基于Hessian分析的相关性引导快速机器遗忘
Correlation-Guided Fast Machine Unlearning via Hessian Analysis
- Indian Institute of Technology (Banaras Hindu University) Varanasi(印度理工学院(巴纳拉斯印度教大学)瓦拉纳西校区)
- Halmstad University(哈尔姆斯塔德大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对安全系统中机器遗忘计算开销大的问题,提出基于Hessian分析的相关性引导遗忘框架,利用闭式更新规则实现82倍加速,并在多个数据集上保持模型效用与遗忘效果。
AI中文摘要:
机器学习在网络和分布式安全系统中的日益普及,催生了对能够选择性地、高效地移除特定训练数据影响的机制的迫切需求,以从生产模型中消除被入侵或对抗性的数据点。诸如GDPR的“被遗忘权”等隐私法规也提出了类似要求。然而,现有的近似遗忘技术在现实世界安全系统中的部署在计算上仍然难以承受,因为它们需要对每个数据点的移除进行重复且昂贵的Hessian逆向量计算,这在处理入侵检测系统、垃圾邮件过滤器和威胁情报平台等场景中的多个相关请求时造成了瓶颈。因此,我们引入了一个计算高效的遗忘框架,该框架识别训练集中的相关数据点,并应用理论上推导出的闭式参数更新规则,与标准影响函数遗忘相比,实现了82倍的墙钟加速,同时在模型效用上相比最先进的基线提高了10^{-2}的准确率。我们的方法通过Hessian阻尼建立了理论保证并确保了数值稳定性。我们在七个不同的数据集架构组合(包括大规模CIFAR-100与ResNet-50)上的评估展示了优越的遗忘效果,成员推断攻击成功率为0.660,拔河得分为0.950。
英文摘要:
The increasing adoption of machine learning in network and distributed security systems has created an urgent need for mechanisms that can selectively and efficiently remove the influence of specific training data to eliminate compromised or adversarial data points from production models. Privacy regulations such as GDPR's \emph{right to be forgotten} also pose similar requirements. However, existing approximate unlearning techniques remain computationally prohibitive for deployment in real-world security systems, as they require repeated expensive Hessian-inverse-vector computations for each data point removal, creating a bottleneck when processing multiple related requests in scenarios such as intrusion detection systems, spam filters, and threat intelligence platforms. Thus, we introduce a computationally efficient unlearning framework that identifies correlated data points in the training set and applies a theoretically derived closed-form parameter update rule, achieving an $82\times$ wall-clock speedup over standard influence function unlearning while preserving model utility with a $10^{-2}$ improvement in accuracy over state-of-the-art baselines. Our method establishes theoretical guarantees and ensures numerical stability through Hessian damping. Our evaluation across seven diverse dataset architecture combinations, including large-scale CIFAR-100 with ResNet-50, demonstrates superior forgetting effectiveness, with membership inference attack success rates of 0.660 and tug-of-war scores of 0.950.