{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:5N52KGFVJDS2YVAPY7U3KOM4T7","short_pith_number":"pith:5N52KGFV","schema_version":"1.0","canonical_sha256":"eb7ba518b548e5ac540fc7e9b5399c9fe443d2218895a0fecf20e033c393fd90","source":{"kind":"arxiv","id":"2406.13356","version":4},"attestation_state":"computed","paper":{"title":"Unlearning or Obfuscating? Jogging the Memory of Unlearned LLMs via Benign Relearning","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Shengyuan Hu, Virginia Smith, Yiwei Fu, Zhiwei Steven Wu","submitted_at":"2024-06-19T09:03:21Z","abstract_excerpt":"Machine unlearning is a promising approach to mitigate undesirable memorization of training data in ML models. However, in this work we show that existing approaches for unlearning in LLMs are surprisingly susceptible to a simple set of $\\textit{benign relearning attacks}$. With access to only a small and potentially loosely related set of data, we find that we can ''jog'' the memory of unlearned models to reverse the effects of unlearning. For example, we show that relearning on public medical articles can lead an unlearned LLM to output harmful knowledge about bioweapons, and relearning gene"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2406.13356","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-06-19T09:03:21Z","cross_cats_sorted":[],"title_canon_sha256":"9bde8fe427f25663b26ead7a56df3cfeaa7c959498428c37b295d1de272a193f","abstract_canon_sha256":"ff932b0bbac1dbff6f6c6e07e0d4683478e6111adee99a8734c2fbb876e80261"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:32:27.586376Z","signature_b64":"GG9taPfFQ+4Edy/0XzCZI7Lqw18sSTHqrEZ7tiSktXjyLNlnucYhVfReGeSrzmIxvtPo9Ifx7LNrrVzOezKMCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"eb7ba518b548e5ac540fc7e9b5399c9fe443d2218895a0fecf20e033c393fd90","last_reissued_at":"2026-07-05T10:32:27.585695Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:32:27.585695Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Unlearning or Obfuscating? Jogging the Memory of Unlearned LLMs via Benign Relearning","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Shengyuan Hu, Virginia Smith, Yiwei Fu, Zhiwei Steven Wu","submitted_at":"2024-06-19T09:03:21Z","abstract_excerpt":"Machine unlearning is a promising approach to mitigate undesirable memorization of training data in ML models. However, in this work we show that existing approaches for unlearning in LLMs are surprisingly susceptible to a simple set of $\\textit{benign relearning attacks}$. With access to only a small and potentially loosely related set of data, we find that we can ''jog'' the memory of unlearned models to reverse the effects of unlearning. For example, we show that relearning on public medical articles can lead an unlearned LLM to output harmful knowledge about bioweapons, and relearning gene"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2406.13356","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2406.13356/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2406.13356","created_at":"2026-07-05T10:32:27.585766+00:00"},{"alias_kind":"arxiv_version","alias_value":"2406.13356v4","created_at":"2026-07-05T10:32:27.585766+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2406.13356","created_at":"2026-07-05T10:32:27.585766+00:00"},{"alias_kind":"pith_short_12","alias_value":"5N52KGFVJDS2","created_at":"2026-07-05T10:32:27.585766+00:00"},{"alias_kind":"pith_short_16","alias_value":"5N52KGFVJDS2YVAP","created_at":"2026-07-05T10:32:27.585766+00:00"},{"alias_kind":"pith_short_8","alias_value":"5N52KGFV","created_at":"2026-07-05T10:32:27.585766+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2510.00761","citing_title":"Downgrade to Upgrade: Optimizer Simplification Enhances Robustness in LLM Unlearning","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.22076","citing_title":"PrivUn: Unveiling Latent Ripple Effects and Shallow Forgetting in Privacy Unlearning","ref_index":32,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07962","citing_title":"Is your algorithm unlearning or untraining?","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.17396","citing_title":"Representation-Guided Parameter-Efficient LLM Unlearning","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01699","citing_title":"Probe-Geometry Alignment: Erasing the Cross-Sequence Memorization Signature Below Chance","ref_index":6,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7","json":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7.json","graph_json":"https://pith.science/api/pith-number/5N52KGFVJDS2YVAPY7U3KOM4T7/graph.json","events_json":"https://pith.science/api/pith-number/5N52KGFVJDS2YVAPY7U3KOM4T7/events.json","paper":"https://pith.science/paper/5N52KGFV"},"agent_actions":{"view_html":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7","download_json":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7.json","view_paper":"https://pith.science/paper/5N52KGFV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2406.13356&json=true","fetch_graph":"https://pith.science/api/pith-number/5N52KGFVJDS2YVAPY7U3KOM4T7/graph.json","fetch_events":"https://pith.science/api/pith-number/5N52KGFVJDS2YVAPY7U3KOM4T7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7/action/storage_attestation","attest_author":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7/action/author_attestation","sign_citation":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7/action/citation_signature","submit_replication":"https://pith.science/pith/5N52KGFVJDS2YVAPY7U3KOM4T7/action/replication_record"}},"created_at":"2026-07-05T10:32:27.585766+00:00","updated_at":"2026-07-05T10:32:27.585766+00:00"}