首次系统梳理机器遗忘验证方法,解决模型删数据后是否真正遗忘的难题。
Towards Reliable Forgetting: A Survey on Machine Unlearning Verification
- 按行为与参数两类证据分类,构建遗忘验证统一框架。
- 指出现有方法在实际部署中的潜在漏洞与不足。
- 适合关注模型隐私合规与可信机器学习的研究者参考。
随着对隐私保护、安全及法律合规(如GDPR)需求的增长,机器遗忘已成为确保机器学习模型可控性与监管一致性的关键技术。然而,该领域面临的核心挑战在于如何有效验证遗忘操作是否已成功且彻底执行。尽管遗忘技术研究日益丰富,但验证方法仍相对匮乏且分散,缺乏统一分类与系统评估框架。本文首次提出机器遗忘验证的结构化综述,构建基于证据类型的分类体系,将现有方法分为行为验证与参数验证两大类。分析各类代表性方法的假设、优势与局限,并揭示实际部署中的潜在风险。最后,提出当前验证研究中的若干开放问题,旨在为发展更鲁棒、高效且理论坚实的遗忘验证机制奠定基础。
原文摘要 · Abstract (English)
With growing demands for privacy protection, security, and legal compliance (e.g., GDPR), machine unlearning has emerged as a critical technique for ensuring the controllability and regulatory alignment of machine learning models. However, a fundamental challenge in this field lies in effectively verifying whether unlearning operations have been successfully and thoroughly executed. Despite a growing body of work on unlearning techniques, verification methodologies remain comparatively underexplored and often fragmented. Existing approaches lack a unified taxonomy and a systematic framework for evaluation. To bridge this gap, this paper presents the first structured survey of machine unlearning verification methods. We propose a taxonomy that organizes current techniques into two principal categories -- behavioral verification and parametric verification -- based on the type of evidence used to assess unlearning fidelity. We examine representative methods within each category, analyze their underlying assumptions, strengths, and limitations, and identify potential vulnerabilities in practical deployment. In closing, we articulate a set of open problems in current verification research, aiming to provide a foundation for developing more robust, efficient, and theoretically grounded unlearning verification mechanisms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。