无需原始数据即可高效删除模型中的特定信息,保障隐私合规。
Towards Source-Free Machine Unlearning
- 通过估计未知数据的海森矩阵实现无源遗忘
- 零样本遗忘下仍保持模型性能,理论保证强
- 适合数据不可复现的隐私保护场景
随着机器学习普及和数据隐私法规演进,从训练好的模型中移除敏感或受版权保护的信息变得愈发重要。现有遗忘方法通常假设可访问完整训练数据,但在实际中原始数据可能不可用,即无源场景。本文聚焦于无源遗忘问题,提出一种算法可在不依赖原始训练数据的前提下,从已训练模型中删除特定数据。基于最新研究,我们提出一种能够估计未知剩余训练数据海森矩阵的方法,这是高效遗忘的关键。利用该估计技术,我们的方法实现了高效的零样本遗忘,并在遗忘性能上提供稳健的理论保障,同时保持对剩余数据的性能。在多种数据集上的大量实验验证了方法的有效性。
原文摘要 · Abstract (English)
As machine learning becomes more pervasive and data privacy regulations evolve, the ability to remove private or copyrighted information from trained models is becoming an increasingly critical requirement. Existing unlearning methods often rely on the assumption of having access to the entire training dataset during the forgetting process. However, this assumption may not hold true in practical scenarios where the original training data may not be accessible, i.e., the source-free setting. To address this challenge, we focus on the source-free unlearning scenario, where an unlearning algorithm must be capable of removing specific data from a trained model without requiring access to the original training dataset. Building on recent work, we present a method that can estimate the Hessian of the unknown remaining training data, a crucial component required for efficient unlearning. Leveraging this estimation technique, our method enables efficient zero-shot unlearning while providing robust theoretical guarantees on the unlearning performance, while maintaining performance on the remaining data. Extensive experiments over a wide range of datasets verify the efficacy of our method.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。