On the Necessity of Auditable Algorithmic Definitions for Machine
  Unlearning
        - URL: http://arxiv.org/abs/2110.11891v1
- Date: Fri, 22 Oct 2021 16:16:56 GMT
- Title: On the Necessity of Auditable Algorithmic Definitions for Machine
  Unlearning
- Authors: Anvith Thudi, Hengrui Jia, Ilia Shumailov, Nicolas Papernot
- Abstract summary: Machine unlearning, i.e. having a model forget about some of its training data, has become increasingly important as privacy legislation promotes variants of the right-to-be-forgotten.
We first show that the definition that underlies approximate unlearning, which seeks to prove the approximately unlearned model is close to an exactly retrained model, is incorrect because one can obtain the same model using different datasets.
We then turn to exact unlearning approaches and ask how to verify their claims of unlearning.
- Score: 13.149070833843133
- License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
- Abstract:   Machine unlearning, i.e. having a model forget about some of its training
data, has become increasingly more important as privacy legislation promotes
variants of the right-to-be-forgotten. In the context of deep learning,
approaches for machine unlearning are broadly categorized into two classes:
exact unlearning methods, where an entity has formally removed the data point's
impact on the model by retraining the model from scratch, and approximate
unlearning, where an entity approximates the model parameters one would obtain
by exact unlearning to save on compute costs. In this paper we first show that
the definition that underlies approximate unlearning, which seeks to prove the
approximately unlearned model is close to an exactly retrained model, is
incorrect because one can obtain the same model using different datasets. Thus
one could unlearn without modifying the model at all. We then turn to exact
unlearning approaches and ask how to verify their claims of unlearning. Our
results show that even for a given training trajectory one cannot formally
prove the absence of certain data points used during training. We thus conclude
that unlearning is only well-defined at the algorithmic level, where an
entity's only possible auditable claim to unlearning is that they used a
particular algorithm designed to allow for external scrutiny during an audit.
 
      
        Related papers
        - Mirror Mirror on the Wall, Have I Forgotten it All? A New Framework for   Evaluating Machine Unlearning [15.37608643831483]
 Machine unlearning methods take a model trained on a dataset and a forget set, then attempt to produce a model as if it had only been trained on the examples not in the forget set.<n>We show that an adversary is able to distinguish between a mirror model and a model produced by an unlearning method.<n>We propose a strong formal definition for machine unlearning called computational unlearning.
 arXiv  Detail & Related papers  (2025-05-13T00:23:17Z)
- Provable unlearning in topic modeling and downstream tasks [36.571324268874264]
 Provable guarantees for unlearning are often limited to supervised learning settings.
We provide the first theoretical guarantees for unlearning in the pre-training and fine-tuning paradigm.
We show that it is easier to unlearn pre-training data from models that have been fine-tuned to a particular task, and one can unlearn this data without modifying the base model.
 arXiv  Detail & Related papers  (2024-11-19T16:04:31Z)
- RESTOR: Knowledge Recovery through Machine Unlearning [71.75834077528305]
 Large language models trained on web-scale corpora can memorize undesirable datapoints.
Many machine unlearning methods have been proposed that aim to 'erase' these datapoints from trained models.
We propose the RESTOR framework for machine unlearning based on the following dimensions.
 arXiv  Detail & Related papers  (2024-10-31T20:54:35Z)
- Attribute-to-Delete: Machine Unlearning via Datamodel Matching [65.13151619119782]
 Machine unlearning -- efficiently removing a small "forget set" training data on a pre-divertrained machine learning model -- has recently attracted interest.
Recent research shows that machine unlearning techniques do not hold up in such a challenging setting.
 arXiv  Detail & Related papers  (2024-10-30T17:20:10Z)
- UnUnlearning: Unlearning is not sufficient for content regulation in   advanced generative AI [50.61495097098296]
 We revisit the paradigm in which unlearning is used for Large Language Models (LLMs)
We introduce a concept of ununlearning, where unlearned knowledge gets reintroduced in-context.
