Flexible, Efficient, and Stable Adversarial Attacks on Machine Unlearning
Zihan Zhou, Yang Zhou, Zijie Zhang, Lingjuan Lyu, Da Yan, Ruoming Jin, Dejing Dou
Abstract
Machine unlearning (MU) aims to remove the influence of specific data points from trained models, enhancing compliance with privacy regulations. However, the vulnerability of basic MU models to malicious unlearning requests in adversarial learning environments has been largely overlooked. Existing adversarial MU attacks suffer from three key limitations: inflexibility due to pre-defined attack targets, inefficiency in handling multiple attack requests, and instability caused by non-convex loss functions. To address these challenges, we propose a Flexible, Efficient, and Stable Attack (DDPA). First, leveraging Carathéodory's theorem, we introduce a convex polyhedral approximation to identify points in the loss landscape where convexity approximately holds, ensuring stable attack performance. Second, inspired by simplex theory and John's theorem, we develop a regular simplex detection technique that maximizes coverage over the parameter space, improving attack flexibility and efficiency. We theoretically derive the proportion of the effective parameter space occupied by the constructed simplex. We evaluate the attack success rate of our DDPA method on real datasets against state-of-the-art machine unlearning attack methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Bridging Symmetry and Robustness: On the Role of Equivariance in Enhancing Adversarial RobustnessLongwei Wang, Ifrat Ikhtear Uddin, KC Santosh, Chaowei Zhang et al.NeurIPS 2025 · 12 citations
- Mitigating the Modality Gap in Vision–Language Models with Fractal Spectral GeometryZihan Zhou, Yang Zhou, Ruoming Jin, Pan He et al.ICML 2026
- Structured Multi-step Jailbreaking under a Hamiltonian Generative FormulationZihan Zhou, Yang Zhou, Jianghai Yu, Lingjuan Lyu et al.ICML 2026
Builds on40
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Machine UnlearningLucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia et al.S&P 2021 · 1,381 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Invisible Backdoor Attack with Sample-Specific TriggersYuezun Li, Yiming Li, Baoyuan Wu, Longkang Li et al.ICCV 2021 · 639 citations
- Input-Aware Dynamic Backdoor AttackTuan Anh Nguyen, Anh Tuan TranNeurIPS 2020 · 601 citations
Related papers
- When to Forget? Complexity Trade-offs in Machine UnlearningMartin Van Waerebeke, Marco Lorenzi, Giovanni Neglia, Kevin ScamanICML 2025
- A Reliable Cryptographic Framework for Empirical Machine Unlearning EvaluationYiwen Tu, Pingbang Hu, Jiaqi MaNeurIPS 2025 · 6 citations
- Rethinking Adversarial Robustness in the Context of the Right to be ForgottenChenxu Zhao, Wei Qian, Yangyi Li, Aobo Chen et al.ICML 2024 · 12 citations
- ZIUM: Zero-Shot Intent-Aware Adversarial Attack on Unlearned ModelsHyun Jun Yook, Ga San Jhun, Jae Hyun Cho, Min Jeon et al.ICCV 2025 · 1 citation
- FUNU: Boosting Machine Unlearning Efficiency by Filtering Unnecessary UnlearningZitong Li, Qingqing Ye, Haibo HuWWW 2025 · 8 citations
