[论文] Do Influence-Derived Data Perturbations Enable Machine Unlearning? A C...

研究领域: ML 作者: Chenkai Wu, Chrispine Kambimbi, Qinyang Zeng, Jun Yan 发布时间: 2026-09-15 arXiv: 2609.12313

论文概要

研究领域: ML 作者: Chenkai Wu, Chrispine Kambimbi, Qinyang Zeng, Jun Yan 发布时间: 2026-09-15 arXiv: 2609.12313

中文摘要

我们评估了深度扰动学习(DPL)——该方法沿影响力导出的方向扰动训练图像与标签——在先前工作为其定位的三种机器遗忘角色中的表现:直接删除信号(最强主张)、保效用正则化器、以及对抗式遗忘的暖启动。较弱角色的证据曾被用来支持较强主张,因此我们采用匹配的协议、以精确种子重训练基线分别检验每个角色。对公开实现的审计发现两个正确性问题:图像方向在增强、归一化后的张量上计算,却被施加到原始图像上;标签扰动幅度低于 float32 分辨率,导致标签实际未被改变。修正图像扰动流水线后,DPL 在 CIFAR-10/ResNet-18 的三个配对种子上均未通过直接删除判据。其效用影响在不同种子间符号不一致,且一旦计入方向计算时间,其表现不及简单的暖启动基线。单种子 Tiny ImageNet 检查同样不支持 DPL 作为正则化器或暖启动;发布代码中的预处理不一致使直接比较无法下定论。这些结果仅覆盖随机实例删除,并不排除影响力方法在其他删除机制中的有效性。我们发布了角色匹配的评估协议与针对基于扰动删除主张的审计清单。

原文摘要

We evaluate Deep Perturbation Learning (DPL), which perturbs training images and labels along influence-derived directions, in three roles in which prior work has positioned it for machine unlearning: a direct deletion signal (the strongest claim), a utility-preserving regularizer, and a warm start for adversarial unlearning. Evidence for the weaker roles has been used to support the stronger one, so we test each role separately under a matched protocol with exact-seed retraining baselines. An audit of the public implementation identifies two correctness issues: image directions are computed on augmented, normalized tensors but applied to raw images, and the label perturbation falls below float32 resolution, leaving labels unchanged. After correcting the image-perturbation pipeline, DPL fa...


*自动采集于 2026-09-15*

#论文 #arXiv #ML #小凯

暂无表态

想参与讨论或点赞?登录后使用完整功能

讨论回复(0)

暂无回复,登录后可参与讨论

本文标签

合作

智谱 GLM-5 已上线

在智谱开放平台 BigModel.cn 打造 AI 应用。新一代旗舰模型 GLM-5 在推理、代码、智能体综合能力达到开源模型 SOTA。

领取 2000万 Tokens