{"id":"0f10a0a5-0dee-48fb-a0dd-02071428f44c","arxiv_id":"2505.05279","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"MTL-UE generates unlearnable multi-task examples by injecting learned class-wise feature embeddings through a generator, degrading both multi-task and single-task models across four datasets.","lead":"MTL-UE adds small, invisible patterns to images so that AI models trained on them fail at multiple tasks, a way for people to stop their data from being used without permission. The method combines a generator network with learned class-specific patterns and outperforms baseline unlearnable example methods across several multi-task datasets and model types.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Claimed 'consistently superior' attacking performance is contradicted by the paper's own ChestX-ray14 STL results (MTL-UE-TAP/SEP worse than TAP/SEP) and no table reports error bars or seeds.","rationale":"The reader's weakest assumption focuses on the shortcut-learning mechanism in Sec. 4.3, which is a reasonable concern but is not the most load-bearing part of the claimed result. Even if the variance-based explanation were imperfect, the method could still deliver superior attacking performance. The load-bearing issue is empirical: the abstract promises consistent superiority, and the paper's own Table 2 contains single-run results in which MTL-UE is worse than the baseline (ChestX-ray14 STL for both TAP and SEP variants). With no error bars, no seeds, and no code, the 'consistently' claim is not established even on the paper's own evidence. This does not make the paper rejectable: the overall pattern across CelebA, UTKFace, and NYUv2 is strongly in favor of MTL-UE, and many of the reported gaps are large. It does mean the central claim is conditionally supported rather than fully verified. My read is therefore consistent with the reader's CONDITIONAL verdict, and the concrete re-run described above would settle whether the exceptions are noise or a genuine limit of the framework.","tokens_in":27429,"tokens_out":9939,"duration_ms":112132,"concrete_test":"Re-run the ChestX-ray14 STL experiments for TAP, SEP, MTL-UE-TAP, and MTL-UE-SEP with at least five independent seeds using identical surrogate checkpoints and training pipelines, and report per-seed AUC-ROC with paired differences. If MTL-UE-TAP/SEP are not consistently and significantly lower than TAP/SEP, or if the differences flip sign across seeds, the 'consistently' claim must be narrowed or removed. As a secondary check, recompute Appendix Table 12's ISS-Grayscale row averages from the per-task numbers; if the reported averages are wrong, audit the other tables for transcription errors.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is the abstract's 'superior attacking performance consistently across 4 MTL datasets...'. The load-bearing condition is that every reported comparison actually favors MTL-UE. The paper's own Table 2 violates this: for ChestX-ray14 STL, where lower AUC-ROC means stronger protection, TAP is 0.6005 and MTL-UE-TAP is 0.6091; SEP is 0.5926 and MTL-UE-SEP is 0.6068. So on the single reported run, MTL-UE is less protective than the corresponding baseline in both cases. The same table shows only marginal gains for MTL-UE-TAP on ChestX-ray14 MTL (0.5341 vs 0.5478). No table anywhere reports standard errors, seeds, or number of runs, and no code or checkpoints are provided, so the 'consistently' claim cannot be separated from noise. Appendix Table 12 also reports an average of 10.68 for MTL-UE-TAP under ISS-Grayscale while its own per-task numbers are 10.68, 16.73, and 40.27, suggesting data-transcription issues. The Sec. 4.3 mechanism story may be plausible, but the headline claim stands or falls on the empirical comparisons, and this is where the evidence is least secure.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes MTL-UE, a generator-based framework for constructing unlearnable examples in multi-task learning. Instead of optimizing a perturbation for each sample, the method trains an encoder-decoder that receives latent features concatenated with per-task, per-class learnable embeddings, and injects the resulting bounded perturbation into the training images. The generator can be plugged into surrogate-dependent UE methods such as EM, TAP, and SEP by replacing the base perturbation objective with the base method's loss. Intra-task and inter-task embedding regularizations are introduced to reduce intra-class variance and increase inter-class separation of spurious features. The paper reports experiments on CelebA, ChestX-ray14, UTKFace, and NYUv2, covering classification and dense