Machine Unlearning Fails to Remove Data Poisoning Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Pawelczyk, Martin, Di, Jimmy Z., Lu, Yiwei, Kamath, Gautam, Sekhari, Ayush, Neel, Seth
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918290597609472
author Pawelczyk, Martin
Di, Jimmy Z.
Lu, Yiwei
Kamath, Gautam
Sekhari, Ayush
Neel, Seth
author_facet Pawelczyk, Martin
Di, Jimmy Z.
Lu, Yiwei
Kamath, Gautam
Sekhari, Ayush
Neel, Seth
contents We revisit the efficacy of several practical methods for approximate machine unlearning developed for large-scale deep learning. In addition to complying with data deletion requests, one often-cited potential application for unlearning methods is to remove the effects of poisoned data. We experimentally demonstrate that, while existing unlearning methods have been demonstrated to be effective in a number of settings, they fail to remove the effects of data poisoning across a variety of types of poisoning attacks (indiscriminate, targeted, and a newly-introduced Gaussian poisoning attack) and models (image classifiers and LLMs); even when granted a relatively large compute budget. In order to precisely characterize unlearning efficacy, we introduce new evaluation metrics for unlearning based on data poisoning. Our results suggest that a broader perspective, including a wider variety of evaluations, are required to avoid a false sense of confidence in machine unlearning procedures for deep learning without provable guarantees. Moreover, while unlearning methods show some signs of being useful to efficiently remove poisoned data without having to retrain, our work suggests that these methods are not yet ``ready for prime time,'' and currently provide limited benefit over retraining.
format Preprint
id arxiv_https___arxiv_org_abs_2406_17216
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Machine Unlearning Fails to Remove Data Poisoning Attacks
Pawelczyk, Martin
Di, Jimmy Z.
Lu, Yiwei
Kamath, Gautam
Sekhari, Ayush
Neel, Seth
Machine Learning
Artificial Intelligence
Cryptography and Security
Computers and Society
We revisit the efficacy of several practical methods for approximate machine unlearning developed for large-scale deep learning. In addition to complying with data deletion requests, one often-cited potential application for unlearning methods is to remove the effects of poisoned data. We experimentally demonstrate that, while existing unlearning methods have been demonstrated to be effective in a number of settings, they fail to remove the effects of data poisoning across a variety of types of poisoning attacks (indiscriminate, targeted, and a newly-introduced Gaussian poisoning attack) and models (image classifiers and LLMs); even when granted a relatively large compute budget. In order to precisely characterize unlearning efficacy, we introduce new evaluation metrics for unlearning based on data poisoning. Our results suggest that a broader perspective, including a wider variety of evaluations, are required to avoid a false sense of confidence in machine unlearning procedures for deep learning without provable guarantees. Moreover, while unlearning methods show some signs of being useful to efficiently remove poisoned data without having to retrain, our work suggests that these methods are not yet ``ready for prime time,'' and currently provide limited benefit over retraining.
title Machine Unlearning Fails to Remove Data Poisoning Attacks
topic Machine Learning
Artificial Intelligence
Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2406.17216