{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/provably-unlearnable-examples","title":"Provably Unlearnable Data Examples","arxiv_id":"2405.03316","date":"2024-05-06","proceeding":null,"authors":["Derui Wang","Minhui Xue","Bo Li","Seyit Camtepe","Liming Zhu"],"abstract":"The exploitation of publicly accessible data has led to escalating concerns regarding data privacy and intellectual property (IP) breaches in the age of artificial intelligence. To safeguard both data privacy and IP-related domain knowledge, efforts have been undertaken to render shared data unlearnable for unauthorized models in the wild. Existing methods apply empirically optimized perturbations to the data in the hope of disrupting the correlation between the inputs and the corresponding labels such that the data samples are converted into Unlearnable Examples (UEs). Nevertheless, the absence of mechanisms to verify the robustness of UEs against uncertainty in unauthorized models and their training procedures engenders several under-explored challenges. First, it is hard to quantify the unlearnability of UEs against unauthorized adversaries from different runs of training, leaving the soundness of the defense in obscurity. Particularly, as a prevailing evaluation metric, empirical test accuracy faces generalization errors and may not plausibly represent the quality of UEs. This also leaves room for attackers, as there is no rigid guarantee of the maximal test accuracy achievable by attackers. Furthermore, we find that a simple recovery attack can restore the clean-task performance of the classifiers trained on UEs by slightly perturbing the learned weights. To mitigate the aforementioned problems, in this paper, we propose a mechanism for certifying the so-called $(q, \\eta)$-Learnability of an unlearnable dataset via parametric smoothing. A lower certified $(q, \\eta)$-Learnability indicates a more robust and effective protection over the dataset. Concretely, we 1) improve the tightness of certified $(q, \\eta)$-Learnability and 2) design Provably Unlearnable Examples (PUEs) which have reduced $(q, \\eta)$-Learnability.","url_abs":"https://arxiv.org/abs/2405.03316v2","url_pdf":"https://arxiv.org/pdf/2405.03316v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"provably-unlearnable-examples","repo_url":"https://github.com/neuralsec/certified-data-learnability","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"data-augmentation","task_name":"Data Augmentation"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2405.03316","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2405.03316"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/neuralsec/certified-data-learnability","reach":{"status":"ok"}}],"summary":{"ran":6,"ran_draft_wrong":1,"unverified":3},"by_repo_kind":{"official":{"samples":10,"ran":7,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":10,"samples":[{"code_sha256_prefix":"dfb395bae3d07d76","entry":"DenseNet121","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"models/DenseNet.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/models/DenseNet.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"dfb395bae3d07d76"}},{"code_sha256_prefix":"f295fe3c209ecf78","entry":"DenseNet169","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"models/DenseNet.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/models/DenseNet.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f295fe3c209ecf78"}},{"code_sha256_prefix":"6383aee1c940e7a5","entry":"DenseNet201","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"models/DenseNet.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/models/DenseNet.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"6383aee1c940e7a5"}},{"code_sha256_prefix":"508cc372f92de005","entry":"MNIST_fourpixel_triggerfunc","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"attack_lib.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/attack_lib.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"508cc372f92de005"}},{"code_sha256_prefix":"d97b19f1db6f5c5a","entry":"MNIST_onepixel_triggerfunc","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"attack_lib.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/attack_lib.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"d97b19f1db6f5c5a"}},{"code_sha256_prefix":"0f23e7e681845fe0","entry":"ResNet18","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"models/ResNet.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/models/ResNet.py","link_basis":"harvester_set","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"0f23e7e681845fe0"}},{"code_sha256_prefix":"21ba14c82993c2fe","entry":"ResNet50","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"models/ResNet.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/models/ResNet.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"21ba14c82993c2fe"}},{"code_sha256_prefix":"ac3dd06d1a08c549","entry":"ResNet34","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"models/ResNet.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/models/ResNet.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"ac3dd06d1a08c549"}},{"code_sha256_prefix":"afe95a5c13746d1d","entry":"certify","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"certify.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/certify.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"afe95a5c13746d1d"}},{"code_sha256_prefix":"aefa2123c98d35c6","entry":"patch_noise_extend_to_img","repo":"neuralsec/certified-data-learnability","repo_kind":"official","path":"dataset.py","file_url":"https://github.com/neuralsec/certified-data-learnability/blob/HEAD/dataset.py","link_basis":"plan_row","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"aefa2123c98d35c6"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}