影响力衍生的数据扰动能否实现机器遗忘?对三种可能角色的受控研究
Do Influence-Derived Data Perturbations Enable Machine Unlearning? A Controlled Study of Three Plausible Roles
浏览论文内容
中文总结 AI 辅助
本研究通过受控实验评估深度扰动学习在机器遗忘中的三种角色,发现其无法直接删除数据,效用不稳定,且不如简单基线,并发布了评估协议与审计清单。
中文摘要 AI 辅助
我们评估了深度扰动学习(Deep Perturbation Learning, DPL),该方法沿影响力导出的方向扰动训练图像和标签,并在先前工作中将其定位用于机器遗忘的三种角色中:直接删除信号(最强主张)、保持效用的正则化器以及对抗性遗忘的暖启动。较弱角色的证据曾被用来支持较强的主张,因此我们在匹配协议下分别测试每种角色,并以精确种子重训练基线作为对照。对公开实现的审计发现了两个正确性问题:图像方向是在增强且归一化的张量上计算的,但应用于原始图像;标签扰动低于float32分辨率,导致标签保持不变。在修正图像扰动流程后,DPL在CIFAR-10/ResNet-18上所有三对配对种子中均未通过直接删除标准。其效用影响在不同种子间符号不一致,且一旦计入方向计算时间,其表现不如简单的暖启动基线。单种子Tiny ImageNet检查同样不支持DPL作为正则化器或暖启动;发布代码中的预处理不一致使得该处的直接比较无法得出结论。这些结果仅涵盖随机实例删除,并不排除基于影响力的方法在其他删除机制中的有效性。我们发布了角色匹配的评估协议和针对基于扰动的删除主张的审计清单。
英文摘要
We evaluate Deep Perturbation Learning (DPL), which perturbs training images and labels along influence-derived directions, in three roles in which prior work has positioned it for machine unlearning: a direct deletion signal (the strongest claim), a utility-preserving regularizer, and a warm start for adversarial unlearning. Evidence for the weaker roles has been used to support the stronger one, so we test each role separately under a matched protocol with exact-seed retraining baselines. An audit of the public implementation identifies two correctness issues: image directions are computed on augmented, normalized tensors but applied to raw images, and the label perturbation falls below float32 resolution, leaving labels unchanged. After correcting the image-perturbation pipeline, DPL fails the direct-deletion criterion on CIFAR-10/ResNet-18 in all three paired seeds. Its utility effects are inconsistent in sign across seeds, and once direction-computation time is counted it underperforms simple warm-start baselines. A one-seed Tiny ImageNet check likewise does not favor DPL as a regularizer or warm start; preprocessing inconsistencies in the released code make the direct comparison there inconclusive. These results cover random instance deletion only and do not rule out influence-based methods in other deletion regimes. We release a role-matched evaluation protocol and an audit checklist for perturbation-based deletion claims.
发表机构
- Monash University(莫纳什大学)
- LibrAI
- Tongji University(同济大学)
- Shanghai Ocean University(上海海洋大学)
机构由 AI 辅助整理,请以论文原文为准。