REVIEW 4 cited by
Federated Unlearning with Knowledge Distillation
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Federated Learning (FL) is designed to protect the data privacy of each client during the training process by transmitting only models instead of the original data. However, the trained model may memorize certain information about the training data. With the recent legislation on right to be forgotten, it is crucially essential for the FL model to possess the ability to forget what it has learned from each client. We propose a novel federated unlearning method to eliminate a client's contribution by subtracting the accumulated historical updates from the model and leveraging the knowledge distillation method to restore the model's performance without using any data from the clients. This method does not have any restrictions on the type of neural networks and does not rely on clients' participation, so it is practical and efficient in the FL system. We further introduce backdoor attacks in the training process to help evaluate the unlearning effect. Experiments on three canonical datasets demonstrate the effectiveness and efficiency of our method.
Forward citations
Cited by 4 Pith papers
-
Unlearning Clients, Features and Samples in Vertical Federated Learning
VFU-KD and VFU-GA unlearn clients, features, and samples in vertical federated learning with no communication during unlearning, using stored embeddings.
-
FedMUA: Exploring the Vulnerabilities of Federated Learning to Malicious Unlearning Attacks
A malicious federated-learning client can flip the global model's prediction on a target sample by crafting feature-unlearning requests on influence-function-selected samples.
-
Quantum-Inspired Audio Unlearning: Towards Privacy-Preserving Voice Biometrics
QPAudioEraser removes a target speaker or accent from a trained audio classifier by negating and mixing final-layer weights, relabeling forget samples, and maximizing prediction entropy.
-
DRAGD: A Federated Unlearning Data Reconstruction Attack Based on Gradient Differences
DRAGD and DRAGDP reconstruct erased federated-learning images by sequentially matching post-unlearning and pre-unlearning gradients, with DRAGDP adding a public-image prior.
Discussion (0). Continue with ORCID to comment.