arXiv:2511.13116cs.LGcs.AI2025-11AAAI被引 3

无需原始数据即可高效删除模型中的特定信息,保护隐私。

Synthetic Forgetting without Access: A Few-shot Zero-glance Framework for Machine Unlearning

  • 用生成网络合成遗忘样本,诱导模型遗忘目标类别知识。
  • 仅用5%保留数据,实现类级遗忘且保持其他类别性能。
  • 适合数据受限场景下的隐私保护机器学习应用。

机器遗忘旨在消除模型中特定数据的影响以保障隐私合规。然而,现有方法通常假设可访问原始训练数据,这在实践中往往不现实。本文针对更真实但更具挑战性的“少样本零接触”场景——仅能获取少量保留数据,且完全无法访问需遗忘的数据——提出GFOES框架。该框架包含生成反馈网络(GFN)和两阶段微调机制。GFN生成最优擦除样本(OES),在目标类别上引发高损失,使模型在无原始遗忘数据的情况下遗忘特定知识,同时保持对保留类别的性能。两阶段微调先实现激进遗忘,再恢复模型实用性。在三个图像分类数据集上的实验表明,GFOES在逻辑输出和表征层面均实现了有效遗忘,仅使用5%的原始数据即可维持强性能。本框架为数据受限条件下的隐私保护机器学习提供了实用且可扩展的解决方案。

原文摘要 · Abstract (English)

Machine unlearning aims to eliminate the influence of specific data from trained models to ensure privacy compliance. However, most existing methods assume full access to the original training dataset, which is often impractical. We address a more realistic yet challenging setting: few-shot zero-glance, where only a small subset of the retained data is available and the forget set is entirely inaccessible. We introduce GFOES, a novel framework comprising a Generative Feedback Network (GFN) and a two-phase fine-tuning procedure. GFN synthesises Optimal Erasure Samples (OES), which induce high loss on target classes, enabling the model to forget class-specific knowledge without access to the original forget data, while preserving performance on retained classes. The two-phase fine-tuning procedure enables aggressive forgetting in the first phase, followed by utility restoration in the second. Experiments on three image classification datasets demonstrate that GFOES achieves effective forgetting at both logit and representation levels, while maintaining strong performance using only 5% of the original data. Our framework offers a practical and scalable solution for privacy-preserving machine learning under data-constrained conditions.

机器遗忘隐私保护生成模型少样本学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。