Federated Unlearning: A Survey on Methods, Design Guidelines, and Evaluation Metrics
arXiv:2401.05146 · doi:10.1109/TNNLS.2024.3478334
Abstract
Federated learning (FL) enables collaborative training of a machine learning (ML) model across multiple parties, facilitating the preservation of users' and institutions' privacy by maintaining data stored locally. Instead of centralizing raw data, FL exchanges locally refined model parameters to build a global model incrementally. While FL is more compliant with emerging regulations such as the European General Data Protection Regulation (GDPR), ensuring the right to be forgotten in this context - allowing FL participants to remove their data contributions from the learned model - remains unclear. In addition, it is recognized that malicious clients may inject backdoors into the global model through updates, e.g., to generate mispredictions on specially crafted data examples. Consequently, there is the need for mechanisms that can guarantee individuals the possibility to remove their data and erase malicious contributions even after aggregation, without compromising the already acquired "good" knowledge. This highlights the necessity for novel federated unlearning (FU) algorithms, which can efficiently remove specific clients' contributions without full model retraining. This article provides background concepts, empirical evidence, and practical guidelines to design/implement efficient FU schemes. This study includes a detailed analysis of the metrics for evaluating unlearning in FL and presents an in-depth literature review categorizing state-of-the-art FU contributions under a novel taxonomy. Finally, we outline the most relevant and still open technical challenges, by identifying the most promising research directions in the field.
21 pages, 6 figures, and 6 tables
References in corpus (28)
- Adam: A Method for Stochastic Optimization
- A Survey on Knowledge Graphs: Representation, Acquisition and Applications
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
- Understanding Black-box Predictions via Influence Functions
- Fine-Grained Visual Classification of Aircraft
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- How To Backdoor Federated Learning
- Measuring the Effects of Non-Identical Data Distribution for Federated Visual Classification
- Stein Variational Gradient Descent: A General Purpose Bayesian Inference Algorithm
- A Survey on Homomorphic Encryption Schemes: Theory and Implementation
- Differentially Private Federated Knowledge Graphs Embedding
- A Review on Machine Unlearning
- Multi-Participant Multi-Class Vertical Federated Learning
- A Survey of Machine Unlearning
- Preservation of the Global Knowledge by Not-True Distillation in Federated Learning
- Federated Unlearning with Knowledge Distillation
- Federated Unlearning: How to Efficiently Erase a Client in FL?
- VeriFi: Towards Verifiable Federated Unlearning
- Learn to Unlearn: A Survey on Machine Unlearning
- A Survey on Federated Unlearning: Challenges, Methods, and Future Directions
- Subspace based Federated Unlearning
- Machine Unlearning of Federated Clusters
- Re-Weighted Softmax Cross-Entropy to Control Forgetting in Federated Learning
- QuickDrop: Efficient Federated Unlearning by Integrated Dataset Distillation
- Forgettable Federated Linear Learning with Certified Data Unlearning
- Exploring Federated Unlearning: Review, Comparison, and Insights
- Federated Unlearning via Class-Discriminative Pruning
- Federated Learning Over Images: Vertical Decompositions and Pre-Trained Backbones Are Difficult to Beat