Verification of Machine Unlearning is Fragile
Binchi Zhang, Zihan Chen, Cong Shen, Jundong Li
摘要
As privacy concerns escalate in the realm of machine learning, data owners now have the option to utilize machine unlearning to remove their data from machine learning models, following recent legislation. To enhance transparency in machine unlearning and avoid potential dishonesty by model providers, various verification strategies have been proposed. These strategies enable data owners to ascertain whether their target data has been effectively unlearned from the model. However, our understanding of the safety issues of machine unlearning verification remains nascent. In this paper, we explore the novel research question of whether model providers can circumvent verification strategies while retaining the information of data supposedly unlearned. Our investigation leads to a pessimistic answer: the verification of machine unlearning is fragile. Specifically, we categorize the current verification strategies regarding potential dishonesty among model providers into two types. Subsequently, we introduce two novel adversarial unlearning processes capable of circumventing both types. We validate the efficacy of our methods through theoretical analysis and empirical experiments using real-world datasets. This study highlights the vulnerabilities and limitations in machine unlearning verification, paving the way for further research into the safety of machine unlearning.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- FUNU: Boosting Machine Unlearning Efficiency by Filtering Unnecessary UnlearningZitong Li, Qingqing Ye, Haibo HuWWW 2025 · 被引用 8 次
- MUNBa: Machine Unlearning Via Nash BargainingJing Wu, Mehrtash HarandiICCV 2025 · 被引用 2 次
- Rethinking Federated Unlearning via the Lens of MemorizationJiaheng Wei, Yanjun Zhang, He Zhang, Leo Yu Zhang 等KDD 2026 · 被引用 1 次
- Towards a Re-evaluation of Data Forging Attacks in PracticeMohamed Suliman, Anisa Halimi, Swanand Ravindra Kadhe, Nathalie Baracaldo 等USENIX Security 2025
它引用的顶会 Paper22
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Machine UnlearningLucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia 等S&P 2021 · 被引用 1,381 次
- Certified Data Removal from Machine Learning ModelsChuan Guo, Tom Goldstein, Awni Y. Hannun, Laurens van der MaatenICML 2020 · 被引用 633 次
- Remember What You Want to Forget: Algorithms for Machine UnlearningAyush Sekhari, Jayadev Acharya, Gautam Kamath, Ananda Theertha SureshNeurIPS 2021 · 被引用 516 次
- When Machine Unlearning Jeopardizes PrivacyMin Chen, Zhikun Zhang, Tianhao Wang, Michael Backes 等CCS 2021 · 被引用 146 次
相关 Paper
- Unlearn and Burn: Adversarial Machine Unlearning Requests Destroy Model AccuracyYangsibo Huang, Daogao Liu, Lynn Chua, Badih Ghazi 等ICLR 2025
- Learn What You Want to Unlearn: Unlearning Inversion Attacks against Machine UnlearningHongsheng Hu, Shuo Wang, Tian Dong, Minhui XueS&P 2024 · 被引用 62 次
- ERASER: Machine Unlearning in MLaaS via an Inference Serving-Aware ApproachYuke Hu, Jian Lou, Jiaqi Liu, Wangze Ni 等CCS 2024 · 被引用 14 次
- Adversarial Machine UnlearningZonglin Di, Sixie Yu, Yevgeniy Vorobeychik, Yang LiuICLR 2025 · 被引用 1 次
- On the Necessity of Auditable Algorithmic Definitions for Machine UnlearningAnvith Thudi, Hengrui Jia, Ilia Shumailov, Nicolas PapernotUSENIX Security 2022
