发表机构
University of Copenhagen(哥本哈根大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究证明仅遗忘的机器遗忘并非总是可行,并指出为处理任意删除请求,算法可能需要记忆整个数据集,表明标准训练中丢弃的信息对后续删除至关重要。
AI 中文摘要
机器遗忘要求一种删除算法,其输出应接近于在不包含所选遗忘样本的情况下从头重新训练的结果。在本工作中,我们研究仅遗忘的机器遗忘,其中删除算法仅接收已训练的模型和需要遗忘的样本,而不使用保留数据或额外的训练信息。我们探讨仅遗忘的机器遗忘是否总是可行。首先,我们表明这取决于学习方法:不同的数据集可能产生相同的已训练模型,但在删除相同样本后却需要非常不同的输出。利用这一观察,我们推导出机器遗忘在匹配重新训练方面准确性的下界,并为几种标准学习算法具体化这些下界。接着,我们探讨当仅遗忘的机器遗忘成功时,必须满足什么条件。为此,我们推导出算法必须记忆关于训练数据的哪些信息以处理任意删除请求的下界。对于简单的阈值学习器,所需信息可能多达整个数据集,尽管普通训练仅保留一个边界点。总体而言,我们的结果表明,普通学习过程中丢弃的信息可能在后来的删除中需要,因此为仅遗忘的机器遗忘设计的模型可能需要比标准训练保留更多信息。
英文摘要
Machine unlearning asks for a deletion algorithm whose output is close to retraining from scratch without the selected forget examples. In this work, we study forget-only unlearning, where the deletion algorithm receives only the trained model and the examples to forget, with no retained data or extra training information. We ask whether forget-only unlearning is always possible. We first show that this depends on the learning method: different datasets can produce the same trained model but require very different outputs after the same examples are removed. Using this observation, we derive lower bounds on how accurately unlearning can match retraining and instantiate them for several standard learning algorithms. We then ask what must be true when forget-only unlearning succeeds. To this end, we derive lower bounds on what an algorithm must memorize about the training data to handle arbitrary deletion requests. For simple threshold learners, the required information can be as large as the entire dataset, even though ordinary training keeps only one boundary point. Overall, our results show that information discarded during ordinary learning may be needed later for deletion, so models designed for forget-only unlearning may need to retain more information than standard training does.