What Can We Learn from Unlearnable Datasets?
Pedro Sandoval Segura, Vasu Singla, Jonas Geiping, Micah Goldblum, Tom Goldstein
Abstract
In an era of widespread web scraping, unlearnable dataset methods have the potential to protect data privacy by preventing deep neural networks from generalizing. But in addition to a number of practical limitations that make their use unlikely, we make a number of findings that call into question their ability to safeguard data. First, it is widely believed that neural networks trained on unlearnable datasets only learn shortcuts, simpler rules that are not useful for generalization. In contrast, we find that networks actually can learn useful features that can be reweighed for high test performance, suggesting that image protection is not assured. Unlearnable datasets are also believed to induce learning shortcuts through linear separability of added perturbations. We provide a counterexample, demonstrating that linear separability of perturbations is not a necessary condition. To emphasize why linearly separable perturbations should not be relied upon, we propose an orthogonal projection attack which allows learning from unlearnable datasets published in ICML 2021 and ICLR 2023. Our proposed attack is significantly less complex than recently proposed techniques. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1bc3b5fb-0e02-4893-a574-d6498e9f5a94Cited by top-tier papers10
- Purify Unlearnable Examples via Rate-Constrained Variational AutoencodersYi Yu, Yufei Wang, Song Xia, Wenhan Yang et al.ICML 2024 · 22 citations
- UnSeg: One Universal Unlearnable Example Generator is Enough against All Image SegmentationYe Sun, Hao Zhang, Tiehua Zhang, Xingjun Ma et al.NeurIPS 2024 · 18 citations
- Detecting and Corrupting Convolution-based Unlearnable ExamplesMinghui Li, Xianlong Wang, Zhifei Yu, Shengshan Hu et al.AAAI 2025 · 13 citations
- One for All: A Universal Generator for Concept Unlearnability via Multi-Modal AlignmentChaochao Chen, Jiaming Zhang, Yuyuan Li, Zhongxuan HanICML 2024 · 8 citations
- When Priors Backfire: On the Vulnerability of Unlearnable Examples to PretrainingZhihao Li, Gezheng Xu, Jiale Cai, Ruiyi Fang et al.ICLR 2026 · 5 citations
Builds on13
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
- Adversarial Examples Make Strong PoisonsLiam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping et al.NeurIPS 2021 · 185 citations
- Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingLue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang et al.NeurIPS 2021 · 90 citations
- Neural Tangent Generalization AttacksChia-Hung Yuan, Shan-Hung WuICML 2021 · 68 citations
Related papers
- Detection and Defense of Unlearnable ExamplesYifan Zhu, Lijia Yu, Xiao-Shan GaoAAAI 2024 · 11 citations
- Ungeneralizable ExamplesJingwen Ye, Xinchao WangCVPR 2024 · 3 citations
- Why Do Unlearnable Examples Work: A Novel Perspective of Mutual InformationYifan Zhu, Yibo Miao, Yinpeng Dong, Xiao-Shan GaoICLR 2026 · 3 citations
- Perturbation-Induced Linearization: Constructing Unlearnable Data with Solely Linear ClassifiersJinlin Liu, Wei Chen, Xiaojin ZhangICLR 2026 · 1 citation
- Availability Attacks Create ShortcutsDa Yu, Huishuai Zhang, Wei Chen, Jian Yin et al.KDD 2022 · 28 citations