prediction tasks, multiple backbones, multiple MTL weighting strategies, ablation studies, partial task protection, partial data protection, and robustness to ISS-style defenses. The central claim is that MTL-UE achieves consistently superior attacking performance across these settings.","tokens_in":27690,"tokens_out":3660,"duration_ms":36992,"significance":"If the empirical claims hold, MTL-UE is a useful and timely contribution: it is the first framework to treat unlearnable examples in a multi-task setting, it is plug-and-play with existing surrogate-dependent UE methods, and it extends to dense prediction tasks. The generator-plus-embedding design is well motivated by the observed failure modes of per-sample perturbation methods and patch-based surrogate-free methods, and the reported computational and parameter efficiency is attractive. The breadth of evaluation is a strength. However, the manuscript currently lacks the evidence needed to support the headline claim of consistent superiority: one of the four main datasets contains results that contradict the claim, no table reports seed variation or uncertainty, and at least one appendix table contains an internal numerical inconsistency. The contribution is promising, but the central empirical claim needs to be either corrected, qualified, or made reproducible before the paper can be accepted.","major_comments":[{"comment":"The abstract and Section 5.2 claim that MTL-UE achieves 'superior attacking performance consistently across 4 MTL datasets.' Table 2 contradicts this claim on the ChestX-ray14 STL columns: lower AUC-ROC means stronger protection, but MTL-UE-TAP reports 0.6091 versus TAP's 0.6005, and MTL-UE-SEP reports 0.6068 versus SEP's 0.5926. Both MTL-UE variants are therefore less protective than their corresponding base methods on this single reported run. The MTL-side gain for MTL-UE-TAP (0.5341 versus 0.5478) is also small. The authors must either correct these numbers, explain why this case is an exception, or change the wording of the headline claim from 'consistently' to a qualified statement.","section":"Section 5.2, Table 2 (ChestX-ray14 STL)"},{"comment":"No table reports standard deviations, confidence intervals, or the number of random seeds. Several comparisons in the paper have small gaps, such as the ChestX-ray14 MTL comparison just mentioned, and the UTKFace MTL gains in Table 2. Without repeated runs, these differences cannot be separated from training noise. Since the central claim is 'consistently superior attacking performance,' the authors should report mean and standard deviation over at least three seeds for the main tables, or provide statistical tests, and make the code or checkpoints available so that the reported numbers can be independently checked.","section":"Section 5.2 and all result tables"},{"comment":"The ISS-Grayscale row for MTL-UE-TAP reports per-task accuracies 10.68, 16.73, and 40.27, but the listed average is 10.68; the arithmetic mean of these three values is 22.56, so the average is internally inconsistent. In the same table, the EM row under ISS-BDR (19.81, 24.81, 58.84, 34.49) is identical to the ISS-Grayscale EM row, and the same duplicate pattern appears for TAP and SEP. These transcription issues must be fixed before the defense-robustness claims in Section B.3 can be evaluated.","section":"Appendix B.3, Table 12"},{"comment":"The mechanism explanation for MTL-UE's success is partly self-referential. Table 3 measures intra-class standard deviation on features from models trained on the very perturbed datasets produced by the method, and Eq. (4) directly minimizes the cosine similarity between embeddings, which is a component of intra-class feature variance. Consequently, part of the reported variance reduction is enforced by construction rather than independently demonstrated. To make the mechanism claim testable, the authors should either measure intra-class variance on a fixed clean-pretrained encoder, or show that the variance reduction predicts attack success across held-out backbones and defenses, rather than only on the models used to generate the perturbations.","section":"Section 4.3, Table 3, Eq. (4)"}],"minor_comments":[{"comment":"The caption reads 'Results of partial task protection on on the UTKFace'; the duplicated 'on' should be removed.","section":"Table 8 caption"},{"comment":"The word 'follwoing' should be 'following'.","section":"Section B.3"},{"comment":"The caption uses 'Ours-EM', 'Ours-TAP', and 'Ours-SEP' while the body and Table 2 use 'MTL-UE-EM', 'MTL-UE-TAP', and 'MTL-UE-SEP'; the notation should be unified.","section":"Figure 9 caption"},{"comment":"The phrase 