MUBox平台评测23种深度学习去记忆方法,揭示其在真实场景中表现不稳。
MUBox: A Critical Evaluation Framework of Deep Machine Unlearning
- 整合23种去记忆技术,统一评估不同场景下的效果
- 发现顶尖方法在复杂任务中效果参差,无万能方案
- 强调需多指标结合,避免单一评估误导结果
近期法律框架要求实现‘被遗忘的权利’,需在用户请求下移除特定数据。机器去记忆作为解决方案,可选择性删除模型中的学习信息。本文提出MUBox,一个全面的深度学习去记忆评估平台,集成23种先进去记忆技术,在6个实际场景中使用11种不同评估指标进行测试。该平台使研究者与实践者能够:(1) 在多种场景下评估并比较不同去记忆方法的效果;(2) 分析当前评估指标对去记忆性能的影响;(3) 在统一框架内开展详细的对比研究。通过MUBox系统评估,我们获得若干关键发现:(a) 即便发表于顶级会议或竞赛获奖的先进方法,在多样场景中仍表现出不一致性,以往研究多集中于简化设置(如随机遗忘、类别级遗忘),凸显了向更复杂任务拓展评估的必要性。(b) 去记忆性能评估仍具挑战性,单一指标无法全面衡量有效性、效率与模型效用保持,必须采用多指标以实现平衡与整体评估。(c) 在去污染场景中,现有方法效果差异显著,高度依赖于具体污染攻击类型。
原文摘要 · Abstract (English)
Recent legal frameworks have mandated the right to be forgotten, obligating the removal of specific data upon user requests. Machine Unlearning has emerged as a promising solution by selectively removing learned information from machine learning models. This paper presents MUBox, a comprehensive platform designed to evaluate unlearning methods in deep learning. MUBox integrates 23 advanced unlearning techniques, tested across six practical scenarios with 11 diverse evaluation metrics. It allows researchers and practitioners to (1) assess and compare the effectiveness of different machine unlearning methods across various scenarios; (2) examine the impact of current evaluation metrics on unlearning performance; and (3) conduct detailed comparative studies on machine unlearning in a unified framework. Leveraging MUBox, we systematically evaluate these unlearning methods in deep learning and uncover several key insights: (a) Even state-of-the-art unlearning methods, including those published in top-tier venues and winners of unlearning competitions, demonstrate inconsistent effectiveness across diverse scenarios. Prior research has predominantly focused on simplified settings, such as random forgetting and class-wise unlearning, highlighting the need for broader evaluations across more difficult unlearning tasks. (b) Assessing unlearning performance remains a non-trivial problem, as no single evaluation metric can comprehensively capture the effectiveness, efficiency, and preservation of model utility. Our findings emphasize the necessity of employing multiple metrics to achieve a balanced and holistic assessment of unlearning methods. (c) In the context of depoisoning, our evaluation reveals significant variability in the effectiveness of existing approaches, which is highly dependent on the specific type of poisoning attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。