arXiv:cs.LG· Qi Kuang, Yin Xia·· 4 小时前
Minimax 高斯机制用于持续机器遗忘
Minimax Gaussian Mechanisms for Continual Machine Unlearning
AI 导读
研究提出面向 Newton 更新的高斯机制,用于处理序列删除请求下的持续机器遗忘,借助高斯差分隐私(GDP)及其自适应组合规则,使全部已发布模型序列在统计上难以与精确重训练区分。
正文
Abstract:Machine unlearning updates a trained model after records are deleted, aiming to match exact retraining without repeating the full training procedure. We develop Gaussian mechanisms for Newton updates under sequential deletion requests. Using Gaussian differential privacy (GDP) and its adaptive composition rule, we show that the full sequence of released models is statistically difficult to distinguish from matched exact retraining. To calibrate these mechanisms for empirical risk minimization, we derive upper bounds on the error of the Newton approximation relative to exact retraining and on how this error changes after each deletion batch. Independent Gaussian noise is calibrated using bounds on the full residual at each release, whereas Gaussian random walk noise uses smaller bounds on residual increments. These bounds yield allocations minimizing the worst-case maximum noise variance across releases under the resulting GDP certification constraints. With count-based bounds, the random walk asymptotically matches the worst-case variance of a single release at deletion cap $M$, while independent noise incurs an additional factor of order $M$. Set-based bounds can reduce the noise variances by using gradients and Hessians of the deleted records. For singleton deletion, we further show that count-based independent noise, count-based random walk noise, and set-based independent noise are minimax among fixed Gaussian covariances under their respective residual or increment bounds. With set-based bounds, allowing variances to adapt to deleted records can improve on every fixed covariance by a factor of order $(\log M)^2$ on some data sequences. The residual and noise bounds also yield parameter and predictive consistency relative to exact retraining, uniformly over deletion policies. Simulations and a credit default data analysis evaluate bounds, noise variances, and estimation errors.
| Subjects: | Machine Learning (stat.ML); Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.11628 [stat.ML] |
| (or arXiv:2610.11628v1 [stat.ML] for this version) | |
| https://doi.org/10.48550/arXiv.2610.11628 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Qi Kuang [view email]
[v1]
Thu, 8 Oct 2026 10:06:26 UTC (153 KB)
来源:arXiv:cs.LG · arxiv.org