arXiv:2508.18671cs.LGcs.AI2025-08中稿 · ICDM2025,10pages被引 5

检验差分隐私模型在近似遗忘后,保留数据的隐私是否仍受保护。

Auditing Approximate Machine Unlearning for Differentially Private Models

  • 从差分隐私和成员推断攻击双视角构建审计标准。
  • 发现现有遗忘方法可能泄露保留数据隐私,需专用私有遗忘算法。
  • 提出高效成员推断攻击A-LiRA,降低影子模型训练成本。

近似机器遗忘旨在移除特定数据对已训练模型的影响以保障个人隐私。现有方法聚焦于被移除记录,假设保留样本不受影响。然而,近期关于‘隐私洋葱效应’的研究表明这一假设可能不成立。尤其当模型具备差分隐私时,尚无研究探讨保留样本在现有机器遗忘方法下是否仍满足差分隐私(DP)标准。本文采用整体视角,审计应用近似遗忘算法后未学习与保留样本的隐私风险。基于差分隐私和成员推断攻击(MIAs)视角,分别提出未学习与保留样本的隐私准则。为提升审计实用性,我们开发了一种高效成员推断攻击A-LiRA,利用数据增强降低影子模型训练开销。实验结果表明,现有近似遗忘算法可能无意中损害差分隐私模型中保留样本的隐私,亟需差分隐私保障的遗忘算法。代码已公开:https://anonymous.4open.science/r/Auditing-machine-unlearning-CB10/README.md

原文摘要 · Abstract (English)

Approximate machine unlearning aims to remove the effect of specific data from trained models to ensure individuals' privacy. Existing methods focus on the removed records and assume the retained ones are unaffected. However, recent studies on the \emph{privacy onion effect} indicate this assumption might be incorrect. Especially when the model is differentially private, no study has explored whether the retained ones still meet the differential privacy (DP) criterion under existing machine unlearning methods. This paper takes a holistic approach to auditing both unlearned and retained samples' privacy risks after applying approximate unlearning algorithms. We propose the privacy criteria for unlearned and retained samples, respectively, based on the perspectives of DP and membership inference attacks (MIAs). To make the auditing process more practical, we also develop an efficient MIA, A-LiRA, utilizing data augmentation to reduce the cost of shadow model training. Our experimental findings indicate that existing approximate machine unlearning algorithms may inadvertently compromise the privacy of retained samples for differentially private models, and we need differentially private unlearning algorithms. For reproducibility, we have pubished our code: https://anonymous.4open.science/r/Auditing-machine-unlearning-CB10/README.md

机器遗忘差分隐私成员推断攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。