通过分步注入噪声提升可认证遗忘的实用性
Sequential Subspace Noise Injection Prevents Accuracy Collapse in Certified Unlearning
- 将噪声按正交子空间逐步注入,避免一次性注入导致精度下降
- 在图像分类任务上,遗忘后准确率显著提升且仍抵御成员推断攻击
- 适合关注隐私保护与模型实用性的研究者和开发者
基于差分隐私的可认证遗忘提供强保障,但目前仍不实用:现有带噪微调方法虽能实现这些保障,却严重降低模型精度。本文提出顺序噪声调度策略,将噪声预算分布在参数空间的正交子空间中,而非一次性注入。这一简单改进有效缓解了噪声的破坏性,同时保持原始认证保证。我们扩展了带噪微调的分析至子空间设置,证明相同的 $(\varepsilon,δ)$ 隐私预算得以保留。在图像分类基准上的实验表明,该方法在遗忘后显著提升准确率,且对成员推断攻击仍具鲁棒性。结果表明,可认证遗忘可同时实现严格保障与实际可用性。
原文摘要 · Abstract (English)
Certified unlearning based on differential privacy offers strong guarantees but remains largely impractical: the noisy fine-tuning approaches proposed so far achieve these guarantees but severely reduce model accuracy. We propose sequential noise scheduling, which distributes the noise budget across orthogonal subspaces of the parameter space, rather than injecting it all at once. This simple modification mitigates the destructive effect of noise while preserving the original certification guarantees. We extend the analysis of noisy fine-tuning to the subspace setting, proving that the same $(\varepsilon,δ)$ privacy budget is retained. Empirical results on image classification benchmarks show that our approach substantially improves accuracy after unlearning while remaining robust to membership inference attacks. These results show that certified unlearning can achieve both rigorous guarantees and practical utility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。