Forgetting Outside the Box: Scrubbing Deep Networks of Information Accessible from Input-Output Observations

被引:66
作者
Golatkar, Aditya [1 ]
Achille, Alessandro [1 ]
Soatto, Stefano [1 ]
机构
[1] Univ Calif Los Angeles, Dept Comp Sci, Los Angeles, CA 90024 USA
来源
COMPUTER VISION - ECCV 2020, PT XXIX | 2020年 / 12374卷
关键词
Forgetting; Data removal; Neural tangent kernel; Information theory;
D O I
10.1007/978-3-030-58526-6_23
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We describe a procedure for removing dependency on a cohort of training data from a trained deep network that improves upon and generalizes previous methods to different readout functions, and can be extended to ensure forgetting in the final activations of the network. We introduce a new bound on how much information can be extracted per query about the forgotten cohort from a black-box network for which only the input-output behavior is observed. The proposed forgetting procedure has a deterministic part derived from the differential equations of a linearized version of the model, and a stochastic part that ensures information destruction by adding noise tailored to the geometry of the loss landscape. We exploit the connections between the final activations and weight dynamics of a DNN inspired by Neural Tangent Kernels to compute the information in the final activations.
引用
收藏
页码:383 / 398
页数:16
相关论文
共 37 条
[1]   Deep Learning with Differential Privacy [J].
Abadi, Martin ;
Chu, Andy ;
Goodfellow, Ian ;
McMahan, H. Brendan ;
Mironov, Ilya ;
Talwar, Kunal ;
Zhang, Li .
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, :308-318
[2]  
Achille A, 2020, Arxiv, DOI arXiv:1905.12213
[3]  
Achille A, 2018, J MACH LEARN RES, V19
[4]  
Arora Sanjeev, 2019, Advances in neural information processing systems, V32
[5]  
Baumhauer T, 2020, Arxiv, DOI [arXiv:2002.02730, 10.48550/ARXIV.2002.02730]
[6]  
Bourtoule L, 2020, Arxiv, DOI arXiv:1912.03817
[7]   RANK-ONE MODIFICATION OF SYMMETRIC EIGENPROBLEM [J].
BUNCH, JR ;
NIELSEN, CP ;
SORENSEN, DC .
NUMERISCHE MATHEMATIK, 1978, 31 (01) :31-48
[8]   VGGFace2: A dataset for recognising faces across pose and age [J].
Cao, Qiong ;
Shen, Li ;
Xie, Weidi ;
Parkhi, Omkar M. ;
Zisserman, Andrew .
PROCEEDINGS 2018 13TH IEEE INTERNATIONAL CONFERENCE ON AUTOMATIC FACE & GESTURE RECOGNITION (FG 2018), 2018, :67-74
[9]   Towards Making Systems Forget with Machine Unlearning [J].
Cao, Yinzhi ;
Yang, Junfeng .
2015 IEEE SYMPOSIUM ON SECURITY AND PRIVACY SP 2015, 2015, :463-480
[10]  
Chaudhuri K, 2011, J MACH LEARN RES, V12, P1069