Forgetting Outside the Box: Scrubbing Deep Networks of Information Accessible from Input-Output Observations
We describe a procedure for removing dependency on a cohort of training data\nfrom a trained deep network that improves upon and generalizes previous methods\nto different readout functions and can be extended to ensure forgetting in the\nactivations of the network. We introduce a new bound on how much information\ncan be extracted per query about the forgotten cohort from a black-box network\nfor which only the input-output behavior is observed. The proposed forgetting\nprocedure has a deterministic part derived from the differential equations of a\nlinearized version of the model, and a stochastic part that ensures information\ndestruction by adding noise tailored to the geometry of the loss landscape. We\nexploit the connections between the activation and weight dynamics of a DNN\ninspired by Neural Tangent Kernels to compute the information in the\nactivations.\n
Paper
References (43)
Scroll for more · 31 remaining