2603.03725v1 Mar 04, 2026 cs.LG

왜 학습 불가능한 예제가 효과적인가: 상호 정보의 새로운 관점

Why Do Unlearnable Examples Work: A Novel Perspective of Mutual Information

Yifan Zhu
Yifan Zhu
Citations: 10
h-index: 2
Yibo Miao
Yibo Miao
Citations: 293
h-index: 10
Yinpeng Dong
Yinpeng Dong
Citations: 29
h-index: 3
Xiao-Shan Gao
Xiao-Shan Gao
Citations: 153
h-index: 7

인터넷에서 수집되는 방대한 양의 데이터는 딥러닝의 엄청난 발전을 이끌었습니다. 이러한 발전과 함께 데이터 프라이버시 및 보안에 대한 우려가 커지고 있습니다. 데이터가 무단 딥 모델에 의해 불법적으로 학습되는 것을 방지하기 위해, 일반화 능력을 저해하는 학습 불가능한 예제를 생성하는 다양한 방법들이 제안되었습니다. 그러나 기존의 접근 방식은 주로 경험적인 휴리스틱에 의존하기 때문에, 학습 불가능한 예제를 견고한 설명으로 개선하기 어렵습니다. 본 논문에서는 학습 불가능한 예제를 상호 정보 감소라는 새로운 관점에서 분석하고 개선합니다. 우리는 효과적인 학습 불가능한 예제가 항상 깨끗한 특징과 오염된 특징 사이의 상호 정보를 감소시키며, 네트워크가 깊어질수록 상호 정보가 낮아질수록 학습 불가능성이 더 향상된다는 것을 보여줍니다. 또한, 공분산 감소 관점에서, 클래스 내 오염된 특징들의 조건부 공분산을 최소화하면 분포 간의 상호 정보를 감소시킬 수 있음을 증명합니다. 이러한 이론적 결과를 바탕으로, 클래스 내 특징들의 코사인 유사도를 최대화하여 공분산을 줄임으로써 일반화 능력을 효과적으로 저해하는 새로운 학습 불가능한 방법인 Mutual Information Unlearnable Examples (MI-UE)를 제안합니다. 광범위한 실험 결과는 우리 방법이 기존 방법보다 훨씬 우수한 성능을 보이며, 심지어 방어 메커니즘 하에서도 효과적임을 보여줍니다.

Original Abstract

The volume of freely scraped data on the Internet has driven the tremendous success of deep learning. Along with this comes the growing concern about data privacy and security. Numerous methods for generating unlearnable examples have been proposed to prevent data from being illicitly learned by unauthorized deep models by impeding generalization. However, the existing approaches primarily rely on empirical heuristics, making it challenging to enhance unlearnable examples with solid explanations. In this paper, we analyze and improve unlearnable examples from a novel perspective: mutual information reduction. We demonstrate that effective unlearnable examples always decrease mutual information between clean features and poisoned features, and when the network gets deeper, the unlearnability goes better together with lower mutual information. Further, we prove from a covariance reduction perspective that minimizing the conditional covariance of intra-class poisoned features reduces the mutual information between distributions. Based on the theoretical results, we propose a novel unlearnable method called Mutual Information Unlearnable Examples (MI-UE) that reduces covariance by maximizing the cosine similarity among intra-class features, thus impeding the generalization effectively. Extensive experiments demonstrate that our approach significantly outperforms the previous methods, even under defense mechanisms.

3 Citations
0 Influential
5 Altmetric
28.0 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!