[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118474-en":3,"doc-seo-118474-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118474,1374391974468,"Eden","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Towards Robust and Generalizable Machine Learning Models - Thesis","With rapid advances and widespread adoption of machine learning, the dissertation addresses robustness and generalization under adversarial inputs and distribution shifts. It studies certified robustness for neural networks, introducing Fast-IBP to improve certified robust accuracy while reducing training time via better initialization and normalization, and analyzes width-scaling limits in Interval Bound Propagation. It further covers responsible deployment of large language models via red-teaming for text detectors and a training-free backtranslation defense against jailbreaking. Additional theory and methods target training-stage over-specialization, prompt-tuning limits, and context loss after instruction fine-tuning.","UCLA  \nUCLA Electronic Theses and Dissertations  \nTitle  \nTowards Robust and Generalizable Machine Learning Models  \nPermalink  \n[https://escholarship.org/uc/item/7cf904h7](https://escholarship.org/uc/item/7cf904h7)  \nAuthor  \nWang, Yihan  \nPublication Date  \n2025  \nPeer reviewed|Thesis/dissertation  \n[eScholarship.org](eScholarship.org) Powered by the California Digital Library  \nUniversity of California  \nUNIVERSITY OF CALIFORNIA Los Angeles  \nTowards Robust and Generalizable Machine Learning Models  \nA dissertation submitted in partial satisfaction of the requirements for the degree Doctor of Philosophy in Computer Science  \nby  \nYihan Wang  \n2025  \n© Copyright by Yihan Wang 2025  \nABSTRACT OF THE DISSERTATION  \nTowards Robust and Generalizable Machine Learning Models  \nby  \nYihan Wang  \nDoctor of Philosophy in Computer Science  \nUniversity of California, Los Angeles, 2025  \nProfessor Cho-Jui Hsieh, Chair  \nWith the rapid advancement and widespread adoption of machine learning technologies, concerns about model robustness and generalization have become increasingly significant. This dissertation discusses and addresses critical challenges in developing machine learning models that are both robust against adversarial examples and capable of generalizing across distribution shifts. We first investigate certified robustness methods for neural networks, proposing Fast-IBP, a novel approach that achieves state-of-the-art certified robust accuracy with significantly reduced training time through improved initialization and normalization techniques. We also provide theoretical analysis on the limitations of width scaling in Interval Bound Propagation training. Moving beyond traditional robustness concerns, we explore challenges in responsible deployment of large language models (LLMs), developing comprehensive red-teaming tests for popular LLM text detection methods and proposing a training-free backtranslation defense against jailbreaking attacks. Finally, we extend our discussions from robustness in the deployment stage to the training stage. We provide theoretical analysis towards the limitations of prompt-tuning, identifying its representation power and failure cases. We also identify format overfitting as a partial explanation for language model overfitting when fine-tuned on specific downstream tasks, and introduce PROMOT, a two-stage fine-  \ntuning strategy that mitigates over-specialization while maintaining or improving in-context learning performance on unfinetuned tasks. Moving from single-task fine-tuning to general instruction finetuning, we identify the loss of context awareness after instruction finetuning for language models. Based on empirical observations, we propose a method to identify context-dependent training examples and mitigate the performance loss. Our work contributes significant advancements in building machine learning systems that are not only powerful but also reliable, safe, and aligned with human values.  \nThe dissertation of Yihan Wang is approved.  \nKai-Wei Chang  \nNanyun Peng  \nQuanquan Gu  \nCho-Jui Hsieh, Committee Chair  \nUniversity of California, Los Angeles  \n2025  \nTABLE OF CONTENTS  \n1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1  \n1.1 Summary of Contributions .............................. 3  \n2 Understanding and Improving the Interval Bound Propagation (IBP) Training .. 5  \n2.1 Introduction ...................................... 5  \n2.2 Background and Relate Work ............................. 6  \n2.2.1 Certified Robust Training ........................... 6  \n2.2.2 Weight Initialization of Neural Networks .................. 7  \n2.2.3 Batch Normalization for DNN Training ................... 7  \n2.2.4 Convergence of Standard Neural Network Training ............. 8  \n2.3 On the Convergence of Certified Robust Training with Interval Bound Propagation 8  \n2.3.1 Preliminaries ................................. 8  \n2.3.2 Convergence Analysis for I","cbCaieYwDAr7mOJ6","https://ap.wps.com/l/cbCaieYwDAr7mOJ6","pdf",2760066,1,227,"English","en",105,"# Introduction\n## Summary of Contributions\n# Understanding and Improving the Interval Bound Propagation (IBP) Training\n## Background and Related Work\n## Convergence of Certified Robust Training with Interval Bound Propagation\n## Fast Interval Bound Propagation (IBP) Training with Short Warmup\n# Towards Resposible Deployment of Large Language Models\n## Detectors, Red-Teaming, and Adversarial Examples in NLP\n## Defending LLMs against Jailbreaking Attacks via Backtranslation","[{\"question\":\"What main problems does the dissertation focus on?\",\"answer\":\"It focuses on building machine learning models that are robust to adversarial examples and can generalize across distribution shifts, including safe and responsible deployment of large language models.\"},{\"question\":\"What is Fast-IBP, and how does it improve certified robustness?\",\"answer\":\"Fast-IBP is a certified robustness training approach that achieves state-of-the-art certified robust accuracy while significantly reducing training time using improved initialization and normalization techniques.\"},{\"question\":\"How does the dissertation address responsible deployment and jailbreaking for LLMs?\",\"answer\":\"It introduces comprehensive red-teaming tests for popular LLM text detection methods and proposes a training-free backtranslation defense to mitigate jailbreaking attacks.\"}]","Towards Robust and Generalizable Machine Learning Models - Thesis | PDF",1785683785,572,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"towards-robust-and-generalizable-machine-learning-models-thesis","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/towards-robust-and-generalizable-machine-learning-models-thesis/118474/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What main problems does the dissertation focus on?","Question",{"text":75,"@type":76},"It focuses on building machine learning models that are robust to adversarial examples and can generalize across distribution shifts, including safe and responsible deployment of large language models.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is Fast-IBP, and how does it improve certified robustness?",{"text":80,"@type":76},"Fast-IBP is a certified robustness training approach that achieves state-of-the-art certified robust accuracy while significantly reducing training time using improved initialization and normalization techniques.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the dissertation address responsible deployment and jailbreaking for LLMs?",{"text":84,"@type":76},"It introduces comprehensive red-teaming tests for popular LLM text detection methods and proposes a training-free backtranslation defense to mitigate jailbreaking attacks.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]