arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

机器遗忘作为私有追溯算法

Machine Unlearning as Private Retroactive Algorithms

Haim Kaplan, Refael Kohen, Yishay Mansour, Kobbi Nissim, Uri Stemmer

arXiv 2609.05329首次发表:更新:

AI 中文总结

该研究将机器遗忘转化为私有追溯算法问题,结合追溯性与持续观察下的差分隐私,在不额外增加渐近成本的前提下实现线性统计等任务的隐私性与追溯性,并给出不可能性结果。

AI 中文摘要

机器遗忘通常旨在模拟从头开始重新训练:在收到删除请求时,遗忘算法应产生若从未包含被删除数据点本会得到的结果。近期研究表明,这种模拟要求针对观察一系列发布内容的对手不具备有意义的隐私语义。因此机器遗忘本身并非隐私问题,而是数据维护问题,这正是追溯算法的研究主题。追溯算法支持修改过去的操作,保证所有后续答案反映修订后的历史,仿佛该历史一直有效。我们提出私有追溯算法的定义,将追溯性要求与持续观察下的差分隐私相结合。我们给出的构造在不超过仅实现隐私的渐近成本下,可同时满足线性统计、聚类和直方图的隐私性与追溯性,同时还给出了相关的不可能性结果。

英文摘要

Machine unlearning typically aims to emulate retraining from scratch: upon a deletion request, the unlearning algorithm should produce an outcome that would have been obtained had the deleted point never been included. Recent work has shown that this emulation requirement carries no meaningful privacy semantics against an adversary who observes a sequence of releases. Machine unlearning is thus not a privacy question per se, but rather a data maintenance question, which is precisely the subject of retroactive algorithms. These are algorithms supporting modifications of past operations, guaranteeing that all subsequent answers reflect the revised history as if it had always been in force. We put forward a definition of private retroactive algorithms, combining the retroactivity requirement with differential privacy under continual observation. We present constructions achieving both privacy and retroactivity at no asymptotic cost over privacy alone for linear statistics, clustering, and histograms, alongside impossibility results.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