Publication Date

Spring 2026

Degree Type

Master's Project

Degree Name

Master of Science in Computer Science (MSCS)

Department

Computer Science

First Advisor

Saptarshi Sengupta

Second Advisor

Sayma Akther

Third Advisor

Vuthea Chheang

Keywords

Mixed Bayesian Stackelberg, Morphence, Moving Target Defense, Adversarial Attacks, Vision Transformers, Image Classification

Abstract

Vision Transformer (ViT) models are highly susceptible to adversarial attacks in image classification tasks. Small imperceptible perturbations to the inputs result in a significant classification. Static defense techniques expose the model for a longer duration, allowing attackers to craft stronger perturbations over time. Moving Target Defense (MTD) addresses this limitation by introducing randomness in choosing models at inference. The Morphence framework implements MTD with a pool of student models, randomly switching among them during inference. This project proposes a game-theoretic scheduling for model switching in the Morphence pipeline. The ViT base models are trained on the CIFAR-10 and CIFAR-100 datasets. Heterogeneous students are generated with varying Gaussian noise perturbations. These students are trained adversarially against primary white-box attacks. The experiments in the project evaluate the performance of the base models and the student models under benign and adversarial inputs. The diversity degree of the student models is evaluated to prove the viability of a mixed strategy inference scheduler. This approach introduces a Mixed Bayesian Stackelberg setting to switch among the student models. The defender chooses a set of mixed strategies in different attack scenarios. The best students are evaluated against adversarial examples. The use of a game-theoretic strategy for strategic model switching improves the adversarial robustness of the Morphence defense.

Available for download on Friday, May 21, 2027

Share

COinS