'in dependently normalized' should be 'independently normalized'.","section":"Figure 9 caption"},{"comment":"The parameter count comparison counts optimized perturbation tensors for EM/TAP/SEP but generator network weights for MTL-UE; since these are different kinds of objects, the comparison would be clearer if the perturbation storage cost and generator parameter count were reported separately.","section":"Appendix A.4"}],"recommendation":"major_revision","confidential_remarks":"The paper is novel relative to the single-task UE literature and the dense-prediction extension is a genuine addition. My main concern is that the headline 'consistently superior' claim is contradicted by one of the paper's own tables and is not supported by uncertainty quantification or code release. The internal inconsistencies in Table 12 look more like reporting errors than misconduct, but the absence of seeds and code makes external verification difficult. I would encourage the editor to ask for a reproducibility checklist and for corrected tables before considering acceptance."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear colleague,\n\nQuick take: this is the first serious attempt at unlearnable examples for multi-task learning, and the empirical core is genuinely useful. The generator-plus-class-wise-embedding design is new in this space, and the evaluation is unusually broad: four datasets, three base UE methods, five backbones, five weighting strategies, plus dense-prediction transfer and partial protection. On CelebA, UTKFace, and NYUv2 the MTL-UE variants beat the adapted baselines by large margins, and the plug-and-play property is real—you can drop it onto EM/TAP/SEP. I would send this to a referee.\n\nWhat it does well: the motivation section (Sec. 4.2) is honest and informative—they actually show that surrogate-dependent UEs degrade as task count grows and that patch-based shortcuts have lower intra-class variance. The design follows from that evidence. The dense-prediction extension is a nice bonus, and the ablation study (Tab. 7) supports the embedding and regularization choices.\n\nSoft spots, in order of severity. First, the abstract claims 'superior attacking performance consistently across 4 MTL datasets...' The paper's own Table 2 contradicts that for ChestX-ray14 STL: MTL-UE-TAP (0.6091) and MTL-UE-SEP (0.6068) are worse than TAP (0.6005) and SEP (0.5926) when protecting STL victims. On that single reported run, the method is less protective. Second, no table reports error bars, seeds, or number of runs, so 'consistently' cannot be separated from noise. Third, Appendix Table 12 has a transcription problem: under ISS-Grayscale, MTL-UE-TAP's per-task numbers are 10.68, 16.73, 40.27 but the listed average is 10.68. That suggests data handling is not fully careful. The mechanism story—intra-class variance of spurious features driving attack success—is plausible, but the variance measurements in Tab. 3 come from models trained on the method's own perturbations, so part of the reduction is enforced by construction; the causal claim needs a more direct test.\n\nNone of these are fatal. The central result holds up on the main MTL benchmarks, and the flaws are addressable: add seed variation, release code, fix the tables, and tone down the abstract.\n\nWho this is for: anyone working on data protection, availability poisoning, or adversarial robustness in multi-task/foundation-model settings. It deserves a serious referee, and with revisions I'd take it.\n\nBest.","headline":"First multi-task unlearnable-example framework with real gains and unusually broad experimental coverage, but the 'consistently' claim overreaches given the ChestX-ray14 STL results and the missing error bars.","tokens_in":28252,"tokens_out":3804,"would_cite":true,"duration_ms":31984,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"MTL-UE is a generator-based framework that makes multi-task datasets unlearnable by injecting class-wise label embeddings into bounded perturbations, degrading both multi-task and single-task models trained on the protected data.","keywords":["unlearnable examples","multi-task learning","data poisoning","availability attacks","generator-based perturbations","class-wise feature embeddings","embedding regularization","dense prediction"],"falsifier":"Train two victim models on the same MTL-UE-protected dataset, one from scratch and one initialized from a clean pretrained checkpoint, then compare accuracy on clean test data; if the pretrained model keeps near-clean accuracy while the from-scratch model fails, the protection depends on training from scratch rather than on the perturbations