arXiv:2505.05279cs.LGcs.CR2025-05ICML被引 12

提出首个面向多任务学习的不可逆数据生成框架,提升攻击效果与泛化性。

MTL-UE: Learning to Learn Nothing for Multi-Task Learning

  • 基于生成器设计,引入标签先验与类别特征嵌入,优化对抗扰动
  • 在4个MTL数据集上均超越现有方法,对5种模型架构和权重策略有效
  • 支持密集预测任务,可无缝集成已有不可逆方法,应用灵活

现有不可逆策略主要针对单任务学习中的个人数据防护,但当前趋势转向多任务数据与多任务学习(MTL),旨在构建可处理多种任务的通用模型。然而,针对MTL数据与模型的不可逆策略仍被忽视。本文提出MTL-UE,首个统一的多任务不可逆样本生成框架。不同于逐样本优化扰动,该框架采用生成器结构,引入标签先验与类别级特征嵌入,显著提升攻击性能。同时,通过任务内与任务间嵌入正则化,增强类间分离、抑制类内方差,极大提升攻击鲁棒性。MTL-UE还具备强适应性,适用于多种密集预测任务,且为即插即用设计,可轻松融合现有依赖代理模型的不可逆方法。大量实验表明,MTL-UE在4个MTL数据集、3种基础不可逆方法、5种模型主干和5种任务加权策略下均表现卓越。

原文摘要 · Abstract (English)

Most existing unlearnable strategies focus on preventing unauthorized users from training single-task learning (STL) models with personal data. Nevertheless, the paradigm has recently shifted towards multi-task data and multi-task learning (MTL), targeting generalist and foundation models that can handle multiple tasks simultaneously. Despite their growing importance, MTL data and models have been largely neglected while pursuing unlearnable strategies. This paper presents MTL-UE, the first unified framework for generating unlearnable examples for multi-task data and MTL models. Instead of optimizing perturbations for each sample, we design a generator-based structure that introduces label priors and class-wise feature embeddings which leads to much better attacking performance. In addition, MTL-UE incorporates intra-task and inter-task embedding regularization to increase inter-class separation and suppress intra-class variance which enhances the attack robustness greatly. Furthermore, MTL-UE is versatile with good supports for dense prediction tasks in MTL. It is also plug-and-play allowing integrating existing surrogate-dependent unlearnable methods with little adaptation. Extensive experiments show that MTL-UE achieves superior attacking performance consistently across 4 MTL datasets, 3 base UE methods, 5 model backbones, and 5 MTL task-weighting strategies.

多任务学习不可逆数据生成对抗模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。