Robust Unlearnable Examples: Protecting Data Privacy Against Adversarial Learning
Shaopeng Fu, Fengxiang He, Yang Liu, Li Shen, Dacheng Tao
Abstract
The tremendous amount of accessible data in cyberspace face the risk of being unauthorized used for training deep learning models. To address this concern, methods are proposed to make data unlearnable for deep learning models by adding a type of error-minimizing noise. However, such conferred unlearnability is found fragile to adversarial training. In this paper, we design new methods to generate robust unlearnable examples that are protected from adversarial training. We first find that the vanilla error-minimizing noise, which suppresses the informative knowledge of data via minimizing the corresponding training loss, could not effectively minimize the adversarial training loss. This explains the vulnerability of error-minimizing noise in adversarial training. Based on the observation, robust error-minimizing noise is then introduced to reduce the adversarial training loss. Experiments show that the unlearnability brought by robust errorminimizing noise can effectively protect data from adversarial training in various scenarios. The code is available at https://github.com/fshp971/ robust-unlearnable-examples .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers32
- Raising the Cost of Malicious AI-Powered Image EditingHadi Salman, Alaa Khaddaj, Guillaume Leclerc, Andrew Ilyas et al.ICML 2023 · 181 citations
- Retrieval-Based Prompt Selection for Code-Related Few-Shot LearningNoor Nashid, Mifta Sintaha, Ali MesbahICSE 2023 · 156 citations
- FIBA: Frequency-Injection based Backdoor Attack in Medical Image AnalysisYu Feng, Benteng Ma, Jing Zhang, Shanshan Zhao et al.CVPR 2022 · 102 citations
- Autoregressive Perturbations for Data PoisoningPedro Sandoval Segura, Vasu Singla, Jonas Geiping, Micah Goldblum et al.NeurIPS 2022 · 62 citations
- Image Shortcut Squeezing: Countering Perturbative Availability Poisons with CompressionZhuoran Liu, Zhengyu Zhao, Martha A. LarsonICML 2023 · 51 citations
Builds on20
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 601 citations
Related papers
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
- Stable Unlearnable Example: Enhancing the Robustness of Unlearnable Examples via Stable Error-Minimizing NoiseYixin Liu, Kaidi Xu, Xun Chen, Lichao SunAAAI 2024 · 19 citations
- Ungeneralizable ExamplesJingwen Ye, Xinchao WangCVPR 2024 · 3 citations
- Asynchronous Event Error-Minimizing Noise for Safeguarding Event DatasetRuofei Wang, Peiqi Duan, Boxin Shi, Renjie WanICCV 2025 · 1 citation
- Towards Provably Unlearnable Examples via Bayes Error OptimizationRuihan Zhang, Jun Sun, Ee-Peng Lim, Peixin ZhangAAAI 2026
