Pith. sign in

REVIEW 33 cited by

Certified Data Removal from Machine Learning Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1911.03030 v6 pith:FDSEYKHF submitted 2019-11-08 cs.LG stat.ML

Certified Data Removal from Machine Learning Models

classification cs.LG stat.ML
keywords datamodelremovalcertifiedlearningmachine-learningmechanismrequest
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

Good data stewardship requires removal of data at the request of the data's owner. This raises the question if and how a trained machine-learning model, which implicitly stores information about its training data, should be affected by such a removal request. Is it possible to "remove" data from a machine-learning model? We study this problem by defining certified removal: a very strong theoretical guarantee that a model from which data is removed cannot be distinguished from a model that never observed the data to begin with. We develop a certified-removal mechanism for linear classifiers and empirically study learning settings in which this mechanism is practical.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 33 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Negative Preference Optimization: From Catastrophic Collapse to Effective Unlearning

    cs.LG 2024-04 conditional novelty 8.0

    NPO enables stable unlearning of 50%+ training data in LLMs on TOFU by making collapse exponentially slower than gradient ascent, preserving sensible outputs where prior methods fail.

  2. Unlearning as Distribution Restoration: A Controlled Counterfactual Study, a Validated Selective Screen, and the Limits of Oracle-Free Certification

    cs.LG 2026-07 conditional novelty 7.0

    Matching a retrained oracle on trained probes can certify models that still retain held-out forget knowledge, and oracle-free unlearning certification is only possible for counterfactual, non-inferable facts.

  3. FedUP: One-Shot Federated Unlearning via Centroid-Guided Plug-in Filters

    cs.LG 2026-06 unverdicted novelty 7.0

    FedUP achieves fast, reversible one-shot federated unlearning via pluggable centroid-guided filters that reduce non-target knowledge loss.

  4. TRACER: Token ReAssignment for Concept ERasure in Generative Recommendation

    cs.IR 2026-06 unverdicted novelty 7.0

    TRACER uses token reassignment for concept-related items plus a coherence regularizer to unlearn specific concepts in generative recommendation while preserving utility better than baselines.

  5. Exact Unlearning in Reinforcement Learning

    cs.LG 2026-06 unverdicted novelty 7.0

    For any ρ>0 there exists a ρ-TV-stable RL algorithm for tabular MDPs supporting exact unlearning at expected cost ρ√(ln T) of retraining from scratch, with regret O(H²√(SAT)+H³S²A+H^{2.5}S²A/ρ) and matching lower boun...

  6. Initialization is Half the Battle: Generating Diverse Images from a Guidance Potential Posterior

    cs.CV 2026-06 unverdicted novelty 7.0

    DivIn samples initial noise from a guidance potential posterior via Langevin dynamics to improve diversity in class-to-image and text-to-image generation.

  7. Interference-Aware Multi-Task Unlearning

    cs.AI 2026-05 unverdicted novelty 7.0

    Introduces interference-aware multi-task unlearning with task-aware gradient projection and instance-level gradient orthogonalization, reducing interference scores by 30.3% and 52.9% on vision benchmarks.

  8. Erase Persona, Forget Lore: Benchmarking Multimodal Copyright Unlearning in Large Vision Language Models

    cs.CV 2026-05 unverdicted novelty 7.0

    CoVUBench is the first benchmark framework for evaluating multimodal copyright unlearning in LVLMs via synthetic data, systematic variations, and a dual protocol for forgetting efficacy and utility preservation.

  9. Shape of Memory: a Geometric Analysis of Machine Unlearning in Second-Order Optimizers

    cs.LG 2026-04 unverdicted novelty 7.0

    Second-order optimizers retain residual geometric memory in their state after unlearning that first-order metrics miss, and only controlled eigendecay perturbations fully erase it.

  10. ZeroUnlearn: Few-Shot Knowledge Unlearning in Large Language Models

    cs.LG 2026-05 unverdicted novelty 6.0

    ZeroUnlearn reformulates machine unlearning as knowledge re-mapping via model editing, using multiplicative updates with closed-form solutions for efficient few-shot removal of sensitive representations while preservi...

  11. Representation-Guided Parameter-Efficient LLM Unlearning

    cs.CL 2026-04 unverdicted novelty 6.0

    REGLU guides LoRA-based unlearning via representation subspaces and orthogonal regularization to outperform prior methods on forget-retain trade-off in LLM benchmarks.

  12. WIN-U: Woodbury-Informed Newton-Unlearning as a retain-free Machine Unlearning Framework

    cs.LG 2026-04 unverdicted novelty 6.0

    WIN-U delivers a retain-free unlearning update that approximates the gold-standard retrained model via a Woodbury-informed Newton step using only forget-set curvature information.

  13. PrivEraserVerify: Efficient, Private, and Verifiable Federated Unlearning

    cs.LG 2026-04 unverdicted novelty 6.0

    PrivEraserVerify unifies efficiency via adaptive checkpointing, privacy via layer-adaptive DP, and verifiability via fingerprints in federated unlearning, claiming 2-3x faster performance than retraining with formal g...

  14. Label Leakage Attacks in Machine Unlearning: A Parameter and Inversion-Based Approach

    cs.CR 2026-04 unverdicted novelty 6.0

    Parameter-difference and model-inversion attacks can identify forgotten classes after machine unlearning on standard image datasets.

  15. Jellyfish: Zero-Shot Federated Unlearning Scheme with Knowledge Disentanglement

    cs.CR 2026-04 unverdicted novelty 6.0

    Jellyfish enables zero-shot federated unlearning through synthetic proxy data generation, channel-restricted knowledge disentanglement, and a composite loss with repair to forget target data while retaining model utility.

