arXiv:2506.06486cs.LGcs.CR2025-06ICML被引 9

无需原始数据即可安全删除模型中的特定信息,保障隐私。

A Certified Unlearning Approach without Access to Source Data

  • 用近似数据集模拟原始数据统计特性,实现无原始数据的可验证删数。
  • 理论保证强,实际中通过噪声调节仍保持有效隐私保护。
  • 适合需要合规删数但无法获取原始数据的场景,如医疗或金融模型。

随着数据隐私法规日益严格,从训练好的模型中移除私人或受版权保护的信息已成为关键需求。传统去学习方法通常依赖完整的训练数据集,但在源数据不可用的情况下不现实。为此,我们提出一种可验证的去学习框架,可在不访问原始训练数据样本的情况下实现有效的数据移除。该方法利用一个代理数据集来近似源数据的统计特性,基于两者的统计距离进行可控的噪声调整。尽管理论保证依赖于精确的统计距离,实际中该距离通常被近似,导致隐私保证略弱但仍具意义。该方法确保了去学习后模型行为的强保障,同时保持其整体性能。我们建立了理论边界,提出了实用的噪声校准技术,并在合成与真实数据集上进行了大量实验验证。结果表明,该方法在隐私敏感场景中具有高效性和可靠性。

原文摘要 · Abstract (English)

With the growing adoption of data privacy regulations, the ability to erase private or copyrighted information from trained models has become a crucial requirement. Traditional unlearning methods often assume access to the complete training dataset, which is unrealistic in scenarios where the source data is no longer available. To address this challenge, we propose a certified unlearning framework that enables effective data removal \final{without access to the original training data samples}. Our approach utilizes a surrogate dataset that approximates the statistical properties of the source data, allowing for controlled noise scaling based on the statistical distance between the two. \updated{While our theoretical guarantees assume knowledge of the exact statistical distance, practical implementations typically approximate this distance, resulting in potentially weaker but still meaningful privacy guarantees.} This ensures strong guarantees on the model's behavior post-unlearning while maintaining its overall utility. We establish theoretical bounds, introduce practical noise calibration techniques, and validate our method through extensive experiments on both synthetic and real-world datasets. The results demonstrate the effectiveness and reliability of our approach in privacy-sensitive settings.

去学习隐私保护模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。