用博弈论平衡删数据后的模型性能与隐私风险。
Game-Theoretic Machine Unlearning: Mitigating Extra Privacy Leakage
- 设计对抗性模块,让删数据不降性能也不泄露隐私
- 实测效果接近重新训练,且隐私泄露风险更低
- 适合关注数据删除合规与隐私保护的研究者
随着机器学习广泛应用,数据提供者面临日益严峻的隐私风险。根据GDPR等法规,组织需移除用户数据及其对模型的影响。机器遗忘是一种新兴技术,旨在使模型能够删除用户私有信息。尽管已有多种高效遗忘方案,但仍存在局限:部分数据删除可能导致模型性能下降;原始模型与生成遗忘模型之间的差异可能被攻击者利用,引发额外隐私泄露。为此,本文提出一种博弈论驱动的机器遗忘算法,模拟遗忘性能与隐私保护之间的竞争关系。该算法包含遗忘模块和隐私模块:遗忘模块采用模型距离与分类误差联合损失函数,求解最优策略;隐私模块则增强对成员推断攻击的防御能力,降低遗忘过程中的隐私泄露风险。在真实数据集上的实验表明,该方法在保持模型性能接近重新训练水平的同时,有效缓解了额外隐私泄露问题。
原文摘要 · Abstract (English)
With the extensive use of machine learning technologies, data providers encounter increasing privacy risks. Recent legislation, such as GDPR, obligates organizations to remove requested data and its influence from a trained model. Machine unlearning is an emerging technique designed to enable machine learning models to erase users' private information. Although several efficient machine unlearning schemes have been proposed, these methods still have limitations. First, removing the contributions of partial data may lead to model performance degradation. Second, discrepancies between the original and generated unlearned models can be exploited by attackers to obtain target sample's information, resulting in additional privacy leakage risks. To address above challenges, we proposed a game-theoretic machine unlearning algorithm that simulates the competitive relationship between unlearning performance and privacy protection. This algorithm comprises unlearning and privacy modules. The unlearning module possesses a loss function composed of model distance and classification error, which is used to derive the optimal strategy. The privacy module aims to make it difficult for an attacker to infer membership information from the unlearned data, thereby reducing the privacy leakage risk during the unlearning process. Additionally, the experimental results on real-world datasets demonstrate that this game-theoretic unlearning algorithm's effectiveness and its ability to generate an unlearned model with a performance similar to that of the retrained one while mitigating extra privacy leakage risks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。