arXiv:2503.22413cs.CRcs.LG2025-03被引 3

首次实现对视觉模型中单个数据的使用审计,可精准追踪数据是否被滥用。

Instance-Level Data-Use Auditing of Visual ML Models

  • 基于成员推理与假设检验,实现细粒度实例级数据使用追踪。
  • 实验发现现有近似删除方法在降低10%模型性能后仍无法彻底清除数据影响。
  • 适用于图像分类、视觉编码器及图文模型,适合关注数据合规性的研究者。

机器学习系统中未经授权使用数据的法律纠纷日益增多,亟需可靠的數據使用審計機制以確保透明與責任。本文提出首個主動式、細粒度的實例級數據使用審計方法,使數據所有者能追蹤其單一數據實例在模型中的使用情況,相比以往工作更具細粒度。該方法擴展了黑箱成員推理與序列假設檢驗的結合,保持可量化且可調節的誤報率特徵。我們在三類視覺機器學習模型上進行評估:圖像分類器、視覺編碼器以及視覺語言模型(包括對比語言-圖像預訓練(CLIP)和自舉語言-圖像預訓練(BLIP)模型)。此外,我們應用該方法評估兩種先進的近似刪除方法的效果。第二項重要發現是:即使犧牲10%的模型效能,現有兩種方法也未能有效消除圖像分類器與CLIP模型中已刪除數據的影響。

原文摘要 · Abstract (English)

The growing trend of legal disputes over the unauthorized use of data in machine learning (ML) systems highlights the urgent need for reliable data-use auditing mechanisms to ensure accountability and transparency in ML. We present the first proactive, instance-level, data-use auditing method designed to enable data owners to audit the use of their individual data instances in ML models, providing more fine-grained auditing results than previous work. To do so, our research generalizes previous work integrating black-box membership inference and sequential hypothesis testing, expanding its scope of application while preserving the quantifiable and tunable false-detection rate that is its hallmark. We evaluate our method on three types of visual ML models: image classifiers, visual encoders, and vision-language models (Contrastive Language-Image Pretraining (CLIP) and Bootstrapping Language-Image Pretraining (BLIP) models). In addition, we apply our method to evaluate the performance of two state-of-the-art approximate unlearning methods. As a noteworthy second contribution, our work reveals that neither method successfully removes the influence of the unlearned data instances from image classifiers and CLIP models, even if sacrificing model utility by $10\%$.

数据审计模型可解释性隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。