Transferable Unlearnable Examples

Jie RenHan XuYuxuan WanXingjun MaLichao SunJiliang Tang

article2023ICLR64 citations

Develops a Classwise Separability Discriminant framework to generate unlearnable data perturbations that reliably transfer across diverse training settings and datasets, preventing unauthorized machine learning models from exploiting published personal data.

Listen

Unauthorized exploitation of personal data published online has become a serious privacy concern, prompting the development of "unlearnable" data strategies. These methods inject subtle, human-imperceptible perturbations into published datasets so that any machine learning models trained on them fail to recognize clean test data. However, existing protection methods fail across two critical dimensions: training-wise transferability (defenses designed against supervised learning fail against unsupervised methods, and vice versa) and data-wise transferability (defenses generated for one dataset lose effectiveness when applied to other datasets or streaming data).

The article aims to evaluate these transferability vulnerabilities and demonstrate a novel framework, called Transferable Unlearnable Examples (TUE), that provides robust, dual-setting protection across both supervised and unsupervised training while transferring seamlessly to unseen datasets.

To develop this solution, the authors introduced an optimizable metric termed Classwise Separability Discriminant (CSD), which maximizes inter-class separation while minimizing intra-class perturbation distance. They integrated CSD into an unsupervised contrastive learning objective through a bi-level optimization scheme. The framework was evaluated across standard image benchmarks (CIFAR-10, CIFAR-100, and SVHN) using various unsupervised backbones (SimCLR, MoCo, and SimSiam) against established baselines.

The findings demonstrate four primary results. First, standard baselines fail across training regimes: Error-Minimizing Noise (EMN) reduces supervised test accuracy to 14.7% on CIFAR-10 but leaves unsupervised training virtually unaffected at 89.8%, whereas Unlearnable Contrastive Learning (UCL) drops unsupervised accuracy to 47.8% while leaving supervised accuracy intact at 92.9%. Second, TUE succeeds across both regimes simultaneously, suppressing CIFAR-10 supervised accuracy to approximately 10% and unsupervised linear probing accuracy to roughly 35–52%. Third, on CIFAR-100, TUE reduces unauthorized supervised accuracy to under 2% and unsupervised accuracy to below 24%. Fourth, TUE demonstrates superior data-wise transferability: when perturbations generated on CIFAR-10 are transferred via class or sample interpolation to SVHN and CIFAR-100, unauthorized model accuracy remains strictly suppressed around 5–14%, whereas existing optimization-based baselines degrade sharply.

These results imply that organizations and users can reliably safeguard public visual data using a single, unified protection mechanism rather than repeatedly engineering customized defenses for every new dataset or training paradigm. By providing an optimizable framework that embeds both samplewise and classwise features, TUE significantly reduces operational overhead while closing the security loophole created when unauthorized actors switch from supervised to self-supervised learning pipelines.

Organizations seeking to protect public-facing visual data should adopt linear-separable perturbation strategies like TUE to secure assets against unauthorized model training. When deploying across evolving datasets with varying class counts, practitioners should use class and sample interpolation to extend existing perturbations efficiently. Future work should validate these techniques against broader downstream tasks, emerging self-supervised architectures, and non-vision data modalities.

arXiv: 2210.10114

No sufficiently relevant recommendations were found.

Cover for Transferable Unlearnable Examples

Abstract

With more people publishing their personal data online, unauthorized data usage has become a serious concern. The unlearnable strategies have been introduced to prevent third parties from training on the data without permission. They add perturbations to the users' data before publishing, which aims to make the models trained on the perturbed published dataset invalidated. These perturbations have been generated for a specific training setting and a target dataset. However, their unlearnable effects significantly decrease when used in other training settings and datasets. To tackle this issue, we propose a novel unlearnable strategy based on Classwise Separability Discriminant (CSD), which aims to better transfer the unlearnable effects to other training settings and datasets by enhancing the linear separability. Extensive experiments demonstrate the transferability of the proposed unlearnable examples across training settings and datasets.

