SCOPE:面向无数据源类别遗忘的纠缠前沿逃逸
SCOPE: Entanglement Frontier Escape for Source-Free Class Unlearning
浏览论文内容
中文总结 AI 辅助
针对无数据源类别遗忘的特征干扰问题,提出SCOPE方法,通过条件投影擦除逃逸特征空间的干扰前沿,在多基准上性能优于现有无数据源擦除器及训练式遗忘器。
中文摘要 AI 辅助
无数据源类别遗忘仅使用遗忘数据在表征层面擦除整个类别,而特征可能泄漏头部不再预测的类别。现有特征空间擦除器采用单一固定投影,但遗忘类别与保留类别共享表征,删除一个会干扰两者重叠区域。我们证明这种张力是一个前沿:每个删除的固定投影至少会产生沿遗忘判别子空间的保留读出能量的保留代价,仅删除该子空间可达到下限。主流无数据源擦除器均采用该形式,故该前沿限制了整个类别。将擦除条件设置为输入可逃逸该前沿,谱条件投影擦除(SCOPE)通过单个门实现,仅在冻结头部权重评分判定为遗忘类别的输入上主要抑制遗忘子空间,它是闭式形式,无需保留数据或梯度训练,成本比重训低几个数量级。在涵盖两个模态、卷积和Transformer骨干的五个物体、人脸、说话人基准上,该前沿可预测测得的保留代价;SCOPE在所有基准及所有遗忘集大小上均领先无数据源擦除器,在最难设置下也优于所有遗忘器,包括训练方法。
英文摘要
Source-free class unlearning erases whole classes using only the forget data, judged at the representation level, where features can leak a class the head no longer predicts. Existing feature-space erasers answer with one fixed projection, yet forget and retain classes share a representation, so deleting one disturbs the other where they overlap. We prove this tension is a frontier. Every fixed projection that deletes pays a retain cost of at least the retain-readout energy along the forget-discriminant subspace, and erasing that subspace alone attains the floor. The leading source-free erasers all instantiate the form it binds, so the frontier limits the whole class. Conditioning the erasure on the input escapes it. Spectral Conditional Projective Erasure (SCOPE) does so with a single gate, suppressing the forget subspace chiefly on inputs its frozen head's weight scores read as a forget class. It is closed form, needs no retain data or gradient training, and costs orders of magnitude less than retraining. Across five object, face, and speaker benchmarks spanning two modalities and both convolutional and transformer backbones, the frontier predicts the measured retain cost. SCOPE leads the source-free erasers on every benchmark and forget-set size, and at the hardest setting it tops every unlearner, trained methods included.