A Duty to Forget, a Right to Be Assured? Exposing Vulnerabilities in Machine Unlearning Services

Hongsheng Hu,Shuo Wang,Jiamin Chang,Haonan Zhong,Ruoxi Sun,Shuang Hao,Haojin Zhu,Minhui Xue
DOI: https://doi.org/10.14722/ndss.2024.24252
2023-01-01
Abstract:The right to be forgotten requires the removal or "unlearning" of a user'sdata from machine learning models. However, in the context of Machine Learningas a Service (MLaaS), retraining a model from scratch to fulfill the unlearningrequest is impractical due to the lack of training data on the serviceprovider's side (the server). Furthermore, approximate unlearning furtherembraces a complex trade-off between utility (model performance) and privacy(unlearning performance). In this paper, we try to explore the potentialthreats posed by unlearning services in MLaaS, specifically over-unlearning,where more information is unlearned than expected. We propose two strategiesthat leverage over-unlearning to measure the impact on the trade-off balancing,under black-box access settings, in which the existing machine unlearningattacks are not applicable. The effectiveness of these strategies is evaluatedthrough extensive experiments on benchmark datasets, across various modelarchitectures and representative unlearning approaches. Results indicatesignificant potential for both strategies to undermine model efficacy inunlearning scenarios. This study uncovers an underexplored gap betweenunlearning and contemporary MLaaS, highlighting the need for carefulconsiderations in balancing data unlearning, model utility, and security.
What problem does this paper attempt to address?