Table of Contents

  • 1 Introduction
  • 2 Related Work
  • 3 Preliminary
  • 3.1 Definitions
  • 3.2 Transferability in Existing Methods
  • 3.2.1 Training-wise Transferability
  • 3.2.2 Data-wise Transferability
  • 3.3 Discussions
  • 4 Transferable Unlearnability from Classwise Separability Discriminant
  • 4.1 Classwise Separability Discriminant
  • 4.2 Transferable Unlearnable Examples
  • 5 Experiment
  • 5.1 Experimental Setups
  • 5.2 Training-wise transferable unlearnability
  • 5.3 Data-wise transferable unlearnability
  • 5.4 Linear Separability of Transferable Unlearnable Examples
  • 5.5 Case Study
  • 6 Conclusion
  • References
  • A Existing unlearnable methods cannot protect unlabeled dataset in a training-wise trasnferable way
  • B Details of experimental settings
  • B.1 Settings of generation process
  • B.2 Settings of evaluation stage

Knowls

  1. Knowl 1 — Classwise Separability Discriminant

    model/method

    The Classwise Separability Discriminant (CSD) is an objective function that quantifies and optimizes the linear separability of perturbations across classes in the input space, independent of the underlying clean images.

    Given a set of perturbations {δi}i=1n⊂Rd\{\delta_i\}_{i=1}^n \subset \mathbb{R}^d associated with ground truth class labels yi∈{1,…,M}y_i \in \{1, \dots, M\} for a dataset with MM classes, the centroid ckc_k of perturbations belonging to class kk is defined as:

    ck=1∣{i:yi=k}∣∑i:yi=kδic_k = \frac{1}{|\{i : y_i = k\}|} \sum_{i: y_i = k} \delta_i

    The intra-class distance σk\sigma_k for class kk measures the average Euclidean distance d(⋅,⋅)d(\cdot, \cdot) from each perturbation in class kk to its centroid ckc_k:

    σk=1∣{i:yi=k}∣∑i:yi=kd(δi,ck)\sigma_k = \frac{1}{|\{i : y_i = k\}|} \sum_{i: y_i = k} d(\delta_i, c_k)

    The inter-class distance di,jd_{i,j} between classes ii and jj is the Euclidean distance between their centroids:

    di,j=d(ci,cj)d_{i,j} = d(c_i, c_j)

    The Classwise Separability Discriminant loss LS({δi,yi}i=1n)L_S(\{\delta_i, y_i\}_{i=1}^n) is the average ratio of combined intra-class spread to inter-class centroid distance across all distinct class pairs:

    LS({δi,yi}i=1n)=1M∑i=1M1M−1∑j=1,j≠iM(σi+σjdi,j)L_S(\{\delta_i, y_i\}_{i=1}^n) = \frac{1}{M} \sum_{i=1}^M \frac{1}{M - 1} \sum_{j=1, j \neq i}^M \left( \frac{\sigma_i + \sigma_j}{d_{i,j}} \right)

    Minimizing LSL_S reduces the intra-class variance and maximizes the distance between class centroids, yielding compact and linearly separable perturbation clusters in input space that do not depend on the input features xix_i.

  2. Knowl 2 — Transferable Unlearnable Examples Bi-Level Optimization

    model/method

    Transferable Unlearnable Examples (TUE) optimizes noise perturbations to simultaneously prevent unauthorized supervised and unsupervised learning while enabling data-wise transfer across datasets. TUE combines an unsupervised contrastive loss with the Classwise Separability Discriminant (CSD) through a bi-level min-min optimization formulation:

    min⁡θmin⁡{δi:∥δi∥∞≤ϵ}∑i=1nLCL(f(θ,T1(xi+δi)),f(θ,T2(xi+δi)))+λLS({δi,yi}i=1n)\min_\theta \min_{\{\delta_i : \|\delta_i\|_\infty \le \epsilon\}} \sum_{i=1}^n L_{CL}\left(f(\theta, T_1(x_i + \delta_i)), f(\theta, T_2(x_i + \delta_i))\right) + \lambda L_S(\{\delta_i, y_i\}_{i=1}^n)

    where xi∈Rdx_i \in \mathbb{R}^d is a training sample, yi∈{1,…,M}y_i \in \{1, \dots, M\} is its class label, δi∈Rd\delta_i \in \mathbb{R}^d is the perturbation constrained under the ℓ∞\ell_\infty norm by ϵ\epsilon, θ\theta represents the parameters of the encoder network ff, T1T_1 and T2T_2 are random data augmentations, LCLL_{CL} is an unsupervised contrastive loss function (e.g., SimCLR, MoCo, or SimSiam), LSL_S is the Classwise Separability Discriminant, and λ>0\lambda > 0 balances the two objectives.