themselves.","tokens_in":27208,"feed_emoji":"🛡️","tokens_out":12027,"duration_ms":113124,"temperature":0.7,"pith_summary":"This paper sets out to establish that multi-task data can be protected from unauthorized model training by a single generator-based perturbation framework, rather than by per-sample optimization. The proposed MTL-UE couples an encoder–decoder network with learnable class-wise embeddings for each task's labels, then adds intra-task and inter-task regularizers to make the injected spurious features more separable and less scattered. The authors claim this is the first unified framework for unlearnable examples in multi-task learning, and that it outperforms existing unlearnable-example baselines consistently across four datasets, five backbones, and five multi-task weighting strategies, while also degrading single-task models trained on any one task. They further demonstrate extension to dense prediction on NYUv2 and plug-and-play compatibility with error-minimizing, adversarial, and self-ensemble base methods. A sympathetic reading is that, if the claim holds, one protected dataset can spoil training for a broad class of both generalist and specialist models.","feed_headline":"One generator makes multi-task data unlearnable for MTL and STL models","feed_subtitle":"A plug-and-play protector that makes existing unlearnable-image methods cover every task at once.","key_machinery":"The load-bearing object is the embedding-injection generator: an encoder $E(\\cdot;\\phi_E)$ maps each input to a latent $z$, task-label priors select one learnable class-wise embedding $e^k_{y_k}$ per task, the embeddings are concatenated with $z$, and a decoder $D(\\cdot;\\phi_D)$ turns the concatenation into a perturbation clipped to the $\\ell_\\infty$ bound. Intra-task embedding regularization minimizes cosine similarity between embeddings within each task, enlarging inter-class distance; inter-task embedding regularization minimizes absolute cosine similarity across tasks, promoting geometric independence. This machinery is what converts the attack from per-sample optimization into learning global spurious-feature structure, and it is the component that makes the framework plug-and-play with surrogate-dependent unlearnable-example losses such as error-minimizing and adversarial objectives.","core_discovery":"MTL-UE's central claim is that unlearnability for multi-task data is best achieved not by optimizing a separate perturbation per sample, but by learning a dataset-wide generator that emits one bounded perturbation per sample as a function of the sample's image and its labels across all tasks. The generator selects a learnable class-wise embedding for every task according to the sample's labels, concatenates those embeddings with the image latent, and decodes the result into a perturbation clipped to an $\\ell_\\infty$ bound. The paper argues this narrows the search space from raw pixel perturbations to the decoder's output space, lowers the intra-class variance of spurious features, and lets corresponding spurious features from several tasks coexist in one perturbation. Two regularizers—intra-task embedding regularization, which pushes embeddings of different classes in the same task apart, and inter-task embedding regularization, which makes embeddings across tasks geometrically independent—are said to improve attack effectiveness and robustness. The reported outcome is that models trained on the protected data, whether multi-task or single-task, drop sharply in accuracy on clean test data across all tasks, with transfer held across backbones and weighting strategies.","pith_inferences":["A causal isolation test the paper does not run is to retrain the generator with all class-wise embeddings frozen at random values; if attack strength persists, the learned embeddings and their regularizers are not the operative component.","The measured transfer gap between CNN surrogates and vision-transformer victims implies a boundary condition: protection strength is tied to how well the surrogate's feature geometry matches the victim's, so testing with a vision-transformer surrogate is a natural next step.","Hard orthogonality is the limit of the inter-task regularizer; replacing the soft penalty with exactly orthogonal embeddings would test whether the benefits saturate and would give a parameter-free version of MTL-UE.","The partial-data results imply the framework is best suited to full-dataset release rather than mixed-scraping scenarios, because a small fraction of clean data quickly restores learnability."],"forward_implications":["A single protected version of a multi-task dataset can be published without