Source Models Leak What They Shouldn’t: Unlearning Zero-Shot Transfer in Domain Adaptation Through Adversarial Optimization
Arnav Devalapally, Poornima Jain, Kartik Srinivas, Vineeth Balasubramanian
摘要
The increasing adaptation of vision models across domains, such as satellite imagery and medical scans, has raised an emerging privacy risk: models may inadvertently retain and leak sensitive source-domain specific information in the target domain. This creates a compelling use case for machine unlearning to protect the privacy of sensitive source-domain data. Among adaptation techniques, source-free domain adaptation (SFDA) calls for an urgent need for machine unlearning (MU), where the source data itself is protected, yet the source model exposed during adaptation encodes its influence. Our experiments reveal that existing SFDA methods exhibit strong zero-shot performance on sourceexclusive classes in the target domain, indicating they inadvertently leak knowledge of these classes into the target domain, even when they are not represented in the target data. We identify and address this risk by proposing an MU setting called SCADA-UL: Unlearning Source-exclusive ClAsses in Domain Adaptation. Existing MU methods do not address this setting as they are not designed to handle data distribution shifts. We propose a new unlearning method, where an adversarially generated forget class sample is unlearned by the model during the domain adaptation process using a novel rescaled labeling strategy and adversarial optimization. We also extend our study to two variants: a continual version of this problem setting and to one where the specific source classes to be forgotten may be unknown. Alongside theoretical interpretations, our comprehensive empirical results show that our method consistently outperforms baselines in the proposed setting while achieving retraining-level unlearning performance on benchmark datasets. Our code is available at https://github.com/D-Arnav/SCADA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- Moment Matching for Multi-Source Domain AdaptationXingchao Peng, Qinxun Bai, Xide Xia, Zijun Huang 等ICCV 2019 · 被引用 2,239 次
- Do We Really Need to Access the Source Data? Source Hypothesis Transfer for Unsupervised Domain AdaptationJian Liang, Dapeng Hu, Jiashi FengICML 2020 · 被引用 1,624 次
- Certified Data Removal from Machine Learning ModelsChuan Guo, Tom Goldstein, Awni Y. Hannun, Laurens van der MaatenICML 2020 · 被引用 633 次
- DeltaGrad: Rapid retraining of machine learning modelsYinjun Wu, Edgar Dobriban, Susan B. DavidsonICML 2020 · 被引用 262 次
- Can Bad Teaching Induce Forgetting? Unlearning in Deep Networks Using an Incompetent TeacherVikram S. Chundawat, Ayush K. Tarun, Murari Mandal, Mohan S. KankanhalliAAAI 2023 · 被引用 247 次
相关 Paper
- Quantifying Samples with Invariance for Source-Free Class Incremental Domain AdaptationZhiyu Ye, Guowen Li, Haoyuan Liang, Zixi Wang 等ACM MM 2025 · 被引用 1 次
- Balancing Discriminability and Transferability for Source-Free Domain AdaptationJogendra Nath Kundu, Akshay R. Kulkarni, Suvaansh Bhambri, Deepesh Mehta 等ICML 2022 · 被引用 110 次
- Efficient Source-free Unlearning via Energy-Guided Data Synthesis and Discrimination-Aware Multitask OptimizationXiuyuan Wang, Chaochao Chen, Weiming Liu, Xinting Liao 等ICML 2025
- Revisiting Source-Free Domain Adaptation: Insights into Representativeness, Generalization, and VarietyRonghang Zhu, Mengxuan Hu, Weiming Zhuang, Lingjuan Lyu 等CVPR 2025
- Exploring Domain-Invariant Parameters for Source Free Domain AdaptationFan Wang, Zhongyi Han, Yongshun Gong, Yilong YinCVPR 2022 · 被引用 90 次
