Unlearning’s Blind Spots: Over‑Unlearning and Prototypical Relearning Attack
SeungBum Ha, Saerom Park, Sung Whan Yoon
Abstract
Machine unlearning (MU) aims to expunge a designated forget set from a trained model without costly retraining, yet the existing techniques overlook two critical blind spots: "over‑unlearning" that deteriorates retained data near the forget set, and post‑hoc "relearning" attacks that aim to resurrect the forgotten knowledge. Focusing on class-level unlearning, we first derive an over-unlearning metric, , which quantifies collateral damage in regions proximal to the forget set, where over-unlearning mainly occurs. Next, we expose an unforeseen relearning threat on MU, i.e., the Prototypical Relearning Attack, which exploits the per-class prototype of the forget class with just a few samples, and easily restores the pre-unlearning performance. To counter both blind spots in class-level unlearning, we introduce , a plug‑and‑play objective that combines (i) a masked knowledge‑distillation penalty on the nearby region of forget classes to suppress , and (ii) an intra‑class dispersion loss that scatters forget-class embeddings, neutralizing Prototypical Relearning Attacks. achieves state-of-the-art results across CIFAR, TinyImageNet, and CASIA-WebFace datasets, offering a practical remedy to unlearning’s blind spots.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7126d952-8bbe-4258-997b-82087dc691b8Builds on25
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 1,861 citations
- Machine UnlearningLucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia et al.S&P 2021 · 1,381 citations
- Certified Data Removal from Machine Learning ModelsChuan Guo, Tom Goldstein, Awni Y. Hannun, Laurens van der MaatenICML 2020 · 633 citations
Related papers
- Decoupled Distillation to Erase: A General Unlearning Method for Any Class-centric TasksYu Zhou, Dian Zheng, Qijie Mo, Renjie Lu et al.CVPR 2025
- Machine Unlearning via Adaptive Gradient Reweighting and Multi-stage Objective OptimizationJuxin Lu, Haoyu Shi, Mengyao Wang, Huaiwen ZhangCVPR 2026
- Targeted Forgetting of Image Subgroups in CLIP ModelsZeliang Zhang, Gaowen Liu, Charles Fleming, Ramana Rao Kompella et al.CVPR 2025
- WARP: Weight Teleportation for Attack-Resilient Unlearning ProtocolsMohammad Mahdi Maheri, Xavier F. Cadet, Peter Chin, Hamed HaddadiICLR 2026 · 1 citation
- Unlearning Isn’t Forgetting: Revealing Hidden Leakage in Class Unlearning EvaluationsAli Ebrahimpour-Boroojeny, Yian Wang, Hari SundaramICML 2026