    The optimization is executed via alternating gradient steps:

    1. Update network parameters θ\theta to minimize contrastive loss on perturbed augmented views:

    θ(t)=arg⁡min⁡θ∑xi∈DcLCL(f(θ,T1(xi+δi(t−1))),f(θ,T2(xi+δi(t−1))))\theta^{(t)} = \arg\min_\theta \sum_{x_i \in \mathcal{D}_c} L_{CL}\left(f(\theta, T_1(x_i + \delta_i^{(t-1)})), f(\theta, T_2(x_i + \delta_i^{(t-1)}))\right)

    1. Update perturbations {δi}\{\delta_i\} jointly to minimize contrastive loss and enforce linear separability:

    {δi(t)}=arg⁡min⁡{δi:∥δi∥∞≤ϵ}∑i=1nLCL(f(θ(t),T1(xi+δi)),f(θ(t),T2(xi+δi)))+λLS({δi,yi}i=1n)\{\delta_i^{(t)}\} = \arg\min_{\{\delta_i : \|\delta_i\|_\infty \le \epsilon\}} \sum_{i=1}^n L_{CL}\left(f(\theta^{(t)}, T_1(x_i + \delta_i)), f(\theta^{(t)}, T_2(x_i + \delta_i))\right) + \lambda L_S(\{\delta_i, y_i\}_{i=1}^n)

    The LCLL_{CL} term creates shortcut features across augmented views to invalidate self-supervised representation learning, while LSL_S establishes linear separability across classes to destroy supervised learning and enable cross-dataset transfer.

  3. Knowl 3 — Training-wise and Data-wise Transferability of Unlearnable Examples

    definition

    Let Dc={(xi,yi)}i=1n\mathcal{D}_c = \{(x_i, y_i)\}_{i=1}^n be a clean training dataset with samples xi∈X⊂Rdx_i \in \mathcal{X} \subset \mathbb{R}^d and labels yi∈Y={1,…,K}y_i \in \mathcal{Y} = \{1, \dots, K\}. An unlearnable dataset Du={(xi+δi,yi)}i=1n\mathcal{D}_u = \{(x_i + \delta_i, y_i)\}_{i=1}^n is generated with perturbations δi∈ΔDc\delta_i \in \Delta_{\mathcal{D}_c} subject to ∥δi∥p≤ϵ\|\delta_i\|_p \le \epsilon such that a model trained on Du\mathcal{D}_u achieves poor accuracy when evaluated on clean test data.

    • Training-wise Transferability: The property that perturbations designed to induce unlearnability under one training framework (such as supervised Empirical Risk Minimization) remain effective at preventing unauthorized parties from learning useful representations when trained under alternative paradigms (such as pre-training an unsupervised feature extractor gηg_\eta on Du\mathcal{D}_u using contrastive learning, followed by downstream fine-tuning or linear probing).

    • Data-wise Transferability: The property that a perturbation set ΔDc\Delta_{\mathcal{D}_c} optimized for a source dataset Dc\mathcal{D}_c can be directly transferred onto an unseen target dataset D~c={(x~i,y~i)}i=1n~\tilde{\mathcal{D}}_c = \{(\tilde{x}_i, \tilde{y}_i)\}_{i=1}^{\tilde{n}} by assigning perturbations δH(i)∈ΔDc\delta_{H(i)} \in \Delta_{\mathcal{D}_c} to target samples as D~u={(x~i+δH(i),y~i)}i=1n~\tilde{\mathcal{D}}_u = \{(\tilde{x}_i + \delta_{H(i)}, \tilde{y}_i)\}_{i=1}^{\tilde{n}} via an indexing function H(i)H(i), thereby rendering D~c\tilde{\mathcal{D}}_c unlearnable without retraining the perturbation set.

