节点文献
面向多类遗忘的模型加噪隐私保护方案
Noise-based unlearning scheme for multi-class unlearning in models
【摘要】 针对人工智能大模型隐私保护中多类遗忘时间开销大、效率低的问题,提出一种面向多类遗忘的子模型加噪隐私保护方案。将原始数据集分割为多个子数据集后训练子模型并聚合生成预训练模型;基于遗忘类数据集学习构建损失最大化噪声矩阵,结合保留类的部分数据集对模型参数进行单个训练周期的损害,使用保留类的部分数据集对模型进行修复。实验结果表明,提出的方案在确保模型对保留类数据集分类准确率的基础上,不仅实现了多类遗忘,还显著降低了时间开销、提高了遗忘效率。
【Abstract】 To address the challenges of high time consumption and low efficiency in multi-class unlearning for privacy protection in large-scale AI models, this paper proposes a noise-injected privacy protection scheme oriented towards multi-class forgetting. The original dataset is partitioned into multiple subsets, which are used to train sub-models that are then aggregated into a pre-trained model. A noise matrix is constructed by maximizing the loss on the data to be forgotten, which is then used to impair the model parameters in a single training epoch. Subsequently, a subset of the data to be retained is used to repair the model. Experimental results show that the proposed scheme achieves effective multi-class forgetting while significantly reducing time overhead and improving forgetting efficiency, without compromising classification accuracy on retained data.
【Key words】 large artificial intelligence model; privacy protection; multi-class unlearning; noise matrix;
- 【文献出处】 重庆邮电大学学报(自然科学版) ,Journal of Chongqing University of Posts and Telecommunications(Natural Science Edition) , 编辑部邮箱 ,2025年03期
- 【分类号】TP309;TP18
- 【下载频次】13