We argue that content filtering for impermissible knowledge will be required and even exact unlearning schemes are not enough for effective content regulation.
 arXiv  Detail & Related papers  (2024-06-27T10:24:35Z)
- An Information Theoretic Approach to Machine Unlearning [45.600917449314444]
 Key challenge in unlearning is forgetting the necessary data in a timely manner, while preserving model performance.
In this work, we address the zero-shot unlearning scenario, whereby an unlearning algorithm must be able to remove data given only a trained model and the data to be forgotten.
We derive a simple but principled zero-shot unlearning method based on the geometry of the model.
 arXiv  Detail & Related papers  (2024-02-02T13:33:30Z)
- Unlearnable Algorithms for In-context Learning [36.895152458323764]
 In this paper, we focus on efficient unlearning methods for the task adaptation phase of a pretrained large language model.
We observe that an LLM's ability to do in-context learning for task adaptation allows for efficient exact unlearning of task adaptation training data.
We propose a new holistic measure of unlearning cost which accounts for varying inference costs.
 arXiv  Detail & Related papers  (2024-02-01T16:43:04Z)
- Learn to Unlearn for Deep Neural Networks: Minimizing Unlearning
  Interference with Gradient Projection [56.292071534857946]
 Recent data-privacy laws have sparked interest in machine unlearning.
Challenge is to discard information about the forget'' data without altering knowledge about remaining dataset.
We adopt a projected-gradient based learning method, named as Projected-Gradient Unlearning (PGU)
We provide empirically evidence to demonstrate that our unlearning method can produce models that behave similar to models retrained from scratch across various metrics even when the training dataset is no longer accessible.
 arXiv  Detail & Related papers  (2023-12-07T07:17:24Z)
- In-Context Unlearning: Language Models as Few Shot Unlearners [27.962361828354716]
 We propose a new class of unlearning methods for Large Language Models (LLMs)
This method unlearns instances from the model by simply providing specific kinds of inputs in context, without the need to update model parameters.
Our experimental results demonstrate that in-context unlearning performs on par with, or in some cases outperforms other state-of-the-art methods that require access to model parameters.
 arXiv  Detail & Related papers  (2023-10-11T15:19:31Z)
- Learning to Unlearn: Instance-wise Unlearning for Pre-trained
  Classifiers [71.70205894168039]
 We consider instance-wise unlearning, of which the goal is to delete information on a set of instances from a pre-trained model.
We propose two methods that reduce forgetting on the remaining data: 1) utilizing adversarial examples to overcome forgetting at the representation-level and 2) leveraging weight importance metrics to pinpoint network parameters guilty of propagating unwanted information.
 arXiv  Detail & Related papers  (2023-01-27T07:53:50Z)
- Verifiable and Provably Secure Machine Unlearning [44.142771334058715]
 Machine unlearning aims to remove points from the training dataset of a machine learning model after training.
We present the first cryptographic definition of verifiable unlearning to formally capture the guarantees of an unlearning system.
We implement the protocol for three different unlearning techniques and validate its feasibility for linear regression, logistic regression, and neural networks.
 arXiv  Detail & Related papers  (2022-10-17T14:19:52Z)
- Forget Unlearning: Towards True Data-Deletion in Machine Learning [18.656957502454592]
 We show that unlearning is not equivalent to data deletion and does not guarantee the "right to be forgotten"
We propose an accurate, computationally efficient, and secure data-deletion machine learning algorithm in the online setting.
 arXiv  Detail & Related papers  (2022-10-17T10:06:11Z)
- Machine Unlearning of Features and Labels [72.81914952849334]
 We propose first scenarios for unlearning and labels in machine learning models.
Our approach builds on the concept of influence functions and realizes unlearning through closed-form updates of model parameters.
 arXiv  Detail & Related papers  (2021-08-26T04:42:24Z)
This list is automatically generated from the titles and abstracts of the papers in this site.
       
     
           This site does not guarantee the quality of this site (including all information) and is not responsible for any consequences.