revealing usable training signal for either a multi-task model or a model trained on any one of its tasks.","Existing single-task unlearnable methods, once wrapped by MTL-UE, inherit multi-task protection without redesigning the base loss, so the framework acts as an upgrade path rather than a replacement.","Because the generator is trained once and reused, the perturbation budget is spent globally; the authors report the attack still works at smaller perturbation bounds down to 4/255.","If the transfer results hold, protection survives changes in victim backbone and multi-task weighting strategy, meaning a data owner does not need to know the attacker's architecture in advance.","Dense prediction datasets with segmentation, depth, and surface-normal tasks are also coverable by replacing class-wise embeddings with task-specific embedders, extending protection beyond classification."],"supporting_citations":[{"why":"Introduces unlearnable examples through error-minimizing noise and serves as the base method wrapped by MTL-UE-EM.","marker":"Huang et al., 2021"},{"why":"Shows adversarial examples work as poisons and is the base method behind MTL-UE-TAP.","marker":"Fowl et al., 2021"},{"why":"Provides self-ensemble protection, the base method behind MTL-UE-SEP.","marker":"Chen et al., 2023"},{"why":"Shows patch-based autoregressive perturbations achieve low intra-class variance, the observation that motivates MTL-UE's embedding design.","marker":"Sandoval-Segura et al., 2022"},{"why":"Establishes shortcut-based availability attacks and serves as a surrogate-free baseline that MTL-UE is compared with.","marker":"Yu et al., 2022a"},{"why":"Supplies the paper's core rationale that spurious features with lower intra-class variance and larger inter-class distance make stronger unlearnable examples.","marker":"Yu et al., 2024a"},{"why":"Introduces image shortcut squeezing defenses that MTL-UE evaluates against; robustness to these defenses is part of the claimed advantage.","marker":"Liu et al., 2023"}],"fun_headline_variants":["One generator makes all tasks unlearnable","MTL-UE: first unified unlearnable example generator for MTL","Generator-based attack poisons multi-task training data","Single generator turns multi-task data into unlearnable examples","Unlearnable for MTL: one generator, label priors, plug-and-play"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that a victim model trained from scratch will preferentially learn the class-wise spurious features the generator injects, and that shrinking the spread of those features is what makes the attack succeed; the paper's own variance evidence is partly self-referential because it is measured on models trained on the generator's own output.","fun_headline_variants_meta":{"raw":{"variants":["One generator makes all tasks unlearnable","MTL-UE: first unified unlearnable example generator for MTL","Generator-based attack poisons multi-task training data","Single generator turns multi-task data into unlearnable examples","Unlearnable for MTL: one generator, label priors, plug-and-play"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000194,"raw_usage":{"total_tokens":1380,"prompt_tokens":996,"completion_tokens":384,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":612,"completion_tokens_details":{"reasoning_tokens":298}},"tokens_in":612,"tokens_out":384,"duration_ms":3864,"temperature":1.0,"reasoning_tokens":298,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T23:07:42.126753+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Train two victim models on the same MTL-UE-protected dataset, one from scratch and one initialized from a clean pretrained checkpoint, then compare accuracy on clean test data; if the pretrained model keeps near-clean accuracy while the from-scratch model fails, the protection depends on training from scratch rather than on the perturbations themselves.","supporting_citations":[{"cited_title":"M., Bailey, J., and Wang, Y","cited_arxiv_id":null,"evidence_quote":"Introduces unlearnable examples through error-minimizing noise and serves as the base method wrapped by MTL-UE-EM."},{"cited_title":"Autoregressive perturbations for data poisoning","cited_arxiv_id":null,"evidence_quote":"Shows patch-based autoregressive perturbations achieve low intra-class variance, the observation that motivates MTL-UE's embedding design."},{"cited_title":"Image shortcut squeezing: Countering perturbative availability poisons with compression","cited_arxiv_id":null,"evidence_quote":"Introduces image shortcut squeezing defenses that MTL-UE evaluates against; robustness to these defenses is part of the claimed advantage."}],"review_version":1}