数据重复攻击可破坏模型删去功能,威胁隐私与性能。
Data Duplication: A Novel Multi-Purpose Attack Paradigm in Machine Unlearning
- 攻击者复制训练数据并植入,诱使模型无法真正删除。
- 重训练方法在特定条件下失效,删除后模型性能严重下降。
- 新近似重复技术可绕过去重检测,适合研究安全机制者。
数据重复是训练数据中的普遍问题。已有研究显示,重复数据会影响模型性能与数据隐私,但其对模型删去过程的影响尚未被充分探索。本文首次系统研究了数据重复在标准机器删去、联邦删去和强化学习删去范式中的作用。我们提出一种攻击者:复制目标模型训练集的一部分,将其加入训练集;训练完成后,要求模型所有者删去这部分数据,并分析删去后的模型表现。例如,攻击者可揭露尽管已执行删去操作,该重复数据的痕迹仍残留在模型中。为规避去重检测,我们设计了三种针对不同删去范式的新型近似重复方法,并评估其在应用去重技术后的效果。结果表明:1)重训练这一标准删去方法在某些条件下无法有效删去数据;2)删去重复数据可能导致模型性能显著下降;3)精心构造的重复数据可逃避去重检测。
原文摘要 · Abstract (English)
Duplication is a prevalent issue within datasets. Existing research has demonstrated that the presence of duplicated data in training datasets can significantly influence both model performance and data privacy. However, the impact of data duplication on the unlearning process remains largely unexplored. This paper addresses this gap by pioneering a comprehensive investigation into the role of data duplication, not only in standard machine unlearning but also in federated and reinforcement unlearning paradigms. Specifically, we propose an adversary who duplicates a subset of the target model's training set and incorporates it into the training set. After training, the adversary requests the model owner to unlearn this duplicated subset, and analyzes the impact on the unlearned model. For example, the adversary can challenge the model owner by revealing that, despite efforts to unlearn it, the influence of the duplicated subset remains in the model. Moreover, to circumvent detection by de-duplication techniques, we propose three novel near-duplication methods for the adversary, each tailored to a specific unlearning paradigm. We then examine their impacts on the unlearning process when de-duplication techniques are applied. Our findings reveal several crucial insights: 1) the gold standard unlearning method, retraining from scratch, fails to effectively conduct unlearning under certain conditions; 2) unlearning duplicated data can lead to significant model degradation in specific scenarios; and 3) meticulously crafted duplicates can evade detection by de-duplication methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。