[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122401-en":3,"doc-seo-122401-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122401,962075114101,"Seraphina","https://ap-avatar.wpscdn.com/avatar/e000253a75eb197efd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780044092746381165",8,"Research & Report","Towards Secure and Privacy-Preserving Machine Learning Systems","This dissertation develops and evaluates adversarial methods targeting modern machine learning pipelines with a focus on security and privacy threats. It studies attacks across text-to-image generation, membership inference enhanced by the information bottleneck, adversarial voice transmission over IP networks, and availability attacks against LiDAR-based detection. For each setting, it defines threat models, designs attack formulations and optimization strategies, and measures effectiveness through experiments, ablations, and user studies.","Washington University in St. Louis  \nWashU Scholarly Repository  \n\n| McKelvey School of Engineering Theses & Dissertations | McKelvey School of Engineering |\n| --- | --- |\n| 5-9-2025\u003Cbr>Towards Secure and Privacy-Preserving Machine Learning Systems\u003Cbr>Han Liu\u003Cbr>Washington University – McKelvey School of Engineering\u003Cbr>Follow this and additional works at: [https://openscholarship.wustl.edu/eng_etds](https://openscholarship.wustl.edu/eng_etds)\u003Cbr> Part of the Computer Sciences Commons |  |\n\nRecommended Citation  \nLiu, Han, \"Towards Secure and Privacy-Preserving Machine Learning Systems\" (2025) . McKelvey School of Engineering Theses & Dissertations. 1256.  \n[https://openscholarship.wustl.edu/eng_etds/1256](https://openscholarship.wustl.edu/eng_etds/1256)  \nThis Dissertation is brought to you for free and open access by the McKelvey School of Engineering at WashU Scholarly Repository. It has been accepted for inclusion in McKelvey School of Engineering Theses & Dissertations by an authorized administrator of WashU Scholarly Repository. For more information, please contact [digital@wumail.wustl.edu](digital@wumail.wustl.edu).  \nWASHINGTON UNIVERSITY IN ST. LOUIS  \nMcKelvey School of Engineering Department of Computer Science & Engineering  \nDissertation Examination Committee: William Yeoh, Chair  \nChenyang Lu  \nBo Yuan  \nChongjie Zhang  \nNing Zhang  \nTowards Secure and Privacy-Preserving Machine Learning Systems  \nby  \nHan Liu  \nA dissertation presented to the McKelvey School of Engineering of Washington University in  \npartial fulfillment of the  \nrequirements for the degree  \nof Doctor of Philosophy  \nMay 2025  \nSt. Louis, Missouri  \n© 2025, Han Liu  \nTable of Contents  \nList [of Figures](of Figures ..................................... vi)[ .....................................](of Figures ..................................... vi)[ vi](of Figures ..................................... vi)  \n[List of Tables](List of Tables .....................................)[ .....................................](List of Tables .....................................). viii  \nAcknowledgments ................................... x  \nAbstract ......................................... xi  \nChapter 1: Introduction ............................... 1  \n1.1 Motivation and Challenges ............................ 1  \n1.2 Overview of the Thesis .............................. 3  \nChapter 2: Background and Related Work ................... 4  \n2.1 Machine Learning Systems ............................ 4  \n2.1.1 Predictive and Generative Models .................... 4  \n2.1.2 Speech Recognition Model ........................ 5  \n2.1.3 Text-to-image Generation Model .................... 6  \n2.1.4 Point Cloud Recognition Model ..................... 7  \n2.1.5 Explainable Machine Learning ...................... 7  \n2.1.6 Federated Learning ............................ 8  \n2.1.7 Security and Privacy Risks ........................ 9  \n2.2 Adversarial Attack ................................ 10  \n2.2.1 Attack Formulation and Threat Model ................. 10  \n2.2.2 Adversarial Attack against Speech Recognition Model ......... 11  \n2.2.3 Adversarial Attack against Text-to-image Generation Model ..... 12  \n2.2.4 Adversarial Attack against Point Cloud Recognition Model ...... 13  \n2.3 Membership Inference Attack .......................... 14  \n2.3.1 Attack Formulation and Threat Model ................. 14  \n2.3.2 Membership Inference Attack against Generative Model ........ 16  \nChapter 3: Adversarial Attacks against Text-to-Image Generation Models 17  \n3.1 Overview ...................................... 17  \n3.2 Methodology ................................... 19  \n3.2.1 Threat Model ............................... 19  \n3.2.2 Formulation and Overview ........................ 19  \n3.2.3 Similarity Measurement ......................... 21  \n3.2.4 Genetic-based Optimization ....................... 22  \n3.2.5 Sample Quality Improvement ...................... 25  \n3.3 Experim","cbCaimr3y6HDbmKF","https://ap.wps.com/l/cbCaimr3y6HDbmKF","pdf",6455185,1,156,"English","en",105,"# Table of Contents\n## List of Figures\n## List of Tables\n## Acknowledgments\n## Abstract\n## Chapter 1: Introduction\n## Chapter 2: Background and Related Work\n## Chapter 3: Adversarial Attacks against Text-to-Image Generation Models\n## Chapter 4: Enhanced Membership Inference Attacks through the Lens of the Information Bottleneck\n## Chapter 5: Targeted Adversarial Voice over IP Network\n## Chapter 6: Adversarial Availability Attacks against LiDAR-Based Detection","[{\"question\":\"What security and privacy threats does the thesis address?\",\"answer\":\"It addresses security and privacy risks including adversarial attacks and membership inference, with methods evaluated across multiple machine learning modalities.\"},{\"question\":\"How are experiments structured for the text-to-image generation attacks?\",\"answer\":\"Experiments include defined experiment settings, evaluation results, and ablation studies to analyze attack behavior and effectiveness.\"},{\"question\":\"What role does the information bottleneck play in membership inference attacks?\",\"answer\":\"The thesis uses the information bottleneck perspective to design attacks and introduce an information removal scheme, then evaluates classification and diffusion models quantitatively.\"}]","Towards Secure and Privacy-Preserving Machine Learning Systems | PDF",1785810447,393,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"towards-secure-and-privacy-preserving-machine-learning-systems","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/towards-secure-and-privacy-preserving-machine-learning-systems/122401/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security and privacy threats does the thesis address?","Question",{"text":75,"@type":76},"It addresses security and privacy risks including adversarial attacks and membership inference, with methods evaluated across multiple machine learning modalities.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How are experiments structured for the text-to-image generation attacks?",{"text":80,"@type":76},"Experiments include defined experiment settings, evaluation results, and ablation studies to analyze attack behavior and effectiveness.",{"name":82,"@type":73,"acceptedAnswer":83},"What role does the information bottleneck play in membership inference attacks?",{"text":84,"@type":76},"The thesis uses the information bottleneck perspective to design attacks and introduce an information removal scheme, then evaluates classification and diffusion models quantitatively.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]