  16. Forget-It-All: Multi-Concept Machine Unlearning via Concept-Aware Neuron Masking

    cs.CV 2026-01 unverdicted novelty 6.0

    FIA uses contrastive concept saliency and temporal-spatial neuron identification to build unified masks that erase multiple target concepts while preserving general generation quality in diffusion models.

  17. POUR: A Provably Optimal Method for Unlearning Representations via Neural Collapse

    cs.CV 2025-11 unverdicted novelty 6.0

    POUR derives a provably optimal forgetting operator by showing that orthogonal projections of simplex equiangular tight frames remain ETFs in lower dimensions, enabling representation-level unlearning with closed-form...

  18. Exploring Nonlinear Pathway in Parameter Space for Machine Unlearning

    cs.AI 2025-05 unverdicted novelty 6.0

    MCU applies mode connectivity to trace nonlinear unlearning pathways in parameter space, adds a parameter mask and adaptive penalty, and produces a range of unlearning models that plug into existing methods.

  19. TOFU: A Task of Fictitious Unlearning for LLMs

    cs.LG 2024-01 conditional novelty 6.0

    TOFU is a new benchmark with synthetic profiles and metrics demonstrating that existing unlearning algorithms for LLMs fail to achieve effective forgetting of targeted information.

  20. SalUn: Empowering Machine Unlearning via Gradient-based Weight Saliency in Both Image Classification and Generation

    cs.LG 2023-10 conditional novelty 6.0

    SalUn uses gradient-based weight saliency to achieve effective machine unlearning of data, classes, or concepts in image classification and generation, narrowing the gap to exact retraining.

  21. TrustErase: Auditable Instant Machine Unlearning with Passport-Embedded Representations

    cs.CR 2026-06 unverdicted novelty 5.0

    TrustErase uses passport-embedded representations for instant, data-free, and auditable machine unlearning through simple deactivation of adaptation layers.

  22. ZeroUnlearn: Few-Shot Knowledge Unlearning in Large Language Models

    cs.LG 2026-05 unverdicted novelty 5.0

    ZeroUnlearn is a few-shot unlearning method that overwrites sensitive inputs with neutral targets via closed-form multiplicative parameter updates enforcing representational orthogonality in LLMs.

  23. ZeroUnlearn: Few-Shot Knowledge Unlearning in Large Language Models

    cs.LG 2026-05 unverdicted novelty 5.0

    ZeroUnlearn is a few-shot unlearning method that maps sensitive inputs to neutral states and enforces representational orthogonality through a closed-form multiplicative update, outperforming baselines while preservin...

  24. Incentivizing User Data Contributions for LLM Improvement under Withdrawal Rights

    cs.GT 2026-05 unverdicted novelty 5.0

    Withdrawal rights paired with centralized cost-based assignment prevent subsidy waste by collecting data only when the improvement threshold is sustainably reachable, turning infeasible cases into null outcomes.

  25. Forgetting to Witness: Efficient Federated Unlearning and Its Visible Evaluation

    cs.LG 2026-04 unverdicted novelty 5.0

    A complete pipeline for federated unlearning via knowledge distillation for efficient removal and a GAN-integrated classifier for visual evaluation of forgetting capacity.

  26. Machine Unlearning on Pre-trained Models by Residual Feature Alignment Using LoRA

    cs.LG 2024-11 unverdicted novelty 5.0

    A LoRA-based residual feature alignment method for efficient machine unlearning on pre-trained models by targeting zero residuals on retained data and shifted residuals on unlearned data.

  27. AdaProb: Efficient Machine Unlearning via Adaptive Probability

    cs.LG 2024-11 unverdicted novelty 5.0

    AdaProb performs machine unlearning by substituting final-layer output probabilities with optimized uniform pseudo-probabilities and updating model weights.

  28. Trustworthy LLMs: a Survey and Guideline for Evaluating Large Language Models' Alignment

    cs.AI 2023-08 accept novelty 5.0

    Survey organizes LLM trustworthiness into seven categories and 29 sub-categories, measures eight sub-categories on popular models, and finds that more aligned models generally score higher but with varying effectiveness.

  29. DFMU: Data-Frugal Machine Unlearning

    cs.LG 2026-06 unverdicted novelty 4.0

    DFMU computes block importance via one forward-backward pass and knowledge-preserving pruning to unlearn classes with 13% data, 40% higher retain accuracy, and 88% faster runtime than SOTA.

  30. LLM Unlearning for Cyber Defense: A Survey on Methods, Challenges, and Emerging Threats

    cs.LG 2026-06 conditional novelty 4.0

    Most gradient-based LLM unlearning methods achieve behavioral suppression, not true forgetting, and current benchmarks cannot certify that knowledge has been removed.

  31. DeepSeek Robustness Against Semantic-Character Dual-Space Mutated Prompt Injection

    cs.CR 2026-04 unverdicted novelty 4.0

    Dual-space semantic-character mutations on prompts achieve higher misuse success rates against DeepSeek than single-space attacks alone.

  32. High-Dimensional Statistics: Reflections on Progress and Open Problems

    math.ST 2026-05 unverdicted novelty 2.0

    A survey synthesizing representative advances, common themes, and open problems in high-dimensional statistics while pointing to key entry-point works.

  33. High-Dimensional Statistics: Reflections on Progress and Open Problems

    math.ST 2026-05 unverdicted novelty 2.0

    This review synthesizes representative advances in high-dimensional statistics, highlights common themes and open problems, and points to key entry works.