Degree

Doctor of Philosophy (PhD)

Department

Computer Science

Document Type

Dissertation

Abstract

Deep learning has become a foundational technology for modern intelligent systems used in sensing, authentication, media generation, and automated decision-making. As these systems are increasingly deployed in security- and privacy-sensitive settings, ensuring their trustworthiness has become a critical challenge. Yet deep learning models remain vulnerable to spoofed sensory inputs, synthetic media, and malicious behaviors hidden within trained networks. These vulnerabilities undermine reliability and raise serious concerns about whether such systems can be trusted under adversarial and deceptive scenarios. This dissertation investigates how to build and restore trust in deep learning across three tightly connected dimensions: multimodal sensing, generative authenticity, and model integrity. The central insight is that benign and adversarial behaviors often exhibit differential robustness under carefully designed representation learning, transformation, and repair mechanisms. By explicitly exploiting these differences, it becomes possible to develop deep learning systems that are more secure, reliable, and resilient. First, we propose IdentityKD for person recognition using mmWave radar sensors. IdentityKD transfers discriminative identity knowledge from a facial recognition model to a radar-based gait recognition model during training. By integrating compositional contrastive learning with knowledge distillation, this framework enhances the discriminative power of gait representations and requires only radar data during inference. Consequently, it achieves accurate and privacy-preserving identity identification. Second, we present LiveGuard, a lightweight voice liveness detection approach for defending against replayed and spoofed speech. LiveGuard combines Wavelet Scattering Transform with Mel spectrogram scaling to capture complementary cues that distinguish live from manipulated voice. With a lightweight architecture, it achieves strong detection performance and low computational overhead. Third, we develop AdvOSD, a diffusion framework for generalizable and efficient fake image detection. AdvOSD probes authenticity through a one-step diffusion-inspired transformation conditioned on adversarial prompting. Because real and fake images respond differently to this transformation, the method effectively detects both synthesized and edited images while remaining computationally efficient. Finally, we present PDS, a data-efficient backdoor defense method for restoring model integrity. PDS combines knowledge distillation with iterative pruning to identify and suppress backdoor-sensitive neurons using limited clean defense data. It removes malicious behaviors across diverse attacks and architectures while preserving clean model utility.

Date

2-6-2026

DOI

https://proquest.com/docview/3347817167

First Committee Chair

Xiali Hei

First Committee Member

Anthony Maida

Second Committee Member

Li Chen

Third Committee Member

Neil Gong

Fourth Committee Member

Sheng Chen

Share

COinS