Ulsan National Institute of Science and Technology (UNIST) logo

A technology has been developed that selectively deletes only personal data or copyright-infringing material learned by artificial intelligence (AI), while preserving recognition performance for similar normal data and blocking even the phenomenon of deleted information reemerging.

Ulsan National Institute of Science and Technology (UNIST) said on the 21st that a joint research team led by Graduate School of Artificial Intelligence Professor Yun Seong-hwan and Department of Industrial Engineering Professor Park Sae-rom developed a machine unlearning technology called Spotter. Machine unlearning is a technology that selectively removes only the influence of specific data or categories from a trained AI model. It can be used for requests to delete personal information in facial recognition services or to clean up harmful or illegal content.

The research team analyzed that existing technologies suffer from an over-deletion problem that erases normal information similar to the deletion target. They also identified a vulnerability in which the characteristics of the deletion target remain inside the model, allowing the erased function to be restored by retraining with a small amount of data. For example, when deleting cat information, recognition rates for tigers and leopards also drop, and feeding in just a few cat photos can revive the model's ability to distinguish cats.

Spotter is designed to retain the ability to distinguish normal information similar to the deletion target, while eliminating the ability to cluster common features from the deletion data. In experiments with a small image dataset, the recognition rate for the deletion target dropped to 0% and stayed at 0.24% even after a retraining attack. With existing technology, retraining on just five photos restored recognition rates from 71.10% to as high as 99.98%. Spotter maintained 99.96% recognition accuracy for the remaining, non-deleted categories.

The research team implemented Spotter as a plug-in that can be easily combined with existing unlearning methods. They said it is expected to be widely applicable to AI services where managing sensitive information is crucial, such as facial recognition, personal information protection, and harmful content deletion.

The study was accepted for presentation at the International Conference on Machine Learning (ICML), held in Seoul from the 6th to the 11th of this month. It was carried out with support from the Ministry of Science and ICT, the National Research Foundation of Korea (NRF), and the Institute of Information & communications Technology Planning & Evaluation (IITP).

※ This article has been translated by AI. Share your feedback here.