[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117643-en":3,"doc-seo-117643-105":30,"detail-sidebar-cat-0-en-105":84},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117643,13056703019662,"Evangeline","https://ap-avatar.wpscdn.com/avatar/be000253a8e92610077?_k=1778726343310543188",8,"Research & Report","Certified Data Removal from Machine Learning Models","Good data stewardship requires removal of data at the request of the data’s owner. This raises whether, and how, a trained machine-learning model that implicitly stores information about its training data should be affected by such a removal request. The work studies certified removal: a strong guarantee that the model after deletion cannot be distinguished from a model never trained on that data. It presents a certified-removal mechanism for linear classifiers and evaluates practical learning settings where the mechanism can be used.","View metadata, citation and similar [papers at ](papers at core.ac.uk)[core.ac.uk](papers at core.ac.uk) brought to you by CORE  \n[provided by](provided by arXiv.org)[ arXiv.org](provided by arXiv.org) e-Print Archive  \nCerti􀀌ed Data Removal from Machine Learning Models  \nChuan Guo Tom Goldstein Awni Hannun Laurens van der Maaten  \nFacebook AI Research, New York  \narXiv : 19 11 .03030v2 [ cs .LG] 11 Nov 2019  \nAbstract  \nGood data stewardship requires removal of data at the request of the data's owner.  \nThis raises the question if and how a trained machine-learning model, which implicitly stores information about its training data, should be a􀀋ected by such a removal request. Is it possible to \\remove\" data from a machine-learning model? We study this problem by de􀀌ning certi􀀌ed removal: a very strong theoretical guarantee that a model from which data is removed cannot be distinguished from a model that never observed the data to begin with. We develop a certi􀀌edremoval mechanism for linear classi􀀌ers and empirically study learning settings in which this mechanism is practical.  \n1 INTRODUCTION  \nMachine-learning models are often trained on thirdparty data, for example, many computer-vision models are trained on images provided by Flickr users (Thomee et al., 2016) . When a party requests that their data be removed from such online platforms, this raises the question how such a request should impact models that were trained prior to the removal. A similar question arises when a model is negatively impacted by a data-poisoning attack (Biggio et al., 2012) . Is it possible to \\remove\" data from a model without re-training that model from scratch?  \nWe study this question in a framework we call certi􀀌ed removal, which theoretically guarantees that an adversary cannot extract information about training data that was removed from a model. Inspired by di􀀋erential privacy (Dwork, 2011), certi􀀌ed removal bounds the max-divergence between the outputs of the model  \nfrom which the data was removed and the outputs of a model that never observed that data. This guarantees that membership-inference attacks (Yeom et al., 2018; Carlini et al., 2019) are unsuccessful on data that was removed from the model. We emphasize that certi􀀌ed removal is a very strong notion of removal; in practical applications, less constraining notions may equally ful􀀌ll the data owner's expectation of removal.  \nWe develop a certi􀀌ed-removal mechanism for L2-regularized linear models that are trained using a differentiable convex loss function, e.g. , logistic regressors. Our removal mechanism applies a Newton step on the model parameters that largely removes the in-􀀍uence of the deleted data point; the residual error of this mechanism decreases quadratically with the size of the training set. To ensure that an adversary cannot extract information from the small residual (i.e., to certify removal), we mask the residual using an approach that randomly perturbs the training loss (Chaudhuri et al., 2011) . We empirically study in which settings the removal mechanism is practical.  \n2 CERTIFIED REMOVAL  \nLet D be a 􀀌xed training dataset and let A be a (randomized) learning algorithm that trains on D and outputs a model h 2 H, that is, A : D ! H. Randomness in A induces a probability distribution over the models in the hypothesis set H. We would like to remove a training sample, x 2 D, from the output of A.  \nTo this end, we de􀀌ne a data-removal mechanism M that is applied to A (D) and aims to remove the in􀀍uence of x. If removal is successful, the output of M should be di􀀎cult to distinguish from the output of A applied on D n x. We say that removal mechanism M performs 􀀏-certi􀀌ed removal for learning algorithm A if 8T 􀀒 H ; D 􀀒 X ; x 2 D:  \ne 􀀀 􀀏 􀀔 P (M(A(D); D ; x) 2 T ) 􀀔 e􀀏 : (1)  \nP (A(D n x) 2 T )  \nThis de􀀌nition states that the ratio between the likelihood of (1) a model from which sample x was removed and (2) a model that was never trained on x to begin  \nwit","cbCaifXlhMq3DMoy","https://ap.wps.com/l/cbCaifXlhMq3DMoy","pdf",1908748,1,13,"English","en",105,"# Introduction\n## Certified removal framework\n## Relationship to differential privacy","[{\"question\":\"Why does certified removal help against membership inference attacks?\",\"answer\":\"By bounding the divergence between outputs with and without the removed sample, the guarantee makes membership inference unsuccessful for data that was removed.\"}]","Certified Data Removal from Machine Learning Models | PDF",1785677572,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":79,"head_meta":81,"extra_data":83,"updated_unix":28},"certified-data-removal-from-machine-learning-models","",{"@graph":36,"@context":78},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/certified-data-removal-from-machine-learning-models/117643/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-02",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72],{"name":73,"@type":74,"acceptedAnswer":75},"Why does certified removal help against membership inference attacks?","Question",{"text":76,"@type":77},"By bounding the divergence between outputs with and without the removed sample, the guarantee makes membership inference unsuccessful for data that was removed.","Answer","https://schema.org",{"og:url":52,"og:type":80,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":82,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":85},[86,90,94,98,103,108,113,116,121,124,128],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":87,"show_sort_weight":88,"slug":89},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":91,"show_sort_weight":92,"slug":93},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Exam",70,"exam",{"id":99,"doc_module":4,"doc_module_name":46,"category_name":100,"show_sort_weight":101,"slug":102},5,"Comic",60,"comic",{"id":104,"doc_module":4,"doc_module_name":46,"category_name":105,"show_sort_weight":106,"slug":107},6,"Technology",50,"technology",{"id":109,"doc_module":4,"doc_module_name":46,"category_name":110,"show_sort_weight":111,"slug":112},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":114,"slug":115},30,"research-report",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},9,"Religion & Spirituality",20,"religion-spirituality",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":122,"show_sort_weight":119,"slug":123},"World Cup","world-cup",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":125,"slug":127},10,"Lifestyle","lifestyle",{"id":129,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":99,"slug":131},19,"General","general"]