The Utility and Complexity of in- and out-of-Distribution Machine Unlearning

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Allouah, Youssef, Kazdan, Joshua, Guerraoui, Rachid, Koyejo, Sanmi
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866917919516000256
author Allouah, Youssef
Kazdan, Joshua
Guerraoui, Rachid
Koyejo, Sanmi
author_facet Allouah, Youssef
Kazdan, Joshua
Guerraoui, Rachid
Koyejo, Sanmi
contents Machine unlearning, the process of selectively removing data from trained models, is increasingly crucial for addressing privacy concerns and knowledge gaps post-deployment. Despite this importance, existing approaches are often heuristic and lack formal guarantees. In this paper, we analyze the fundamental utility, time, and space complexity trade-offs of approximate unlearning, providing rigorous certification analogous to differential privacy. For in-distribution forget data -- data similar to the retain set -- we show that a surprisingly simple and general procedure, empirical risk minimization with output perturbation, achieves tight unlearning-utility-complexity trade-offs, addressing a previous theoretical gap on the separation from unlearning "for free" via differential privacy, which inherently facilitates the removal of such data. However, such techniques fail with out-of-distribution forget data -- data significantly different from the retain set -- where unlearning time complexity can exceed that of retraining, even for a single sample. To address this, we propose a new robust and noisy gradient descent variant that provably amortizes unlearning time complexity without compromising utility.
format Preprint
id arxiv_https___arxiv_org_abs_2412_09119
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The Utility and Complexity of in- and out-of-Distribution Machine Unlearning
Allouah, Youssef
Kazdan, Joshua
Guerraoui, Rachid
Koyejo, Sanmi
Machine Learning
Cryptography and Security
Optimization and Control
Machine unlearning, the process of selectively removing data from trained models, is increasingly crucial for addressing privacy concerns and knowledge gaps post-deployment. Despite this importance, existing approaches are often heuristic and lack formal guarantees. In this paper, we analyze the fundamental utility, time, and space complexity trade-offs of approximate unlearning, providing rigorous certification analogous to differential privacy. For in-distribution forget data -- data similar to the retain set -- we show that a surprisingly simple and general procedure, empirical risk minimization with output perturbation, achieves tight unlearning-utility-complexity trade-offs, addressing a previous theoretical gap on the separation from unlearning "for free" via differential privacy, which inherently facilitates the removal of such data. However, such techniques fail with out-of-distribution forget data -- data significantly different from the retain set -- where unlearning time complexity can exceed that of retraining, even for a single sample. To address this, we propose a new robust and noisy gradient descent variant that provably amortizes unlearning time complexity without compromising utility.
title The Utility and Complexity of in- and out-of-Distribution Machine Unlearning
topic Machine Learning
Cryptography and Security
Optimization and Control
url https://arxiv.org/abs/2412.09119