arXiv:2503.23536cs.LGcs.AI2025-03综述被引 6

通过扰动数据让模型无法学习有用信息,保护隐私与安全。

A Survey on Unlearnable Data

  • 对训练数据加扰动,使模型难以提取有效特征。
  • 系统梳理生成方法、评测指标与实际应用挑战。
  • 适合关注数据隐私与模型安全的研究者参考。

不可学习数据(Unlearnable Data, ULD)作为一种新兴防御技术,旨在阻止机器学习模型从特定数据中学习有意义的模式,从而保护数据隐私与安全。通过向训练数据引入扰动,ULD 会降低模型性能,使未经授权的模型难以提取有用表示。尽管 ULD 越来越重要,现有综述多集中于对抗攻击和模型遗忘等关联领域,较少将其作为独立研究方向。本文填补该空白,全面回顾了 ULD 的生成方法、公开基准、评估指标、理论基础及实际应用。我们对比分析不同方法在不可学习性、不可察觉性、效率与鲁棒性方面的优劣与权衡。此外,探讨关键挑战,如扰动不可察觉性与模型退化间的平衡,以及生成过程的计算复杂度。最后,提出有前景的未来研究方向,强调其在机器学习数据保护中的潜在重要作用。

原文摘要 · Abstract (English)

Unlearnable data (ULD) has emerged as an innovative defense technique to prevent machine learning models from learning meaningful patterns from specific data, thus protecting data privacy and security. By introducing perturbations to the training data, ULD degrades model performance, making it difficult for unauthorized models to extract useful representations. Despite the growing significance of ULD, existing surveys predominantly focus on related fields, such as adversarial attacks and machine unlearning, with little attention given to ULD as an independent area of study. This survey fills that gap by offering a comprehensive review of ULD, examining unlearnable data generation methods, public benchmarks, evaluation metrics, theoretical foundations and practical applications. We compare and contrast different ULD approaches, analyzing their strengths, limitations, and trade-offs related to unlearnability, imperceptibility, efficiency and robustness. Moreover, we discuss key challenges, such as balancing perturbation imperceptibility with model degradation and the computational complexity of ULD generation. Finally, we highlight promising future research directions to advance the effectiveness and applicability of ULD, underscoring its potential to become a crucial tool in the evolving landscape of data protection in machine learning.

数据隐私模型安全不可学习数据防御技术

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。