arXiv:2506.02761cs.AIcs.CL2025-06中稿 · ACM CCS 2025被引 10

提出图像生成模型可撤销学习新框架,解决隐私与安全评估难题

Rethinking Machine Unlearning in Image Generation Models

  • 构建分层任务分类体系,明确不同撤销学习场景的实现路径
  • 设计多维度评估框架,涵盖五个关键指标验证撤销效果
  • 发布高质量数据集,支持算法评测与内容检测模型训练

随着图像生成模型的广泛应用,数据隐私与内容安全成为用户、服务提供方和政策制定者关注的重点。机器可撤销学习(MU)被视为一种成本效益高且有前景的解决方案。尽管已有进展,图像生成模型可撤销学习(IGMU)在实践中仍存在显著差距,如任务区分不明确、缺乏指导原则、评估框架缺失及指标不可靠等问题,阻碍了对撤销机制的理解与实用算法的设计。本文对现有先进算法与评估标准进行系统评估,发现IGMU任务中存在若干关键缺陷与挑战。基于此,我们做出三项核心贡献:(1)提出CatIGMU,一个新型分层任务分类框架,为IGMU提供具体实现指导,助力算法设计与测试环境搭建;(2)引入EvalIGMU,一个包含五个关键维度的综合评估框架,具备可靠定量指标;(3)构建DataIGM,一个高质量可撤销学习数据集,可用于广泛评估IGMU算法、训练内容检测器并作为基准测试平台。结合EvalIGMU与DataIGM,我们发现多数现有IGMU算法在不同评估维度上表现不佳,尤其在保留性与鲁棒性方面问题突出。代码与模型已开源。

原文摘要 · Abstract (English)

With the surge and widespread application of image generation models, data privacy and content safety have become major concerns and attracted great attention from users, service providers, and policymakers. Machine unlearning (MU) is recognized as a cost-effective and promising means to address these challenges. Despite some advancements, image generation model unlearning (IGMU) still faces remarkable gaps in practice, e.g., unclear task discrimination and unlearning guidelines, lack of an effective evaluation framework, and unreliable evaluation metrics. These can hinder the understanding of unlearning mechanisms and the design of practical unlearning algorithms. We perform exhaustive assessments over existing state-of-the-art unlearning algorithms and evaluation standards, and discover several critical flaws and challenges in IGMU tasks. Driven by these limitations, we make several core contributions, to facilitate the comprehensive understanding, standardized categorization, and reliable evaluation of IGMU. Specifically, (1) We design CatIGMU, a novel hierarchical task categorization framework. It provides detailed implementation guidance for IGMU, assisting in the design of unlearning algorithms and the construction of testbeds. (2) We introduce EvalIGMU, a comprehensive evaluation framework. It includes reliable quantitative metrics across five critical aspects. (3) We construct DataIGM, a high-quality unlearning dataset, which can be used for extensive evaluations of IGMU, training content detectors for judgment, and benchmarking the state-of-the-art unlearning algorithms. With EvalIGMU and DataIGM, we discover that most existing IGMU algorithms cannot handle the unlearning well across different evaluation dimensions, especially for preservation and robustness. Code and models are available at https://github.com/ryliu68/IGMU.

图像生成可撤销学习隐私安全评估框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。