arXiv:2604.04030cs.CRcs.LG2026-04被引 1

无需用户数据即可删除模型中特定信息,保护隐私同时保持模型性能。

Jellyfish: Zero-Shot Federated Unlearning Scheme with Knowledge Disentanglement

  • 用噪声生成代理数据实现零样本遗忘,不依赖原始训练数据。
  • 通过通道激活稀疏化与多损失协同优化,平衡遗忘与保留效果。
  • 适用于需快速删除敏感数据的联邦学习场景,如医疗、金融领域。

随着数据隐私与安全的重要性日益提升,联邦遗忘作为新研究方向,致力于确保一旦特定数据被删除,联邦学习模型不再保留或泄露相关信息。本文提出一种零样本联邦遗忘方案Jellyfish,其在四个关键方面区别于传统框架:合成数据生成、知识解耦、损失函数设计与模型修复。为保护被遗忘数据的隐私,设计了零样本遗忘机制,以最小化误差的噪声作为被遗忘数据的代理数据。为维持模型效用,首次提出知识解耦机制,通过限制被遗忘数据在最终卷积层的激活通道数并鼓励激活稀疏性来正则化输出。进一步构建包含硬损失、混淆损失、知识蒸馏损失、权重漂移损失、梯度调和与梯度掩码的综合损失函数,有效对齐‘遗忘’与‘保留’的目标学习轨迹。最后,提出零样本修复机制,利用代理数据在不访问用户本地数据的情况下恢复模型准确率至可接受范围。在多种设置下进行的全面实验验证了该方案的有效性与鲁棒性。

原文摘要 · Abstract (English)

With the increasing importance of data privacy and security, federated unlearning emerges as a new research field dedicated to ensuring that once specific data is deleted, federated learning models no longer retain or disclose related information. In this paper, we propose a zero-shot federated unlearning scheme, named Jellyfish. It distinguishes itself from conventional federated unlearning frameworks in four key aspects: synthetic data generation, knowledge disentanglement, loss function design, and model repair. To preserve the privacy of forgotten data, we design a zero-shot unlearning mechanism that generates error-minimization noise as proxy data for the data to be forgotten. To maintain model utility, we first propose a knowledge disentanglement mechanism that regularises the output of the final convolutional layer by restricting the number of activated channels for the data to be forgotten and encouraging activation sparsity. Next, we construct a comprehensive loss function that incorporates multiple components, including hard loss, confusion loss, distillation loss, model weight drift loss, gradient harmonization, and gradient masking, to effectively align the learning trajectories of the objectives of ``forgetting" and ``retaining". Finally, we propose a zero-shot repair mechanism that leverages proxy data to restore model accuracy within acceptable bounds without accessing users' local data. To evaluate the performance of the proposed zero-shot federated unlearning scheme, we conducted comprehensive experiments across diverse settings. The results validate the effectiveness and robustness of the scheme.

联邦学习数据删除隐私保护零样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。