arXiv:2512.16126cs.LGcs.CV2025-12AAAI被引 3

机器遗忘引发隐私泄露,双视角攻击可暴露保留数据

Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure

  • 通过对比原始与遗忘后模型,提取保留数据的成员信息
  • 新攻击方法无需训练模型,仅用轻量级比值推断即有效
  • 揭示遗忘技术反噬隐私的隐患,适合关注数据安全的研究者

机器遗忘是移除训练数据以响应删除请求的新技术,虽保护用户权利,却引入新隐私风险。现有研究多关注被遗忘数据的隐私,而对保留数据的风险几乎未探。本文首次在双视角设置下揭示机器遗忘带来的漏洞:攻击者可同时查询原始与遗忘模型,从信息论角度提出‘隐私知识增益’概念,证明其能获取比单独查询任一模型更多情报。为此,我们提出DVIA攻击方法,利用黑盒查询双模型,无需训练攻击模型,仅通过轻量级似然比推断模块实现高效推理。跨多种数据集与模型架构的实验验证了该攻击的有效性,凸显双视角场景下的隐私威胁。

原文摘要 · Abstract (English)

Machine unlearning is a newly popularized technique for removing specific training data from a trained model, enabling it to comply with data deletion requests. While it protects the rights of users requesting unlearning, it also introduces new privacy risks. Prior works have primarily focused on the privacy of data that has been unlearned, while the risks to retained data remain largely unexplored. To address this gap, we focus on the privacy risks of retained data and, for the first time, reveal the vulnerabilities introduced by machine unlearning under the dual-view setting, where an adversary can query both the original and the unlearned models. From an information-theoretic perspective, we introduce the concept of {privacy knowledge gain} and demonstrate that the dual-view setting allows adversaries to obtain more information than querying either model alone, thereby amplifying privacy leakage. To effectively demonstrate this threat, we propose DVIA, a Dual-View Inference Attack, which extracts membership information on retained data using black-box queries to both models. DVIA eliminates the need to train an attack model and employs a lightweight likelihood ratio inference module for efficient inference. Experiments across different datasets and model architectures validate the effectiveness of DVIA and highlight the privacy risks inherent in the dual-view setting.

隐私安全机器遗忘对抗攻击数据泄露

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。