构建虚构人脸数据集,评估视觉语言模型遗忘能力。
Benchmarking Vision Language Model Unlearning via Fictitious Facial Identity Dataset

- 设计虚构人脸VQA数据集,精准控制信息来源与暴露程度。
- 四类基线方法均存在遗忘效果差、效用与遗忘平衡难问题。
- 引入隐私攻击测试,推动更鲁棒的遗忘算法发展。
机器遗忘已成为有效消除训练数据中特定信息的策略。然而,随着视觉数据的日益融合,视觉语言模型(VLM)中的隐私问题仍缺乏深入研究。为此,我们提出面部身份遗忘基准(FIUBench),一个专为评估VLM遗忘算法有效性而设计的新基准,适用于“被遗忘的权利”场景。具体地,通过构建虚构人脸身份的VQA数据集来定义VLM遗忘任务,并采用两阶段评估流程,精确控制信息来源及其暴露水平。在评估方面,鉴于VLM支持多种语义相同的问题表达形式,我们还提供包括成员推断攻击和精心设计的对抗性隐私攻击在内的稳健评估指标。在FIUBench上评估四种基线VLM遗忘算法后发现,所有方法在遗忘性能上均受限,且模型效用与遗忘质量之间存在显著权衡。此外,我们的结果强调了隐私攻击在鲁棒评估中的重要性。我们希望FIUBench能推动更高效VLM遗忘算法的发展。
原文摘要 · Abstract (English)
Machine unlearning has emerged as an effective strategy for forgetting specific information in the training data. However, with the increasing integration of visual data, privacy concerns in Vision Language Models (VLMs) remain underexplored. To address this, we introduce Facial Identity Unlearning Benchmark (FIUBench), a novel VLM unlearning benchmark designed to robustly evaluate the effectiveness of unlearning algorithms under the Right to be Forgotten setting. Specifically, we formulate the VLM unlearning task via constructing the Fictitious Facial Identity VQA dataset and apply a two-stage evaluation pipeline that is designed to precisely control the sources of information and their exposure levels. In terms of evaluation, since VLM supports various forms of ways to ask questions with the same semantic meaning, we also provide robust evaluation metrics including membership inference attacks and carefully designed adversarial privacy attacks to evaluate the performance of algorithms. Through the evaluation of four baseline VLM unlearning algorithms within FIUBench, we find that all methods remain limited in their unlearning performance, with significant trade-offs between model utility and forget quality. Furthermore, our findings also highlight the importance of privacy attacks for robust evaluations. We hope FIUBench will drive progress in developing more effective VLM unlearning algorithms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。