Mixed-Privacy Forgetting in Deep Networks

被引:56
|
作者
Golatkar, Aditya [1 ,2 ]
Achille, Alessandro [1 ]
Ravichandran, Avinash [1 ]
Polito, Marzia [1 ]
Soatto, Stefano [1 ]
机构
[1] Amazon Web Serv, Seattle, WA 98109 USA
[2] Univ Calif Los Angeles, Los Angeles, CA 90024 USA
来源
2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021 | 2021年
关键词
D O I
10.1109/CVPR46437.2021.00085
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We show that the influence of a subset of the training samples can be removed - or "forgotten" - from the weights of a network trained on large-scale image classification tasks, and we provide strong computable bounds on the amount of remaining information after forgetting. Inspired by real-world applications of forgetting techniques, we introduce a novel notion of forgetting in mixed-privacy setting, where we know that a "core" subset of the training samples does not need to be forgotten. While this variation of the problem is conceptually simple, we show that working in this setting significantly improves the accuracy and guarantees of forgetting methods applied to vision classification tasks. Moreover, our method allows efficient removal of all information contained in non-core data by simply setting to zero a subset of the weights with minimal loss in performance. We achieve these results by replacing a standard deep network with a suitable linear approximation. With opportune changes to the network architecture and training procedure, we show that such linear approximation achieves comparable performance to the original network and that the forgetting problem becomes quadratic and can be solved efficiently even for large models. Unlike previous forgetting methods on deep networks, ours can achieve close to the state-of-the-art accuracy on large scale vision tasks. In particular, we show that our method allows forgetting without having to trade off the model accuracy.
引用
收藏
页码:792 / 801
页数:10
相关论文
共 50 条
  • [1] A Study on Catastrophic Forgetting in Deep LSTM Networks
    Schak, Monika
    Gepperth, Alexander
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING - ICANN 2019: DEEP LEARNING, PT II, 2019, 11728 : 714 - 728
  • [2] Privacy Partition: A Privacy-preserving Framework for Deep Neural Networks in Edge Networks
    Chi, Jianfeng
    Owusu, Emmanuel
    Yin, Xuwang
    Yu, Tong
    Chan, William
    Liu, Yiming
    Liu, Haodong
    Chen, Jiasen
    Sim, Swee
    Iyengar, Vibha
    Tague, Patrick
    Tian, Yuan
    2018 THIRD IEEE/ACM SYMPOSIUM ON EDGE COMPUTING (SEC), 2018, : 378 - 380
  • [3] Catastrophic Forgetting in Deep Graph Networks: A Graph Classification Benchmark
    Carta, Antonio
    Cossu, Andrea
    Errica, Federico
    Bacciu, Davide
    FRONTIERS IN ARTIFICIAL INTELLIGENCE, 2022, 5
  • [4] Privacy Law That Does Not Protect Privacy, Forgetting the Right to be Forgotten
    Cunningham, McKay
    BUFFALO LAW REVIEW, 2017, 65 (03): : 495 - 546
  • [5] Deep Graph Memory Networks for Forgetting-Robust Knowledge Tracing
    Abdelrahman, Ghodai
    Wang, Qing
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (08) : 7844 - 7855
  • [6] Privacy and Search Engines: Forgetting or Contexualizing?
    de Mars, Sylvia
    O'Callaghan, Patrick
    JOURNAL OF LAW AND SOCIETY, 2016, 43 (02) : 257 - 284
  • [7] Differential Privacy Algorithm under Deep Neural Networks
    Zhou Zhiping
    Qian Xinyu
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2022, 44 (05) : 1773 - 1781
  • [8] Privacy-Preserving Publication of Deep Neural Networks
    Sei, Yuichi
    Okumura, Hiroshi
    Ohsuga, Akihiko
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 1418 - 1425
  • [9] Preserving differential privacy in convolutional deep belief networks
    NhatHai Phan
    Wu, Xintao
    Dou, Dejing
    MACHINE LEARNING, 2017, 106 (9-10) : 1681 - 1704
  • [10] Exploiting Vulnerabilities of Deep Neural Networks for Privacy Protection
    Sanchez-Matilla, Ricardo
    Li, Chau Yi
    Shamsabadi, Ali Shahin
    Mazzon, Riccardo
    Cavallaro, Andrea
    IEEE TRANSACTIONS ON MULTIMEDIA, 2020, 22 (07) : 1862 - 1873