Do SSL Models Have Déjà Vu? A Case of Unintended Memorization in Self-supervised Learning
Casey Meehan, Florian Bordes, Pascal Vincent, Kamalika Chaudhuri, Chuan Guo
Abstract
Self-supervised learning (SSL) algorithms can produce useful image representations by learning to associate different parts of natural images with one another. However, when taken to the extreme, SSL models can unintendedly memorize specific parts in individual training samples rather than learning semantically meaningful associations. In this work, we perform a systematic study of the unintended memorization of image-specific information in SSL models -- which we refer to as déjà vu memorization. Concretely, we show that given the trained model and a crop of a training image containing only the background (e.g., water, sky, grass), it is possible to infer the foreground object with high accuracy or even visually reconstruct it. Furthermore, we show that déjà vu memorization is common to different SSL algorithms, is exacerbated by certain design choices, and cannot be detected by conventional techniques for evaluating representation quality. Our study of déjà vu memorization reveals previously unknown privacy risks in SSL models, as well as suggests potential practical mitigation strategies. Code is available at https://github.com/facebookresearch/DejaVu.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- Finding NeMo: Localizing Neurons Responsible For Memorization in Diffusion ModelsDominik Hintersdorf, Lukas Struppek, Kristian Kersting, Adam Dziedzic et al.NeurIPS 2024 · 46 citations
- ViP: A Differentially Private Foundation Model for Computer VisionYaodong Yu, Maziar Sanjabi, Yi Ma, Kamalika Chaudhuri et al.ICML 2024 · 19 citations
- Memorization in Self-Supervised Learning Improves Downstream GeneralizationWenhao Wang, Muhammad Ahmad Kaleem, Adam Dziedzic, Michael Backes et al.ICLR 2024 · 19 citations
- Localizing Memorization in SSL Vision EncodersWenhao Wang, Adam Dziedzic, Michael Backes, Franziska BoenischNeurIPS 2024 · 11 citations
- Rethinking the Role of Verbatim Memorization in LLM PrivacyTom Sander, Bargav Jayaraman, Mark Ibrahim, Kamalika Chaudhuri et al.NeurIPS 2025 · 5 citations
Builds on20
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec et al.NeurIPS 2020 · 9,171 citations
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou et al.ICCV 2021 · 8,921 citations
- Unsupervised Learning of Visual Features by Contrasting Cluster AssignmentsMathilde Caron, Ishan Misra, Julien Mairal, Priya Goyal et al.NeurIPS 2020 · 5,249 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
Related papers
- Measuring Dejavu Memorization EfficientlyNarine Kokhlikyan, Bargav Jayaraman, Florian Bordes, Chuan Guo et al.NeurIPS 2024 · 4 citations
- Bridging the Gap to Real-World Object-Centric LearningMaximilian Seitzer, Max Horn, Andrii Zadaianchuk, Dominik Zietlow et al.ICLR 2023 · 31 citations
- SUA: Stealthy Multimodal Large Language Model Unlearning AttackXianren Zhang, Hui Liu, Delvin Ce Zhang, Xianfeng Tang et al.EMNLP 2025
- Separating Knowledge and Perception with Procedural DataAdrián Rodríguez-Muñoz, Manel Baradad, Phillip Isola, Antonio TorralbaICML 2025
- Dataset Inference for Self-Supervised ModelsAdam Dziedzic, Haonan Duan, Muhammad Ahmad Kaleem, Nikita Dhawan et al.NeurIPS 2022 · 59 citations
