信息网络安全 ›› 2026, Vol. 26 ›› Issue (7): 1149-1163.doi: 10.3969/j.issn.1671-1122.2026.07.011

• AI安全防御 • 上一篇    下一篇

基于知识蒸馏和对抗样本的联邦遗忘方法

宋孟元, 夏辉()   

  1. 中国海洋大学信息科学与工程学部计算机科学与技术学院青岛 266100
  • 收稿日期:2025-12-03 出版日期:2026-07-10 发布日期:2026-09-03
  • 通讯作者: 夏辉 E-mail:xiahui@ouc.edu.cn
  • 作者简介:宋孟元(2001—),男,山东,硕士研究生,主要研究方向为隐私保护、联邦学习和人工智能安全|夏辉(1986—),男,山东,教授,博士,主要研究方向为无线自组织网络、物联网安全和人工智能安全
  • 基金资助:
    国家自然科学基金(62572448);国家自然科学基金(62172377);国家重点研发计划(2024YFB3311802);泰山学者工程(tsqn202312102);山东省自然科学基金(ZR2025QA25)

Federated unlearning via knowledge distillation and adversarial examples

Song Mengyuan, Xia Hui()   

  1. College of Computer Science and Technology Faculty of Information Science and Engineering, Ocean University of China, Qingdao 266100, China
  • Received:2025-12-03 Online:2026-07-10 Published:2026-09-03
  • Contact: Xia Hui E-mail:xiahui@ouc.edu.cn

摘要:

随着人工智能技术的迅猛发展,联邦学习已在医疗、金融等多个领域得到广泛应用。然而,面对日益严峻的隐私保护需求,如何在保障数据隐私的前提下高效地从模型中删除敏感信息,仍是一项具有挑战性的任务。为此,文章提出一种基于知识蒸馏和对抗样本的联邦遗忘方法,旨在兼顾模型效用与隐私性的同时,尽可能降低遗忘过程的时间开销。为验证所提方法的有效性,文章设计了两种应用场景,并选用4个数据集及6种主流基准方法开展对比实验。实验结果表明,所提方法在模型可用性、隐私性和运行效率3个方面实现了良好的平衡。在CIFAR-10和SVHN数据集上,与6种基准方法相比,该方法在保持模型可用性基本不变的前提下,显著提升了隐私性和运行效率。

关键词: 联邦遗忘, 机器遗忘, 联邦学习, 对抗样本, 知识蒸馏

Abstract:

With the rapid advancement of artificial intelligence, federated learning has been widely adopted in multiple sensitive domains such as healthcare and finance. However, amid growing demands for privacy protection, how to efficiently remove sensitive information from models while preserving data privacy remains a challenging task. To address this issue, this paper proposed a federated unlearning method that combines knowledge distillation with adversarial examples, aiming to balance model utility and privacy while minimizing the time overhead of the unlearning process. To validate the effectiveness of the proposed method, we designed two application scenarios and conducted comparative experiments using four datasets and six mainstream baseline methods. Experimental results demonstrate that the proposed method achieves a favorable trade-off among model usability, privacy, and runtime efficiency. On the CIFAR-10 and SVHN datasets, compared with the six baseline methods, our approach significantly improves privacy protection and runtime efficiency while maintaining model usability at a comparable level.

Key words: federated unlearning, machine unlearning, federated learning, adversarial examples, knowledge distillation

中图分类号: