arXiv:2602.15602cs.LGstat.ML2026-02

按数据点个体贡献动态加噪,实现更高效的可信删数

Certified Per-Instance Unlearning Using Individual Sensitivity Bounds

  • 根据每个数据点对模型的影响程度动态调整噪声
  • 理论证明在岭回归中可大幅减少所需噪声量
  • 适合需要严格数据删除保障的场景,如合规性要求高的应用

通过噪声注入实现可信机器删数,传统方法基于最坏情况敏感度校准噪声,导致性能下降。本文提出一种基于个体数据点贡献的自适应噪声校准方法,解决机制依赖待删除数据点的挑战。针对通过朗之万动力学训练的岭回归,推导出高概率的个体敏感度边界,实现显著降低噪声注入的可信删数。在线性设置中验证理论结果,并在深度学习设置中提供进一步实证支持。

原文摘要 · Abstract (English)

Certified machine unlearning can be achieved via noise injection leading to differential privacy guarantees, where noise is calibrated to worst-case sensitivity. Such conservative calibration often results in performance degradation, limiting practical applicability. In this work, we investigate an alternative approach based on adaptive per-instance noise calibration tailored to the individual contribution of each data point to the learned solution. This raises the following challenge: how can one establish formal unlearning guarantees when the mechanism depends on the specific point to be removed? To define individual data point sensitivities in noisy gradient dynamics, we consider the use of per-instance differential privacy. For ridge regression trained via Langevin dynamics, we derive high-probability per-instance sensitivity bounds, yielding certified unlearning with substantially less noise injection. We corroborate our theoretical findings through experiments in linear settings and provide further empirical evidence on the relevance of the approach in deep learning settings.

删数差分隐私自适应噪声

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。