Skip to Main Content
HBS Home
  • About
  • Academic Programs
  • Alumni
  • Faculty & Research
  • Baker Library
  • Giving
  • Harvard Business Review
  • Initiatives
  • News
  • Recruit
  • Map / Directions
Faculty & Research
  • Faculty
  • Research
  • Featured Topics
  • Academic Units
  • …→
  • Harvard Business School→
  • Faculty & Research→
Publications
Publications
  • Article
  • Advances in Neural Information Processing Systems (NeurIPS)

Adaptive Machine Unlearning

By: Varun Gupta, Christopher Jung, Seth Neel, Aaron Roth, Saeed Sharifi-Malvajerdi and Chris Waites
  • Format:Print
ShareBar

Abstract

Data deletion algorithms aim to remove the influence of deleted data points from trained models at a cheaper computational cost than fully retraining those models. However, for sequences of deletions, most prior work in the non-convex setting gives valid guarantees only for sequences that are chosen independently of the models that are published. If people choose to delete their data as a function of the published models (because they don't like what the models reveal about them, for example), then the update sequence is adaptive. In this paper, we give a general reduction from deletion guarantees against adaptive sequences to deletion guarantees against non-adaptive sequences, using differential privacy and its connection to max information. Combined with ideas from prior work which give guarantees for non-adaptive deletion sequences, this leads to extremely flexible algorithms able to handle arbitrary model classes and training methodologies, giving strong provable deletion guarantees for adaptive deletion sequences. We show in theory how prior work for non-convex models fails against adaptive deletion sequences, and use this intuition to design a practical attack against the SISA algorithm of Bourtoule et al.

Keywords

Machine Learning; AI and Machine Learning

Citation

Gupta, Varun, Christopher Jung, Seth Neel, Aaron Roth, Saeed Sharifi-Malvajerdi, and Chris Waites. "Adaptive Machine Unlearning." Advances in Neural Information Processing Systems (NeurIPS) 34 (2021).
  • Read Now

About The Author

Seth Neel

Technology and Operations Management
→More Publications

More from the Authors

    • 2023
    • Proceedings of the Conference on Empirical Methods in Natural Language Processing

    MoPe: Model Perturbation-based Privacy Attacks on Language Models

    By: Marvin Li, Jason Wang, Jeffrey Wang and Seth Neel
    • 2023
    • Faculty Research

    Black-box Training Data Identification in GANs via Detector Networks

    By: Lukman Olagoke, Salil Vadhan and Seth Neel
    • 2023
    • Faculty Research

    In-Context Unlearning: Language Models as Few Shot Unlearners

    By: Martin Pawelczyk, Seth Neel and Himabindu Lakkaraju
More from the Authors
  • MoPe: Model Perturbation-based Privacy Attacks on Language Models By: Marvin Li, Jason Wang, Jeffrey Wang and Seth Neel
  • Black-box Training Data Identification in GANs via Detector Networks By: Lukman Olagoke, Salil Vadhan and Seth Neel
  • In-Context Unlearning: Language Models as Few Shot Unlearners By: Martin Pawelczyk, Seth Neel and Himabindu Lakkaraju
ǁ
Campus Map
Harvard Business School
Soldiers Field
Boston, MA 02163
→Map & Directions
→More Contact Information
  • Make a Gift
  • Site Map
  • Jobs
  • Harvard University
  • Trademarks
  • Policies
  • Accessibility
  • Digital Accessibility
Copyright © President & Fellows of Harvard College.