",{"text":80,"@type":76},"It presents an algorithm that generates a precise sequence of permissible moves to deceive an automatic prescription service, using forged inputs based on binary clinical features of symptoms.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the key idea behind the AML approach for OSN spam account detection?",{"text":84,"@type":76},"The proposed black-box evasion attack is formulated as an optimization problem that computes adversarial samples while preserving statistical correlation and semantic dependency in the feature space.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]