Machine Unlearning
2019/12/09 by Lucas Bourtoule, Varun Chandrasekaran, Bourtoule, Lucas +13 · 3 voices · 150 citations
#cs.CR #cs.AI #cs.LG
paper · pdf · doi:10.48550/arxiv.1912.03817
Abstract
Once users have shared their data online, it is generally difficult for them to revoke access and ask for the data to be deleted. Machine learning (ML) exacerbates this problem because any model trained with said data may have memorized it, putting users at risk of a successful privacy attack exposing their information. Yet, having models unlearn is notoriously difficult. We introduce SISA training, a framework that expedites the unlearning process by strategically limiting the influence of a data point in the training procedure. While our framework is applicable to any learning algorithm, it is designed to achieve the largest improvements for stateful algorithms like stochastic gradient descent for deep neural networks. SISA training reduces the computational overhead associated with unlearning, even in the worst-case setting where unlearning requests are made uniformly across the training set. In some cases, the service provider may have a prior on the distribution of unlearning requests that will be issued by users. We may take this prior into account to partition and order data accordingly, and further decrease overhead from unlearning. Our evaluation spans several datasets from different domains, with corresponding motivations for unlearning. Under no distributional assumptions, for simple learning tasks, we observe that SISA training improves time to unlearn points from the Purchase dataset by 4.63x, and 2.45x for the SVHN dataset, over retraining from scratch. SISA training also provides a speed-up of 1.36x in retraining for complex learning tasks such as ImageNet classification; aided by transfer learning, this results in a small degradation in accuracy. Our work contributes to practical data governance in machine unlearning.
Cited by
- DCS: A Unified Conditional Sensitivity Framework for Cross-Modal Copyright Infringement Detection
- Unlearning Under Imbalance: Benchmarking Fairness in Multimodal LLM Unlearning
- Unlearning as Distribution Restoration: A Controlled Counterfactual Study, a Validated Selective Screen, and the Limits of Oracle-Free Certification
- Falsifiable Release Gates for Self-Improving Systems: Standing Invariants at Scale
- Stochastic Meta-Unlearning: Bridging Language Backbone and Multimodal Unlearning
- Understanding How University Guidelines Address Privacy and Security Issues of Generative AI in Academic Settings
- Quantifying Training Membership Information in the Hyperspherical Embedding Geometry of Face Recognition Models
- When Machine Unlearning Meets Retrieval-Augmented Generation (RAG): Keep Secret or Forget Knowledge?
- Not All Tokens Are Meant to Be Forgotten
- Not All Data Are Unlearned Equally
- Privacy Ripple Effects from Adding or Removing Personal Information in Language Model Training
- Measuring Chain of Thought Faithfulness by Unlearning Reasoning Steps
- Certifying the Right to Be Forgotten: Primal-Dual Optimization for Sample and Label Unlearning in Vertical Federated Learning
- Understanding Machine Unlearning Through the Lens of Mode Connectivity
- DECAF: De-Clustering for Adaptive Representational Unlearning
- Doc-to-LoRA: Learning to Instantly Internalize Contexts
- Obliviate: Efficient Unlearning in Recommender Systems
- A Mechanistic Perspective and Difficulty Metric for Unlearning
- Investigating Model Editing for Unlearning in Large Language Models
- Machine Unlearning in the Era of Quantum Machine Learning: An Empirical Study
- Towards Benchmarking Privacy Vulnerabilities in Selective Forgetting with Large Language Models
- Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure
- Metanetworks as Regulatory Operators: Learning to Edit for Requirement Compliance
- FAME: Fictional Actors for Multilingual Erasure
- Erasing CLIP Memories: Non-Destructive, Data-Free Zero-Shot class Unlearning in CLIP Models
- Selective, Controlled and Domain-Agnostic Unlearning in Pretrained CLIP: A Training- and Data-Free Approach
- Face Identity Unlearning for Retrieval via Embedding Dispersion
- Forgetful but Faithful: A Cognitive Memory Architecture and Benchmark for Privacy-Aware Generative Agents
- Sparse Concept Anchoring for Interpretable and Controllable Neural Representations
- Natural Geometry of Robust Data Attribution: From Convex Models to Deep Networks
- ZK-APEX: Zero-Knowledge Approximate Personalized Unlearning with Executable Proofs
