arXiv:2412.00126cs.LG2024-12被引 2

提出高效联邦遗忘方法SFU,删数据不降性能还省资源

Streamlined Federated Unlearning: Unite as One to Be Highly Efficient

  • 用多教师指导机制,让模型在遗忘目标数据时保持性能
  • 相比重训练快4.2倍,通信量减少63%,且在图像/文本数据上表现更优
  • 适合需要快速删除用户数据又不想损失模型精度的隐私场景

随着“被遗忘权”法规的实施,联邦学习面临数据删除需求。现有联邦遗忘方法虽提升效率,但常导致模型性能下降,需额外步骤恢复。为此,我们提出轻量级联邦遗忘方法SFU,可在不重新训练的前提下有效移除目标数据影响,并保持剩余数据上的模型性能。通过设计实用的多教师系统,利用多个不同教师模型指导未学习模型,实现精准遗忘与性能保留。SFU在计算和存储上均高效,具备高度灵活性与泛化能力。在图像与文本基准数据集上的实验表明,其时间与通信效率显著优于重训练基线和现有最优方法。进一步通过后门攻击验证了其有效性。

原文摘要 · Abstract (English)

Recently, the enactment of ``right to be forgotten" laws and regulations has imposed new privacy requirements on federated learning (FL). Researchers aim to remove the influence of certain data from the trained model without training from scratch through federated unlearning (FU). While current FU research has shown progress in enhancing unlearning efficiency, it often results in degraded model performance upon achieving the goal of data unlearning, necessitating additional steps to recover the performance of the unlearned model. Moreover, these approaches also suffer from many shortcomings such as high consumption of computational and storage resources. To this end, we propose a streamlined federated unlearning approach (SFU) aimed at effectively removing the influence of the target data while preserving the model performance on the retained data without degradation. We design a practical multi-teacher system that achieves both target data influence removal and model performance preservation by guiding the unlearned model through several distinct teacher models. SFU is both computationally and storage-efficient, highly flexible, and generalizable. We conduct extensive experiments on both image and text benchmark datasets. The results demonstrate that SFU significantly improves time and communication efficiency compared to the benchmark retraining method and significantly outperforms existing SOTA methods. Additionally, we verify the effectiveness of SFU using the backdoor attack.

联邦学习数据遗忘隐私保护高效算法

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。