Data Redaction from Pre-trained GANs

Data Redaction from Pre-trained GANs
复制标题

DOI:
10.1109/satml54575.2023.00048
复制
发表时间:
2022-06
期刊:
2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)
影响因子:
--
通讯作者:
Zhifeng Kong;Kamalika Chaudhuri
Zhifeng Kong;Kamalika Chaudhuri
中科院分区:
其他
文献类型:
--
作者:
Zhifeng Kong;Kamalika Chaudhuri

文献摘要

相似文献

众所周知,大型预训练的通用模型偶尔会输出难以理解的样本,这使他们的可信度不足。在这项工作中,并非总是充分解决问题,我们采用不同的,更友好的方法“编辑”或避免输出某些样本。我们表明,修复是与数据删除的根本不同的任务,并且数据删除可能并不总是会导致重新介绍。对数据修订的三种不同的算法,这些算法在现实世界图像数据集上进行了广泛的评估。能够以全面重新训练成本的一小部分保留高发电质量的同时编辑数据,
Large pre-trained generative models are known to occasionally output undesirable samples, which undermines their trustworthiness. The common way to mitigate this is to re-train them differently from scratch using different data or different regularization - which uses a lot of computational resources and does not always fully address the problem. In this work, we take a different, more compute- friendly approach and investigate how to post-edit a model after training so that it “redacts”, or refrains from outputting certain kinds of samples. We show that redaction is a fundamentally different task from data deletion, and data deletion may not always lead to redaction. We then consider Generative Adversar-ial Networks (GANs), and provide three different algorithms for data redaction that differ on how the samples to be redacted are described. Extensive evaluations on real-world image datasets show that our algorithms out-perform data deletion baselines, and are capable of redacting data while retaining high generation quality at a fraction of the cost of full re- training,