- Forget and Explain: Transparent Verification of GNN Unlearning
- LUNE: Efficient LLM Unlearning via LoRA Fine-Tuning with Negative Examples
- Recover-to-Forget: Gradient Reconstruction from LoRA for Efficient LLM Unlearning
- Memory Power Asymmetry in Human-AI Relationships: Preserving Mutual Forgetting in the Digital Age
- SUGAR: A Sweeter Spot for Generative Unlearning of Many Identities
- RapidUn: Influence-Driven Parameter Reweighting for Efficient Large Language Model Unlearning
- Efficient Public Verification of Private ML via Regularization
- Grokked Models are Better Unlearners
- Adaptive-lambda Subtracted Importance Sampled Scores in Machine Unlearning for DDPMs and VAEs
- Teleportation-Based Defenses for Privacy in Approximate Machine Unlearning
- FedSGT: Exact Federated Unlearning via Sequential Group-based Training
- Illuminating the Black Box: Real-Time Monitoring of Backdoor Unlearning in CNNs via Explainable AI
- ModHiFi: Identifying High Fidelity predictive components for Model Modification
- POUR: A Provably Optimal Method for Unlearning Representations via Neural Collapse
- SineProject: Machine Unlearning for Stable Vision Language Alignment
- Curvature-Aware Safety Restoration In LLMs Fine-Tuning
- SG-OIF: A Stability-Guided Online Influence Framework for Reliable Vision Data
- Geometric-disentangelment Unlearning
- Membership Inference Attacks Beyond Overfitting
- Erase to Retain: Low Rank Adaptation Guided Selective Unlearning in Medical Segmentation Networks
- Beyond Tokens in Language Models: Interpreting Activations through Text Genre Chunks
- Selective Forgetting in Option Calibration: An Operator-Theoretic Gauss-Newton Framework
- Coffee: Controllable Diffusion Fine-tuning
- Forgetting-MarI: LLM Unlearning via Marginal Information Regularization
- Learning to Fast Unrank in Collaborative Filtering Recommendation
- Beyond Uniform Deletion: A Data Value-Weighted Framework for Certified Machine Unlearning
- FiCABU: A Fisher-Based, Context-Adaptive Machine Unlearning Processor for Edge AI
- The Realignment Problem: When Right becomes Wrong in LLMs
- Improving Unlearning with Model Updates Probably Aligned with Gradients
- Quantum Machine Unlearning: Foundations, Mechanisms, and Taxonomy
- MPRU: Modular Projection-Redistribution Unlearning as Output Filter for Classification Pipelines
- Signed Graph Unlearning
- Multistakeholder Impacts of Profile Portability in a Recommender Ecosystem
- A Survey on Unlearning in Large Language Models
- On the Impossibility of Retrain Equivalence in Machine Unlearning
- Label Smoothing Improves Gradient Ascent in LLM Unlearning
- Efficient Utility-Preserving Machine Unlearning with Implicit Gradient Surgery
- Leverage Unlearning to Sanitize LLMs
- LEGO: A Lightweight and Efficient Multiple-Attribute Unlearning Framework for Recommender Systems
- LLM Unlearning with LLM Beliefs
- Not Every Time and Frequency Need to Be Forgotten in Diffusion Unlearning
- Backdoor Unlearning by Linear Task Decomposition
- Gaussian Certified Unlearning in High Dimensions: A Hypothesis Testing Approach
- Evaluating the Quality of Randomness and Entropy in Tasks Supported by Large Language Models
- Approximate Domain Unlearning for Vision-Language Models
- Federated Unlearning in the Wild: Rethinking Fairness and Data Discrepancy
- Cross-Modal Attention Guided Unlearning in Vision-Language Models
- Distribution Preference Optimization: A Fine-grained Perspective for LLM Unlearning
- Agentic Context Engineering: Evolving Contexts for Self-Improving Language Models
- Machine Unlearning in Speech Emotion Recognition via Forget Set Alone
- Unlearning in Diffusion models under Data Constraints: A Variational Inference Approach
- Direct Token Optimization: A Self-contained Approach to Large Language Model Unlearning
- Rotation Control Unlearning: Quantifying and Controlling Continuous Unlearning for LLM with The Cognitive Rotation Space
- SMS: Self-supervised Model Seeding for Verification of Machine Unlearning
- Ascent Fails to Forget
- Understanding the Dilemma of Unlearning for Large Language Models
- Preserving Cross-Modal Stability for Visual Unlearning in Multimodal Scenarios
- Copyright Infringement Detection in Text-to-Image Diffusion Models via Differential Privacy
- OFMU: Optimization-Driven Framework for Machine Unlearning
- Can Prompts Rewind Time for LLMs? Evaluating the Effectiveness of Prompted Knowledge Cutoffs
- A Unified Framework for Diffusion Model Unlearning with f-Divergence
