审计机器遗忘时,隐私与可审计性存在不可调和的矛盾。
Behavioral Audit of Machine Unlearning Has a Privacy Cost

- 通过行为查询审计遗忘效果,会暴露数据成员信息
- 凸模型下,任何行为审计都会泄露保留数据隐私
- 适用于关注隐私审计设计的系统安全研究者
通过机器遗忘(MU)移除学习数据已被广泛研究,但尚无公认的审计方案。现有工作表明,恶意模型所有者可伪造证据规避遗忘,而好奇的审计者或攻击者即使访问有限,也能推断出模型及训练数据的敏感属性。然而,在模型所有者不诚实且审计者诚实但好奇的互信困境下,行为审计仍无解。本文提供信息论证明:对凸机器学习模型,仅依赖模型行为信号的通用审计方案,无法识别未充分遗忘的模型而不泄露保留数据集的成员信息。因此,在该威胁模型下,隐私与审计存在固有权衡。实证结果在凸模型上强烈支持该结论,进一步实验表明非凸模型也存在此张力。研究呼吁在现实审计威胁模型下更审慎对待隐私-审计矛盾,并为隐私保护审计方案的设计奠定基础。代码已开源:https://github.com/LiouTang/Behavioral-Unlearn-Audit。
原文摘要 · Abstract (English)
The removal of learned data from Machine Learning models through Machine Unlearning (MU) has been widely studied; however, there has yet to be an agreed-upon scheme for auditing MU. Existing work has shown that a dishonest model owner can falsify evidence to avoid executing MU, while curious auditors (and adversaries) can infer the privacy-sensitive properties of the model and its training data even with limited access. Yet auditing of MU under mutual distrust between the model owner and the auditor remains unexplored. We provide an information-theoretic proof for this scenario: for convex ML models, a generic audit scheme that relies solely on querying the model for \textit{behavioral} signals cannot identify insufficiently unlearned models without revealing membership information of the retained set. Therefore, auditing MU under the assumption of a dishonest model owner and an honest-but-curious auditor faces an inherent privacy-audit tradeoff. Our empirical results on convex models strongly supports this result, while further experiments demonstrate that this privacy-audit tension persists in non-convex models. Our results call for a more careful consideration of the privacy-audit tension under a realistic auditor threat model, and serve as a foundation for more scrutiny of designs of privacy-preserving audit schemes for the MU pipeline. We also release our code implementation at https://github.com/LiouTang/Behavioral-Unlearn-Audit.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。