Provably Unlearnable Data Examples
Derui Wang, Minhui Xue, Bo Li, Seyit Camtepe, Liming Zhu
Abstract
The exploitation of publicly accessible data has led to escalating concerns regarding data privacy and intellectual property (IP) breaches in the age of artificial intelligence. To safeguard both data privacy and IP-related domain knowledge, efforts have been undertaken to render shared data unlearnable for unauthorized models in the wild. Existing methods apply empirically optimized perturbations to the data in the hope of disrupting the correlation between the inputs and the corresponding labels such that the data samples are converted into Unlearnable Examples (UEs). Nevertheless, the absence of mechanisms to verify the robustness of UEs against uncertainty in unauthorized models and their training procedures engenders several under-explored challenges. First, it is hard to quantify the unlearnability of UEs against unauthorized adversaries from different runs of training, leaving the soundness of the defense in obscurity. Particularly, as a prevailing evaluation metric, empirical test accuracy faces generalization errors and may not plausibly represent the quality of UEs. This also leaves room for attackers, as there is no rigid guarantee of the maximal test accuracy achievable by attackers. Furthermore, we find that a simple recovery attack can restore the clean-task performance of the classifiers trained on UEs by slightly perturbing the learned weights. To mitigate the aforementioned problems, in this paper, we propose a mechanism for certifying the so-called -Learnability of an unlearnable dataset via parametric smoothing. A lower certified -Learnability indicates a more robust and effective protection over the dataset. Concretely, we 1) improve the tightness of certified -Learnability and 2) design Provably Unlearnable Examples (PUEs) which have reduced -Learnability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- ALMGuard: Safety Shortcuts and Where to Find Them as Guardrails for Audio-Language ModelsWeifei Jin, Yuxin Cao, Junjie Su, Minhui Xue et al.NeurIPS 2025 · 9 citations
- When Priors Backfire: On the Vulnerability of Unlearnable Examples to PretrainingZhihao Li, Gezheng Xu, Jiale Cai, Ruiyi Fang et al.ICLR 2026 · 5 citations
- Versatile Transferable Unlearnable Example GeneratorZhihao Li, Jiale Cai, Gezheng Xu, Hao Zheng et al.NeurIPS 2025 · 3 citations
- FUSE: Full‑spectrum Unlearnable Examples via Spectral EqualizationJiale Cai, Gezheng Xu, Zhihao Li, Ruiyi Fang et al.ICML 2026 · 1 citation
- SafeSpeech: Robust and Universal Voice Protection Against Malicious Speech SynthesisZhisheng Zhang, Derui Wang, Qianyi Yang, Pengyang Huang et al.USENIX Security 2025
Builds on40
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- An Image is Worth One Word: Personalizing Text-to-Image Generation using Textual InversionRinon Gal, Yuval Alaluf, Yuval Atzmon, Or Patashnik et al.ICLR 2023 · 464 citations
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
Related papers
- Ungeneralizable ExamplesJingwen Ye, Xinchao WangCVPR 2024 · 3 citations
- How Far Are We from True Unlearnability?Kai Ye, Liangcai Su, Chenxiong QianICLR 2025
- Unlearnable Examples Give a False Sense of Security: Piercing through Unexploitable Data with Learnable ExamplesWan Jiang, Yunfeng Diao, He Wang, Jianxin Sun et al.ACM MM 2023 · 14 citations
- One for All: A Universal Generator for Concept Unlearnability via Multi-Modal AlignmentChaochao Chen, Jiaming Zhang, Yuyuan Li, Zhongxuan HanICML 2024 · 8 citations
- Towards LLM Unlearning Resilient to Relearning Attacks: A Sharpness-Aware Minimization Perspective and BeyondChongyu Fan, Jinghan Jia, Yihua Zhang, Anil Ramakrishna et al.ICML 2025