  4. Knowl 4 — Linear Perturbation Interpolation for Cross-Dataset Transfer

    model/method

    When transferring a perturbation set ΔDc\Delta_{\mathcal{D}_c} generated on a source dataset Dc\mathcal{D}_c to an unseen target dataset D~c\tilde{\mathcal{D}}_c with more classes (Ktarget>KsourceK_{\text{target}} > K_{\text{source}}) or more samples per class (ntarget>nsourcen_{\text{target}} > n_{\text{source}}), linear interpolation synthesizes additional perturbations while retaining linear separability:

    1. Inter-class Interpolation (generating perturbations for new classes): For two perturbations δi\delta_i and δj\delta_j belonging to different source classes (yi≠yjy_i \neq y_j), a new class perturbation δk∗\delta_k^* is synthesized as:

    δk∗=αδi+(1−α)δjwhere yi≠yj,  α∈(0,1)\delta_k^* = \alpha \delta_i + (1 - \alpha) \delta_j \quad \text{where } y_i \neq y_j, \; \alpha \in (0, 1)

    1. Intra-class Interpolation (generating additional perturbations within an existing class): For two perturbations δi\delta_i and δj\delta_j belonging to the same source class (yi=yjy_i = y_j), an additional intra-class perturbation δk∗\delta_k^* is synthesized as:

    δk∗=αδi+(1−α)δjwhere yi=yj,  α∈(0,1)\delta_k^* = \alpha \delta_i + (1 - \alpha) \delta_j \quad \text{where } y_i = y_j, \; \alpha \in (0, 1)

    Varying the scalar parameter α\alpha generates arbitrarily sized perturbation sets matching the dimension and class count of the target dataset without re-running optimization.

  5. Knowl 5 — Training-wise Transferability Comparison Across Supervised and Unsupervised Learning

    data/table

    Performance of unlearnable example methods on CIFAR-10 and CIFAR-100 evaluated under supervised training (CrossEntropy Loss on ResNet-18) and unsupervised training (linear probing after 1000 pretraining epochs using SimCLR, MoCo, and SimSiam). Perturbations are constrained by ∥δi∥∞≤8/255\|\delta_i\|_\infty \le 8/255.

    Dataset CIFAR-10 CIFAR-100
    Method Supervised (%) Unsupervised (%) Supervised (%) Unsupervised (%)
    SimCLR Backbone
    Clean Data 93.79 90.04 74.49 63.68
    EMN 14.74 89.79 5.23 62.00
    SN 19.23 88.93 2.13 62.31
    UCL 92.86 47.78 72.17 16.68
    TUE 10.67 52.38 0.76 19.51
    MoCo Backbone
    Clean Data 93.79 89.90 74.49 63.03
    EMN 14.74 89.18 5.23 60.62
    SN 19.23 89.32 2.13 61.81
    UCL 92.62 44.24 71.59 18.74
    TUE 10.06 63.38 1.09 23.60
    SimSiam Backbone
    Clean Data 93.79 90.59 74.49 64.69
    EMN 14.74 91.43 5.23 65.96
    SN 19.23 91.54 2.13 66.83
    UCL 93.50 30.43 71.84 4.64
    TUE 10.03 35.57 1.21 6.17

    Supervised methods (EMN, SN) suppress supervised accuracy to ≤19.23%\le 19.23\% on CIFAR-10 and ≤5.23%\le 5.23\% on CIFAR-100, but fail against unsupervised learning (accuracy remains ≈89%−91%\approx 89\% - 91\% on CIFAR-10). Unsupervised Unlearnable Contrastive Learning (UCL) suppresses unsupervised learning to 30.43%−47.78%30.43\% - 47.78\% on CIFAR-10 but provides almost no protection in supervised training (92.62%−93.50%92.62\% - 93.50\%). TUE achieves unlearnability across both regimes, reducing supervised accuracy to ≈10%\approx 10\% on CIFAR-10 and ≈1%\approx 1\% on CIFAR-100 while maintaining unsupervised unlearnability comparable to UCL.

  6. Knowl 6 — Robustness of Unlearnability Under Sample-Perturbation Swapping

    data/table

    Supervised test accuracy (%) on ResNet-18 when testing data-wise transferability by swapping perturbation assignments within the same training dataset. In intra-class swapping, sample xix_i is perturbed by δj\delta_j where yj=yi,j≠iy_j = y_i, j \neq i. In inter-class swapping, sample xix_i is perturbed by δj\delta_j where yj≠yi,j≠iy_j \neq y_i, j \neq i.

