arXiv:2511.08191cs.AI2025-11

通过最大化贝叶斯误差,构造出无法被模型学习的可信数据实例。

Towards Provably Unlearnable Examples via Bayes Error Optimisation

  • 基于贝叶斯误差最大化,系统性生成不可学习数据。
  • 在混合干净数据场景下仍能保持不可学习性,且可证明有效。
  • 适用于隐私保护场景,适合关注数据安全的研究者。

机器学习模型的成功依赖于大规模数据训练,而这些数据常来自网络来源,引发用户数据隐私担忧。为应对这一问题,研究提出‘不可学习样本’概念:看似自然但经刻意修改的数据,使模型难以从中学习。现有方法多依赖经验试错,缺乏理论保证,且在与真实数据混合时失效。本文提出一种新方法,通过系统性最大化贝叶斯误差(不可约分类误差)来构造不可学习样本。我们设计了基于优化的算法,并采用投影梯度上升实现高效求解。该方法可严格证明提升贝叶斯误差,在与真实数据混合时仍保持有效性。跨多个数据集和模型架构的实验结果与理论分析一致,验证了该方法在实践中有效限制数据可学习性。

原文摘要 · Abstract (English)

The recent success of machine learning models, especially large-scale classifiers and language models, relies heavily on training with massive data. These data are often collected from online sources. This raises serious concerns about the protection of user data, as individuals may not have given consent for their data to be used in training. To address this concern, recent studies introduce the concept of unlearnable examples, i.e., data instances that appear natural but are intentionally altered to prevent models from effectively learning from them. While existing methods demonstrate empirical effectiveness, they typically rely on heuristic trials and lack formal guarantees. Besides, when unlearnable examples are mixed with clean data, as is often the case in practice, their unlearnability disappears. In this work, we propose a novel approach to constructing unlearnable examples by systematically maximising the Bayes error, a measurement of irreducible classification error. We develop an optimisation-based approach and provide an efficient solution using projected gradient ascent. Our method provably increases the Bayes error and remains effective when the unlearning examples are mixed with clean samples. Experimental results across multiple datasets and model architectures are consistent with our theoretical analysis and show that our approach can restrict data learnability, effectively in practice.

隐私保护不可学习贝叶斯误差

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。