{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:52UVZFUDXJE4U2TBLF3UXSFRFZ","short_pith_number":"pith:52UVZFUD","schema_version":"1.0","canonical_sha256":"eea95c9683ba49ca6a6159774bc8b12e479743af2c5f2d4b44f25c8696a75988","source":{"kind":"arxiv","id":"2507.20573","version":1},"attestation_state":"computed","paper":{"title":"Reminiscence Attack on Residuals: Exploiting Approximate Machine Unlearning for Privacy","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Haibo Hu, Haoyang Li, Huadi Zheng, Li Hu, Qingqing Ye, Yaxin Xiao, Yijie Jiao, Zi Liang","submitted_at":"2025-07-28T07:12:12Z","abstract_excerpt":"Machine unlearning enables the removal of specific data from ML models to uphold the right to be forgotten. While approximate unlearning algorithms offer efficient alternatives to full retraining, this work reveals that they fail to adequately protect the privacy of unlearned data. In particular, these algorithms introduce implicit residuals which facilitate privacy attacks targeting at unlearned data. We observe that these residuals persist regardless of model architectures, parameters, and unlearning algorithms, exposing a new attack surface beyond conventional output-based leakage. Based on"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.20573","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-07-28T07:12:12Z","cross_cats_sorted":[],"title_canon_sha256":"8fea0bf14e14f94406359c5235254006425bb29fd3c57ba8a44e48ce0355650c","abstract_canon_sha256":"354494a5e04445ce8128578654f5a8e6a4ad775f4ed9daf65d04db19d5c650c5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:44:21.813156Z","signature_b64":"7Nt7yTDU8Z1z7qdjW1236KlP8BEleIvFjbhx5cNMWAO8lm7k9vUOi75citvpt6GgfXfWfqTT8bFVSsjadaWEAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"eea95c9683ba49ca6a6159774bc8b12e479743af2c5f2d4b44f25c8696a75988","last_reissued_at":"2026-07-05T11:44:21.812748Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:44:21.812748Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Reminiscence Attack on Residuals: Exploiting Approximate Machine Unlearning for Privacy","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Haibo Hu, Haoyang Li, Huadi Zheng, Li Hu, Qingqing Ye, Yaxin Xiao, Yijie Jiao, Zi Liang","submitted_at":"2025-07-28T07:12:12Z","abstract_excerpt":"Machine unlearning enables the removal of specific data from ML models to uphold the right to be forgotten. While approximate unlearning algorithms offer efficient alternatives to full retraining, this work reveals that they fail to adequately protect the privacy of unlearned data. In particular, these algorithms introduce implicit residuals which facilitate privacy attacks targeting at unlearned data. We observe that these residuals persist regardless of model architectures, parameters, and unlearning algorithms, exposing a new attack surface beyond conventional output-based leakage. Based on"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.20573","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.20573/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.20573","created_at":"2026-07-05T11:44:21.812804+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.20573v1","created_at":"2026-07-05T11:44:21.812804+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.20573","created_at":"2026-07-05T11:44:21.812804+00:00"},{"alias_kind":"pith_short_12","alias_value":"52UVZFUDXJE4","created_at":"2026-07-05T11:44:21.812804+00:00"},{"alias_kind":"pith_short_16","alias_value":"52UVZFUDXJE4U2TB","created_at":"2026-07-05T11:44:21.812804+00:00"},{"alias_kind":"pith_short_8","alias_value":"52UVZFUD","created_at":"2026-07-05T11:44:21.812804+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ","json":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ.json","graph_json":"https://pith.science/api/pith-number/52UVZFUDXJE4U2TBLF3UXSFRFZ/graph.json","events_json":"https://pith.science/api/pith-number/52UVZFUDXJE4U2TBLF3UXSFRFZ/events.json","paper":"https://pith.science/paper/52UVZFUD"},"agent_actions":{"view_html":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ","download_json":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ.json","view_paper":"https://pith.science/paper/52UVZFUD","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.20573&json=true","fetch_graph":"https://pith.science/api/pith-number/52UVZFUDXJE4U2TBLF3UXSFRFZ/graph.json","fetch_events":"https://pith.science/api/pith-number/52UVZFUDXJE4U2TBLF3UXSFRFZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ/action/storage_attestation","attest_author":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ/action/author_attestation","sign_citation":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ/action/citation_signature","submit_replication":"https://pith.science/pith/52UVZFUDXJE4U2TBLF3UXSFRFZ/action/replication_record"}},"created_at":"2026-07-05T11:44:21.812804+00:00","updated_at":"2026-07-05T11:44:21.812804+00:00"}