arXiv:2601.06967cs.LGcs.CR2026-01

提出新方法应对数据删除非独立同分布时的可信遗忘问题

A Robust Certified Machine Unlearning Method Under Distribution Shift

  • 基于信任区域约束的迭代牛顿法,感知数据分布变化
  • 在分布偏移下仍保持高效且可靠的(ε, δ)可信遗忘
  • 适合需要合规性保障的实际系统,如隐私保护场景

现有基于牛顿法的可信遗忘方法依赖于请求删除的数据为独立同分布(i.i.d.)的假设。然而,实际中删除请求往往存在偏差,导致原始与保留数据集间出现分布偏移,使现有方法失效。本文指出,在非 i.i.d. 删除情况下,牛顿法的可信遗忘效率和有效性显著下降。为此,我们提出一种分布感知的可信遗忘框架,通过受信任区域约束的迭代牛顿更新,更贴近重新训练模型,并获得更紧的梯度残差预运行界,从而实现高效的 (ε, δ)-可信遗忘。我们在多个评估指标上进行了广泛实验,验证了该方法在分布偏移下的实用性与全面性能。

原文摘要 · Abstract (English)

The Newton method has been widely adopted to achieve certified unlearning. A critical assumption in existing approaches is that the data requested for unlearning are selected i.i.d.(independent and identically distributed). However,the problem of certified unlearning under non-i.i.d. deletions remains largely unexplored. In practice, unlearning requests are inherently biased, leading to non-i.i.d. deletions and causing distribution shifts between the original and retained datasets. In this paper, we show that certified unlearning with the Newton method becomes inefficient and ineffective under non-i.i.d. unlearning sets. We then propose a better certified unlearning approach by performing a distribution-aware certified unlearning framework based on iterative Newton updates constrained by a trust region. Our method provides a closer approximation to the retrained model and yields a tighter pre-run bound on the gradient residual, thereby ensuring efficient (epsilon, delta)-certified unlearning. To demonstrate its practical effectiveness under distribution shift, we also conduct extensive experiments across multiple evaluation metrics, providing a comprehensive assessment of our approach.

可信遗忘分布偏移牛顿法隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。