Over the past years, Machine Learning-as-a-Service (MLaaS) has received a surging demand for supporting Machine Learning-driven services to offer revolutionized user experience across diverse application areas. MLaaS provides inference service with low inference latency based on an ML model trained using a dataset collected from numerous individual data owners. Recently, for the sake of data owners' privacy and to comply with the "right to be forgotten (RTBF)" as enacted by data protection legislation, many machine unlearning methods have been proposed to remove data owners' data from trained models upon their unlearning requests. However, despite their promising efficiency, almost all existing machine unlearning methods handle unlearning requests independently from inference requests, which unfortunately introduces a new security issue of inference service obsolescence and a privacy vulnerability of undesirable exposure for machine unlearning in MLaaS. In this paper, we propose the ERASER framework for machinE unleaRning in MLaAS via an inferencE seRving-aware approach. ERASER strategically choose appropriate unlearning execution timing to address the inference service obsolescence issue. A novel inference consistency certification mechanism is proposed to avoid the violation of RTBF principle caused by postponed unlearning executions, thereby mitigating the undesirable exposure vulnerability. ERASER offers three groups of design choices to allow for tailor-made variants that best suit the specific environments and preferences of various MLaaS systems. Extensive empirical evaluations across various settings confirm ERASER's effectiveness, e.g., it can effectively save up to 99% of inference latency and 31% of computation overhead over the inference-oblivion baseline.
翻译:近年来,机器学习即服务(MLaaS)为支持机器学习驱动的服务提供了日益增长的需求,以在多样化应用领域中提供革命性的用户体验。MLaaS基于通过从众多个体数据所有者处收集的数据集训练得到的机器学习模型,提供低推理延迟的推理服务。最近,为保护数据所有者隐私并遵循数据保护法规所规定的“被遗忘权(RTBF)”,许多机器遗忘方法被提出,旨在根据数据所有者的遗忘请求从已训练模型中移除其数据。然而,尽管这些方法在效率方面表现出色,但几乎所有现有的机器遗忘方法都独立于推理请求来处理遗忘请求,这不幸地引入了推理服务过时的新安全问题以及MLaaS中机器遗忘可能导致非预期暴露的隐私漏洞。本文提出ERASER框架,它是一种通过推理服务感知方法实现MLaaS中机器遗忘的解决方案。ERASER通过策略性地选择适当的遗忘执行时机来解决推理服务过时问题。同时,提出一种新颖的推理一致性认证机制,以避免因延迟执行遗忘而违反RTBF原则,从而缓解非预期暴露的脆弱性。ERASER提供三组设计选项,允许定制最适合不同MLaaS系统特定环境和偏好的变体。在各种设置下进行的广泛实证评估证实了ERASER的有效性,例如,相较于忽略推理的基线方法,它能有效节省高达99%的推理延迟和31%的计算开销。