arXiv:2602.16697cs.LGcs.DS2026-02被引 1

机器遗忘存在隐私漏洞,删除数据可能泄露未删除数据

Protecting the Undeleted in Machine Unlearning

  • 提出新安全定义,保护未删除数据免受删除操作泄露
  • 实验证明仅控少量数据点即可重建几乎全部数据
  • 适合关注数据隐私与机器学习安全的研究者

机器遗忘旨在从训练好的模型中移除特定数据点,通常追求模拟‘完美重训练’——即若原始数据从未被加入时应得到的模型。我们发现,此类方法及其安全定义对剩余(未删除)数据点带来显著隐私风险。通过构造重构攻击,我们证明在某些任务中,即使攻击者仅控制 ω(1) 个数据点,也能仅通过发起删除请求,重建几乎整个数据集。我们调研了现有机器遗忘的安全定义,发现它们要么易受此类攻击,要么过于严格而无法支持基本功能(如精确求和)。为此,我们提出一种新安全定义,专门保护未删除数据不因其他数据的删除而泄露。我们证明该定义可支持多种核心功能,如公告板、求和运算和统计学习。

原文摘要 · Abstract (English)

Machine unlearning aims to remove specific data points from a trained model, often striving to emulate "perfect retraining", i.e., producing the model that would have been obtained had the deleted data never been included. We demonstrate that this approach, and security definitions that enable it, carry significant privacy risks for the remaining (undeleted) data points. We present a reconstruction attack showing that for certain tasks, which can be computed securely without deletions, a mechanism adhering to perfect retraining allows an adversary controlling merely $ω(1)$ data points to reconstruct almost the entire dataset merely by issuing deletion requests. We survey existing definitions for machine unlearning, showing they are either susceptible to such attacks or too restrictive to support basic functionalities like exact summation. To address this problem, we propose a new security definition that specifically safeguards undeleted data against leakage caused by the deletion of other points. We show that our definition permits several essential functionalities, such as bulletin boards, summations, and statistical learning.

机器遗忘隐私保护数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。