Publication Date

Spring 2026

Degree Type

Master's Project

Degree Name

Master of Science in Computer Science (MSCS)

Department

Computer Science

First Advisor

Mark Stamp

Second Advisor

Fabio Di Troia

Third Advisor

Thomas Austin

Keywords

Machine Learning Models, Parameter Perturbation, Bit-Level Attacks, Steganography, Neural Networks

Abstract

This project investigates how classical machine learning models respond to small, targeted modifications in their parameters. Using Hidden Markov Models (HMMs) and Support Vector Machines (SVMs), a number of bit-level and proportional perturbation experiments were performed. These include 8-bit quantization, least-significant-bit flips, Progressive Bit Search, and probability sensitivity analysis. To provide a broader comparison, these experiments were also extended to neural models, specifically Mul- tilayer Perceptrons (MLPs) and Long Short-Term Memory networks (LSTMs). This allowed us to analyze both classical and deep learning architectures. Applied to the Drebin Android malware dataset, the results show that only a limited set of parameters significantly affect model behavior and most remain stable under modification. Classi- cal models are parameter-efficient but brittle, offering limited steganographic capacity due to their small and highly sensitive parameter structure. On the other hand, neural networks are parameter-redundant, having higher steganographic capacity by allowing modifications to be distributed across many parameters with minimal impact on performance. These results show clear differences in how classical and neural models respond to parameter changes and bit-flip attacks with implications for both robustness and hidden information embedding. This work provides a framework for understanding parameter sensitivity and steganographic capacity across different types of machine learning models.

Available for download on Saturday, May 22, 2027

Share

COinS