{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/what-can-we-learn-from-unlearnable-datasets-1","title":"What Can We Learn from Unlearnable Datasets?","arxiv_id":"2305.19254","date":"2023-05-30","proceeding":"NeurIPS 2023 11","authors":["Pedro Sandoval-Segura","Vasu Singla","Jonas Geiping","Micah Goldblum","Tom Goldstein"],"abstract":"In an era of widespread web scraping, unlearnable dataset methods have the potential to protect data privacy by preventing deep neural networks from generalizing. But in addition to a number of practical limitations that make their use unlikely, we make a number of findings that call into question their ability to safeguard data. First, it is widely believed that neural networks trained on unlearnable datasets only learn shortcuts, simpler rules that are not useful for generalization. In contrast, we find that networks actually can learn useful features that can be reweighed for high test performance, suggesting that image protection is not assured. Unlearnable datasets are also believed to induce learning shortcuts through linear separability of added perturbations. We provide a counterexample, demonstrating that linear separability of perturbations is not a necessary condition. To emphasize why linearly separable perturbations should not be relied upon, we propose an orthogonal projection attack which allows learning from unlearnable datasets published in ICML 2021 and ICLR 2023. Our proposed attack is significantly less complex than recently proposed techniques.","url_abs":"https://arxiv.org/abs/2305.19254v3","url_pdf":"https://arxiv.org/pdf/2305.19254v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"what-can-we-learn-from-unlearnable-datasets-1","repo_url":"https://github.com/psandovalsegura/learn-from-unlearnable","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2305.19254","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2305.19254"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/psandovalsegura/learn-from-unlearnable","reach":null}],"summary":{"ran_fixture":2,"ran_violates":1,"ran_honours":1,"ran_draft_wrong":2,"unverified":1},"by_repo_kind":{"official":{"samples":7,"ran":6,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":7,"samples":[{"code_sha256_prefix":"4b7599d7bc4b87ea","entry":"accuracy","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"orthogonal_projection_step_2.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/orthogonal_projection_step_2.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"4b7599d7bc4b87ea"}},{"code_sha256_prefix":"e5220172f7aa9f0c","entry":"get_projection_vectors","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"utils_projection.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/utils_projection.py","link_basis":"first_harvest_node","language":"python","status":"ran_violates","verification_level":1,"contract_check":"VIOLATES","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e5220172f7aa9f0c"}},{"code_sha256_prefix":"3b3c31fb50ca361a","entry":"get_q_matrix","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"utils_projection.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/utils_projection.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"3b3c31fb50ca361a"}},{"code_sha256_prefix":"3718df2d9d83946f","entry":"normalize_zero_one","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"orthogonal_projection_step_1.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/orthogonal_projection_step_1.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"3718df2d9d83946f"}},{"code_sha256_prefix":"5bfde9f5c9d2a4c0","entry":"project_data","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"utils_projection.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/utils_projection.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"5bfde9f5c9d2a4c0"}},{"code_sha256_prefix":"0756a99508caf42c","entry":"rand_bbox","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"orthogonal_projection_step_2.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/orthogonal_projection_step_2.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"0756a99508caf42c"}},{"code_sha256_prefix":"e8cfe7fab2a6b0da","entry":"train","repo":"psandovalsegura/learn-from-unlearnable","repo_kind":"official","path":"orthogonal_projection_step_2.py","file_url":"https://github.com/psandovalsegura/learn-from-unlearnable/blob/HEAD/orthogonal_projection_step_2.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e8cfe7fab2a6b0da"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}