作者:郑志高,殷凯,邝瑶雯,王涛*,陈亚虹,姚世红,黄浩
出版刊物:Proceedings of the ACM Web Conference 2026
出版时间:2026年
内容摘要:
Deep neural networks (DNNs) have achieved remarkable success across various domains, but their reliance on large datasets often containing sensitive information raises significant privacy concerns. In response to stringent privacy regulations such as GDPR and CCPA, machine unlearning (MUL) has emerged as a critical technique to remove the influence of specific data samples from trained models. However, existing unlearning methods face two major challenges: privacy deficiencies in the remaining datasets and significant instability of the model after unlearning. To address these issues, we propose DeepUL, a deep unlearning algorithm that leverages model sparsity to enhance both privacy and stability. DeepUL follows a two-step process: first pruning and then unlearning. The pruning step not only sparsifies the model but also decouples the model parameters from the original training data, thereby improving privacy. The unlearning step employs gradient projection to eliminate dependencies on the data to be deleted while maintaining the model stability. Additionally, we introduce a hierarchical weight pruning strategy to achieve differential pruning across network layers, preventing layer collapse and ensuring robustness. Extensive experiments on benchmark datasets demonstrate that DeepUL outperforms existing methods in utility, unlearning efficacy, privacy guarantee, and stability, making it a practical and effective solution for machine unlearning.
深度神经网络(DNN)在各领域取得了显著成功,但其对往往包含敏感信息的大规模数据集的依赖引发了严重的隐私担忧。为响应GDPR和CCPA等严格的隐私法规,机器遗忘(MUL)已成为一项关键技术,用于从已训练模型中消除特定数据样本的影响。然而,现有遗忘方法面临两大挑战:剩余数据集中的隐私缺陷以及遗忘后模型的显著不稳定性。为解决这些问题,我们提出DeepUL,一种利用模型稀疏性来同时增强隐私性与稳定性的深度遗忘算法。DeepUL遵循先剪枝后遗忘的两步流程。剪枝步骤不仅使模型稀疏化,还将模型参数与原始训练数据解耦,从而提升隐私性。遗忘步骤采用梯度投影来消除对拟删除数据的依赖,同时保持模型稳定性。此外,我们引入分层权重剪枝策略,实现跨网络层的差异化剪枝,防止层坍塌并确保鲁棒性。在基准数据集上的大量实验表明,DeepUL在效用、遗忘效果、隐私保障和稳定性方面均优于现有方法,使其成为机器遗忘的一种实用且有效的解决方案。