    Dataset Methods Original (%) Intra (%) Inter (%)
    CIFAR-10 EMN 15.88 30.74 33.91
    SN 14.07 13.59 13.15
    TUE (SimCLR) 10.67 10.16 10.90
    TUE (MoCo) 10.06 12.04 8.57
    TUE (SimSiam) 10.03 10.25 10.47
    CIFAR-100 EMN 6.59 21.63 35.50
    SN 2.13 2.44 2.73
    TUE (SimCLR) 0.76 1.11 1.13
    TUE (MoCo) 1.09 1.25 3.63
    TUE (SimSiam) 1.21 1.28 1.08

    EMN unlearnability degrades under swapping (test accuracy rises by 15.04%15.04\% for intra-class swap and 28.91%28.91\% for inter-class swap on CIFAR-100) because EMN perturbations depend heavily on sample-specific image content xix_i. In contrast, TUE perturbations rely on classwise linear separability, keeping variation under swapping below 3%3\% and preserving unlearnability.

  7. Knowl 7 — Cross-Dataset Transferability of Unlearnable Perturbations

    data/table

    Supervised test accuracy (%) on non-target datasets when applying unlearnable perturbations generated exclusively on CIFAR-10. Evaluated datasets include SVHN-small (5,000 images per class sampled from SVHN), CIFAR-100 (100 classes, using inter-class interpolation), and full SVHN (73,257 images, using intra-class interpolation).

    Method SVHN-small (%) CIFAR-100 (%) SVHN (%)
    EMN 27.59 21.80 24.72
    SN 9.58 9.35 7.77
    TUE (SimCLR) 9.77 10.53 11.72
    TUE (MoCo) 11.29 8.32 13.95
    TUE (SimSiam) 10.28 5.10 12.93

    When EMN perturbations optimized for CIFAR-10 are transferred to SVHN-small, accuracy degrades to 27.59%27.59\% (compared to 11.64%11.64\% when EMN is optimized directly on SVHN-small). TUE maintains strong unlearnability across all transfer targets, limiting classifier accuracy to 5.10%−13.95%5.10\% - 13.95\%, confirming that linear separability combined with perturbation interpolation provides data-wise transferability.

  8. Knowl 8 — Experimental Configurations for TUE Generation and Evaluation

    experimental setup

    Perturbations are generated using Projected Gradient Descent (PGD) on ResNet-18 under an ℓ∞\ell_\infty bound of ϵ=8/255\epsilon = 8/255. Alternating bi-level optimization schedules are configured as follows:

    • TUE (SimCLR): Model parameters are trained for 40 epochs; after every 1/51/5 epoch of model parameter updates, the perturbation set is updated for 1 epoch using PGD-20.
    • TUE (MoCo): Model parameters are trained for 200 epochs with encoder momentum 0.990.99; after every 1 epoch of model parameter updates, the perturbation set is updated for 1 epoch using PGD-5.
    • TUE (SimSiam): Model parameters are trained for 50 epochs; after every 1/41/4 epoch of model parameter updates, the perturbation set is updated for 1 epoch using PGD-20.

    Evaluation protocols:

    • Supervised Training: ResNet-18 trained for 200 epochs using SGD with initial learning rate 0.10.1 and Cosine Annealing learning rate schedule under CrossEntropy loss.
    • Unsupervised Training: ResNet-18 pre-trained for 1000 epochs using InfoNCE loss (SimCLR with SGD lr 0.060.06, MoCo with Adam lr 0.30.3 and Cosine Annealing) or cosine similarity (SimSiam with SGD lr 0.060.06 and Cosine Annealing), followed by 100 epochs of linear probing (SimCLR: Adam lr 0.0010.001; MoCo: SGD lr 3030 with Cosine Annealing; SimSiam: SGD lr 3030 with Cosine Annealing) under CrossEntropy loss.

Coverage note — Qualitative t-SNE scatter visualizations and visual image-perturbation examples were omitted because their empirical conclusions are quantitatively covered by the transferability tables and method descriptions.

