acceptodds
Under review as a conference paper at ICLR 2027

HERA: An Empirical Audit of Partition Guarantees on Unlearnable Data

Abstract

Unlearnable examples perturb training images to impair learning, but recovery accuracy alone does not establish stability to later record edits or equality to retraining after deletion. We use HERA, a testbed of deterministic hash-partitioned ridge ensembles over fixed image views or frozen ImageNet-pretrained ResNet-18 features, to audit these properties on four archived CIFAR-10 protection instances. The partition guarantees are established; our contribution is an empirical comparison of clean-label allocation, regularization and shard count. Equal-weight ensembles combining 40,000 protected records with 2,000 clean records improve mean accuracy and certification over protected-only ensembles at all 32 tested five-shard instance–penalty settings, without uniformly dominating clean-only. Their certificates cover edits to the combined training set. Training-only shard-local cross-validation retains higher combined mean one-record certified accuracy than both separate options for every instance, although the NTGA difference from protected-only remains unresolved. The selector maximizes fold accuracy on each condition's training distribution using a previously explored penalty grid; it does not optimize ensemble certification. Tuned combined CUDA reaches 71.30% certified accuracy versus clean-only's 69.71%, but remains 4.07 accuracy points lower. Separate-resource comparisons expose strong regularization sensitivity: clean-only certification peaks among tested shared penalties at 70.21%, versus CUDA's 64.92%, before declining at larger penalties. Small clean shards motivate a near-interpolation hypothesis, not an established mechanism. Separate pooled additions reveal clean-budget dependence, with CUDA reducing accuracy at 2,000 clean labels despite helping at 250. Sparse deletion checks match local and fresh states and predictions while reusing untouched shards. These fixed-feature results motivate joint accuracy/certification reporting with shard-local selection, not claims of optimal allocation or robustness to dense perturbations.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.