To comply with AI and data regulations, the need to forget private or copyrighted information from trained machine learning models is increasingly important. The key challenge in unlearning is forgetting the necessary data in a timely manner, while preserving model performance. In this work, we address the zero-shot unlearning scenario, whereby an unlearning algorithm must be able to remove data given only a trained model and the data to be forgotten. Under such a definition, existing state-of-the-art methods are insufficient. Building on the concepts of Lipschitz continuity, we present a method that induces smoothing of the forget sample's output, with respect to perturbations of that sample. We show this smoothing successfully results in forgetting while preserving general model performance. We perform extensive empirical evaluation of our method over a range of contemporary benchmarks, verifying that our method achieves state-of-the-art performance under the strict constraints of zero-shot unlearning.
翻译:为遵守人工智能和数据法规,从已训练的机器学习模型中遗忘隐私或版权信息的需求日益重要。遗忘的关键挑战在于及时清除必要数据的同时保持模型性能。本文针对零样本遗忘场景展开研究,即遗忘算法必须仅凭已训练模型和待遗忘数据即可实现数据移除。在此定义下,现有最先进方法存在不足。基于Lipschitz连续性概念,我们提出一种方法,通过对待遗忘样本的扰动施加输出平滑化处理。实验表明,该平滑化过程在保持模型整体性能的同时成功实现遗忘。我们在多个当代基准数据集上开展了全面的实证评估,验证了该方法在零样本遗忘的严格约束下达到了最先进的性能。