- Beyond Sharp Minima: Robust LLM Unlearning via Feedback-Guided Multi-Point Optimization
- CURE: Centroid-guided Unsupervised Representation Erasure for Facial Recognition Systems
- Benign on Label, Malicious by Design: Clean-Label Dormant-to-Activated Backdoor via Machine Unlearning with Removable Camouflage
- Subtract or Replay? Exact Deletion from Language-Model Memory
- Beyond Binary Rewards: A Comparative Study of Reward Design for Reinforcement Unlearning
- Memory in Large Language Models: Mechanisms, Evaluation and Evolution
- TraceHiding: Scalable Machine Unlearning for Mobility Data
- Scrub It Out! Erasing Sensitive Memorization in Code Language Models via Machine Unlearning
- ReTrack: Data Unlearning in Diffusion Models through Redirecting the Denoising Trajectory
- Forget What's Sensitive, Remember What Matters: Token-Level Differential Privacy in Memory Sculpting for Continual Learning
- Module-Aware Parameter-Efficient Machine Unlearning on Transformers
- Membership Inference Attacks on Recommender System: A Survey
- Machine Unlearning for Responsible and Adaptive AI in Education
- Customized Retrieval-Augmented Generation with LLM for Debiasing Recommendation Unlearning
- Bias-Aware Machine Unlearning: Towards Fairer Vision Models via Controllable Forgetting
- zkUnlearner: A Zero-Knowledge Framework for Verifiable Unlearning with Multi-Granularity and Forgery-Resistance
- MRD-LiNet: A Novel Lightweight Hybrid CNN with Gradient-Guided Unlearning for Improved Drought Stress Identification
- From Membership-Privacy Leakage to Quantum Machine Unlearning
- The Measure of Deception: An Analysis of Data Forging in Machine Unlearning
- Pre-Forgettable Models: Prompt Learning as a Native Mechanism for Unlearning
- Graph Unlearning: Efficient Node Removal in Graph Neural Networks
- Evaluating the Defense Potential of Machine Unlearning against Membership Inference Attacks
- AMCR: A Framework for Assessing and Mitigating Copyright Risks in Generative Models
- FUTURE: Flexible Unlearning for Tree Ensemble
- Towards Mitigating Excessive Forgetting in LLM Unlearning via Entanglement-Guidance with Proxy Constraint
- MobText-SISA: Efficient Machine Unlearning for Mobility Logs with Spatio-Temporal and Natural-Language Data
- Tackling Federated Unlearning as a Parameter Estimation Problem
- Auditing Approximate Machine Unlearning for Differentially Private Models
- Data Augmentation Improves Machine Unlearning
- Curriculum Approximate Unlearning for Session-based Recommendation
- BadFU: Backdoor Federated Learning through Adversarial Machine Unlearning
- Reliable Unlearning Harmful Information in LLMs with Metamorphosis Representation Projection
- Towards Source-Free Machine Unlearning
- Side Effects of Erasing Concepts from Diffusion Models
- FedUP: Efficient Pruning-based Federated Unlearning for Model Poisoning Attacks
- Involuntary Jailbreak: On Self-Prompting Attacks
- Unlearning at Scale: Implementing the Right to be Forgotten in Large Language Models
- Demystifying Foreground-Background Memorization in Diffusion Models
- Slow Tuning and Low-Entropy Masking for Safe Chain-of-Thought Distillation
- Invisible Watermarks, Visible Gains: Steering Machine Unlearning with Bi-Level Watermarking Design
- EFU: Enforcing Federated Unlearning via Functional Encryption
- Revisiting Data Attribution for Influence Functions
- Towards Unveiling Predictive Uncertainty Vulnerabilities in the Context of the Right to Be Forgotten
- Membership Inference Attacks with False Discovery Rate Control
- Membership Inference Attack with Partial Features
- Integrated Influence: Data Attribution with Baseline
- WSS-CL: Weight Saliency Soft-Guided Contrastive Learning for Efficient Machine Unlearning Image Classification
- Conformal Unlearning: A New Paradigm for Unlearning in Conformal Predictors
- Superior resilience to poisoning and amenability to unlearning in quantum machine learning
- Graph Unlearning via Embedding Reconstruction -- A Range-Null Space Decomposition Approach
- IMU: Influence-guided Machine Unlearning
- Towards Evaluation for Real-World LLM Unlearning
- Efficient Machine Unlearning via Influence Approximation
- LoReUn: Data Itself Implicitly Provides Cues to Improve Machine Unlearning
- Zero-Shot Machine Unlearning with Proxy Adversarial Data Generation
- Reminiscence Attack on Residuals: Exploiting Approximate Machine Unlearning for Privacy
- Unlearning of Knowledge Graph Embedding via Preference Optimization
- Machine unlearning [wikipedia]
Discussions
Related