arXiv:2601.06436cs.LGstat.ML2026-01被引 2

提出去中心化联邦学习中可认证的数据删除方法,解决隐私遗忘难题。

Certified Unlearning in Decentralized Federated Learning

  • 基于牛顿型更新量化数据影响传播,用费舍尔矩阵近似二阶信息
  • 通过带校准噪声的修正更新消除网络中残留影响,实现可证明删除
  • 适用于需要合规删除数据的去中心化场景,如医疗、金融联邦系统

受“被遗忘权”驱动,机器遗忘已成为隐私保护机器学习的关键需求。然而,在去中心化联邦学习(DFL)中其实践仍基本空白。在DFL中,客户端仅与邻接节点交换本地更新,导致模型信息在网络中传播混合。当某客户端请求删除数据时,其影响已隐式嵌入整个系统,若无中心协调则难以清除。本文提出一种基于牛顿型更新的新型可认证遗忘框架。首先量化数据影响在训练过程中的传播路径;利用损失函数对目标数据的曲率信息,构建牛顿型近似的修正更新;为保证可扩展性,通过费舍尔信息矩阵近似二阶信息。最终将带校准噪声的更新广播至网络,消除各客户端间的残留影响。理论上证明该方法满足可认证遗忘的形式定义,使遗忘后的模型难以与无删改数据重训练模型区分。同时建立效用边界,表明遗忘模型仍接近从零开始重训练的结果。在多种去中心化设置下的实验验证了该框架的有效性与高效性。

原文摘要 · Abstract (English)

Driven by the right to be forgotten (RTBF), machine unlearning has become an essential requirement for privacy-preserving machine learning. However, its realization in decentralized federated learning (DFL) remains largely unexplored. In DFL, clients exchange local updates only with neighbors, causing model information to propagate and mix across the network. As a result, when a client requests data deletion, its influence is implicitly embedded throughout the system, making removal difficult without centralized coordination. We propose a novel certified unlearning framework for DFL based on Newton-style updates. Our approach first quantifies how a client's data influence propagates during training. Leveraging curvature information of the loss with respect to the target data, we then construct corrective updates using Newton-style approximations. To ensure scalability, we approximate second-order information via Fisher information matrices. The resulting updates are perturbed with calibrated noise and broadcast through the network to eliminate residual influence across clients. We theoretically prove that our approach satisfies the formal definition of certified unlearning, ensuring that the unlearned model is difficult to distinguish from a retrained model without the deleted data. We also establish utility bounds showing that the unlearned model remains close to retraining from scratch. Extensive experiments across diverse decentralized settings demonstrate the effectiveness and efficiency of our framework.

联邦学习数据删除隐私保护可认证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。