Towards Trustworthy Machine Learning in High-Stakes Decision Making
Author
Summary, in English
This thesis develops a principled perspective on the verification and characterization of trustworthiness properties in DNNs. Robustness, privacy leakage, and fairness are formulated as optimization problems over network outputs subject to variations in inputs, models, or datasets.
A primary contribution is the development of methods for robustness verification based on refinement of relaxation-based approximations. In particular, a layer-wise refinement strategy is introduced that tightens convex relaxations of nonlinear activation constraints. The approach progressively tightens relaxation-based approximations, yielding improvements of sound bounds while avoiding full combinatorial enumeration of activation patterns. In addition, the thesis establishes a perspective on how model properties influence verifiability and introduces verification-friendly network transformations that improve bound tightness without degrading prediction performance.
Beyond single network analysis, the thesis proposes verification frameworks for comparing model variants over shared input regions. This formulation enables verification of local implication and behavioral preservation under model transformations, with joint optimization providing strictly tighter guarantees than independent analyses.
The thesis further analyzes cross-dimensional relations between robustness, privacy, and fairness. In personalized learning settings, it demonstrates that robustness-induced representations can encode identity-specific patterns, enabling patient membership inference without access to training samples. It also introduces a locally-persistent counterfactual bias formulation that captures fairness disparities within perturbation regions and can be incorporated as a training regularizer.
In summary, this thesis establishes the formal ground for analyzing and improving trustworthiness properties of DNNs. The results contribute to optimization-based verification, model transformation analysis, and the study of interactions between robustness, privacy, and fairness, contributing to more reliable machine learning.
Department/s
Publishing year
2026
Language
English
Full text
- Available as PDF - 7 MB
Document type
Doctoral Thesis (compilation)
Publisher
Electrical and Information Technology, Lund University
Topic
- Computer Sciences
Status
Published
Supervisor
- Amir Aminifar
- Ahmed Rezine
- Maria Kihl
ISBN/ISSN/Other
- ISBN: 978-91-8104-993-0
- ISBN: 978-91-8104-992-3
Defence date
11 June 2026
Defence time
09:15
Defence place
Lecture Hall E:1406, building E, Ole Römers väg 3, Faculty of Engineering LTH, Lund University, Lund. The dissertation will be live streamed, but part of the premises is to be excluded from the live stream.
Opponent
- Shoukry, Yasser (Assoc. Prof.)