References

  1. 1.Kurt Bollacker, Colin Evans, Praveen Paritosh, Tim Sturge, and Jamie Taylor. Freebase: a collaboratively created graph database for structuring human knowledge. In Proceedings of the 2008 ACM SIGMOD international conference on Management of data, pp. 1247–1250, 2008.
  2. 2.Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton. A simple framework for contrastive learning of visual representations. In International conference on machine learning, pp. 1597–1607. PMLR, 2020a.
  3. 3.Xinlei Chen and Kaiming He. Exploring simple siamese representation learning. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pp. 15750–15758, 2021.
  4. 4.Xinlei Chen, Haoqi Fan, Ross Girshick, and Kaiming He. Improved baselines with momentum contrastive learning. arXiv preprint arXiv:2003.04297, 2020b.
  5. 5.Liam H Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping, Wojciech Czaja, and Tom Goldstein. Adversarial examples make strong poisons. In Advances in Neural Information Processing Systems, 2021.
  6. 6.Robert Geirhos, Jörn-Henrik Jacobsen, Claudio Michaelis, Richard Zemel, Wieland Brendel, Matthias Bethge, and Felix A Wichmann. Shortcut learning in deep neural networks. Nature Machine Intelligence, 2(11):665–673, 2020.
  7. 7.Jean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec, Pierre Richemond, Elena Buchatskaya, Carl Doersch, Bernardo Avila Pires, Zhaohan Guo, Mohammad Gheshlaghi Azar, et al. Bootstrap your own latent-a new approach to self-supervised learning. Advances in Neural Information Processing Systems, 33:21271–21284, 2020.
  8. 8.Yandong Guo, Lei Zhang, Yuxiao Hu, Xiaodong He, and Jianfeng Gao. Ms-celeb-1m: A dataset and benchmark for large-scale face recognition. In European conference on computer vision, pp. 87–102. Springer, 2016.
  9. 9.Hao He, Kaiwen Zha, and Dina Katabi. Indiscriminate poisoning attacks on unsupervised contrastive learning. arXiv preprint arXiv:2202.11202, 2022.
  10. 10.Gary B Huang, Marwan Mattar, Tamara Berg, and Eric Learned-Miller. Labeled faces in the wild: A database forstudying face recognition in unconstrained environments. In Workshop on faces in’Real-Life’Images: detection, alignment, and recognition, 2008.
  11. 11.Hanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey, and Yisen Wang. Unlearnable examples: Making personal data unexploitable. In International Conference on Learning Representations, 2020.
  12. 12.Alex Krizhevsky, Geoffrey Hinton, et al. Learning multiple layers of features from tiny images. 2009.
  13. 13.Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations, 2018.
  14. 14.Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli. Towards poisoning of deep learning algorithms with back-gradient optimization. In Proceedings of the 10th ACM workshop on artificial intelligence and security, pp. 27–38, 2017.
  15. 15.Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng. Reading digits in natural images with unsupervised feature learning. 2011.
  16. 16.Shawn Shan, Emily Wenger, Jiayun Zhang, Huiying Li, Haitao Zheng, and Ben Y Zhao. Fawkes: Protecting privacy against unauthorized deep learning models. In 29th USENIX Security Symposium (USENIX Security 20), pp. 1589–1604, 2020.
  17. 17.Tongzhou Wang and Phillip Isola. Understanding contrastive representation learning through alignment and uniformity on the hypersphere. In International Conference on Machine Learning, pp. 9929–9939. PMLR, 2020.
  18. 18.Da Yu, Huishuai Zhang, Wei Chen, Jian Yin, and Tie-Yan Liu. Indiscriminate poisoning attacks are shortcuts. arXiv preprint arXiv:2111.00898, 2021.

Citation

MLA
Ren, J., et al. “Transferable Unlearnable Examples”. arXiv, 2022, http://arxiv.org/abs/2210.10114v1.
APA
Ren, J., Xu, H., Wan, Y., Ma, X., Sun, L., & Tang, J. (2022). Transferable Unlearnable Examples. arXiv. http://arxiv.org/abs/2210.10114v1
Chicago
Ren, J., H. Xu, Y. Wan, X. Ma, L. Sun, and J. Tang. 2022. “Transferable Unlearnable Examples”. arXiv. http://arxiv.org/abs/2210.10114v1.
Harvard
Ren, J. et al. (2022) “Transferable Unlearnable Examples”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2210.10114v1.
Vancouver
1. Ren J, Xu H, Wan Y, Ma X, Sun L, Tang J (2022) Transferable Unlearnable Examples. arXiv

BibTeX

@article{ren2022transferable,
  title = {Transferable Unlearnable Examples},
  author = {Ren, Jie and Xu, Han and Wan, Yuxuan and Ma, Xingjun and Sun, Lichao and Tang, Jiliang},
  year = {2022},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2210.10114v1},
  eprint = {2210.10114}
}
Metadata:arXiv

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: Authors