软标签可泄露教师对记忆数据的隐含知识,学生能间接学到未见过的内容。
Dataset distillation for memorized data: Soft labels can leak held-out teacher knowledge
- 用软标签传递教师对记忆数据的预测,实现知识迁移
- 学生在未见数据上仍可达接近100%准确率
- 该现象对温度敏感,适用于多种模型与数据设置
数据集蒸馏旨在通过教师模型将训练数据压缩为更少样本,使学生能有效学习。尽管其成功常归因于数据结构,但现代神经网络也记忆特定事实,而这些记忆信息是否以及如何在蒸馏中传递仍不明确。本文发现,学生在教师提供的软标签指导下,可在从未直接观察过的记忆数据上取得非平凡的准确率。即使在结构化数据上,当教师未泛化时,该现象依然存在。为隔离分析,我们考虑有限独立同分布随机数据集,其中泛化本不可能,教师的成功拟合即意味着纯粹记忆。即便如此,学生仍能学到关于保留数据的非平凡信息,某些情况下可达完美准确率。在此类设置中,足够多的软标签可功能性还原教师模型——学生在所有可能输入上的预测与教师一致,包括保留的记忆数据。我们发现该现象强烈依赖于对数几率平滑的温度参数,但在不同网络容量、架构和数据组成下仍持续存在。
原文摘要 · Abstract (English)
Dataset distillation aims to compress training data into fewer examples via a teacher, from which a student can learn effectively. While its success is often attributed to structure in the data, modern neural networks also memorize specific facts, but if and how such memorized information is can transferred in distillation settings remains less understood. In this work, we show that students trained on soft labels from teachers can achieve non-trivial accuracy on held-out memorized data they never directly observed. This effect persists on structured data when the teacher has not generalized.To analyze it in isolation, we consider finite random i.i.d. datasets where generalization is a priori impossible and a successful teacher fit implies pure memorization. Still, students can learn non-trivial information about the held-out data, in some cases up to perfect accuracy. In those settings, enough soft labels are available to recover the teacher functionally - the student matches the teacher's predictions on all possible inputs, including the held-out memorized data. We show that these phenomena strongly depend on the temperature with which the logits are smoothed, but persist across varying network capacities, architectures and dataset compositions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。