When Priors Backfire: On the Vulnerability of Unlearnable Examples to Pretraining
Zhihao Li, Gezheng Xu, Jiale Cai, Ruiyi Fang, Di Wu, Qicheng Lao, Charles Ling, Boyu Wang
Abstract
Unlearnable Examples (UEs) serve as a data protection strategy that generates imperceptible perturbations to mislead models into learning spurious correlations instead of underlying semantics. In this paper, we uncover a fundamental vulnerability of UEs that emerges when learning starts from a pretrained model. Crucially, our empirical analysis shows that even when data are protected by carefully crafted perturbations, pretraining priors still furnish rich semantic representations that allow the model to circumvent the shortcuts introduced by UEs and capture genuine features, thereby nullifying unlearnability. To address this, we propose (inding rtificial perturbations to ncorrect argets), a novel bi‑level optimization formulation. Specifically, the inner level aims at associating the perturbed samples with real labels to simulate standard data-label alignment, while the outer level actively disrupts this alignment by enforcing a mislabel-perturbation binding that maps samples to designated incorrect targets. This mechanism effectively overrides the semantic guidance of priors, forcing the model to rely on the injected perturbations and consequently preventing the acquisition of true semantics. Extensive experiments on standard benchmarks and multiple pretrained backbones demonstrate that BAIT effectively mitigates the influence of pretraining priors and maintains data unlearnability. Code is available at https://github.com/zhli-cs/BAIT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e78968dc-519c-4ecb-9fa9-59e58f201b2bCited by top-tier papers4
- FUSE: Full‑spectrum Unlearnable Examples via Spectral EqualizationJiale Cai, Gezheng Xu, Zhihao Li, Ruiyi Fang et al.ICML 2026 · 1 citation
- Dual-branch Robust Unlearnable ExamplesXianlong Wang, Hangtao Zhang, Wenbo Pan, Ziqi Zhou et al.ICML 2026 · 1 citation
- Discretized Density-Guided Source-Free Adaptation for Continuous TargetsGezheng Xu, Qi CHEN, QIUHAO Zeng, Charles X. Ling et al.ICML 2026
- Attention with Routed-Memory for Learnable Sparse ControlQIUHAO Zeng, Jerry Huang, Peng Lu, Ruiyi Fang et al.ICML 2026
Builds on37
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Unlearnable Examples: Making Personal Data UnexploitableHanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey et al.ICLR 2021 · 255 citations
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor et al.NeurIPS 2020 · 242 citations
Related papers
- A3: Few-shot Prompt Learning of Unlearnable Examples with Cross-Modal Adversarial Feature AlignmentXuan Wang, Xitong Gao, Dongping Liao, Tianrui Qin et al.CVPR 2025
- Unlearnable Clusters: Towards Label-Agnostic Unlearnable ExamplesJiaming Zhang, Xingjun Ma, Qi Yi, Jitao Sang et al.CVPR 2023
- Versatile Transferable Unlearnable Example GeneratorZhihao Li, Jiale Cai, Gezheng Xu, Hao Zheng et al.NeurIPS 2025 · 3 citations
- Unlearnable Examples Give a False Sense of Security: Piercing through Unexploitable Data with Learnable ExamplesWan Jiang, Yunfeng Diao, He Wang, Jianxin Sun et al.ACM MM 2023 · 14 citations
- How Far Are We from True Unlearnability?Kai Ye, Liangcai Su, Chenxiong QianICLR 2025
