{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:PFK7GKWIZ76D72GZUPSQUSS6PY","short_pith_number":"pith:PFK7GKWI","schema_version":"1.0","canonical_sha256":"7955f32ac8cffc3fe8d9a3e50a4a5e7e2d8f9db95c96085b970d60b1e1a372c5","source":{"kind":"arxiv","id":"2511.04934","version":3},"attestation_state":"computed","paper":{"title":"Leak@$k$: Unlearning Does Not Make LLMs Forget Under Probabilistic Decoding","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Hadi Reisizadeh, Jiajun Ruan, Mingyi Hong, Sijia Liu, Soumyadeep Pal, Yiwei Chen","submitted_at":"2025-11-07T02:30:05Z","abstract_excerpt":"Unlearning in large language models (LLMs) is critical for regulatory compliance and for building ethical generative AI systems that avoid producing private, toxic, illegal, or copyrighted content. Despite rapid progress, in this work, we show that \\textit{almost all} existing unlearning methods fail to achieve true forgetting in practice. Specifically, while evaluations of these `unlearned' models under deterministic (greedy) decoding often suggest successful knowledge removal using standard benchmarks, we show that sensitive information reliably resurfaces when models are sampled with standa"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2511.04934","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-11-07T02:30:05Z","cross_cats_sorted":[],"title_canon_sha256":"4cd68bed1d057db6864cfd506beaf2359a84e56506f6d1816c935d73d493d821","abstract_canon_sha256":"8ee486415041487365e543261a18ba0a59e67c80e1a41442f51bbeed991d9aaf"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T01:04:36.084876Z","signature_b64":"zi4oQGIQiOkCBr2aDn8Laio9rAuZNMpTd0EuQ/iWRJeNWRh0cuuCzHABKdxR3HmTmNxqXzJFc5b+ctaHXy44BQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7955f32ac8cffc3fe8d9a3e50a4a5e7e2d8f9db95c96085b970d60b1e1a372c5","last_reissued_at":"2026-05-29T01:04:36.084324Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T01:04:36.084324Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Leak@$k$: Unlearning Does Not Make LLMs Forget Under Probabilistic Decoding","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Hadi Reisizadeh, Jiajun Ruan, Mingyi Hong, Sijia Liu, Soumyadeep Pal, Yiwei Chen","submitted_at":"2025-11-07T02:30:05Z","abstract_excerpt":"Unlearning in large language models (LLMs) is critical for regulatory compliance and for building ethical generative AI systems that avoid producing private, toxic, illegal, or copyrighted content. Despite rapid progress, in this work, we show that \\textit{almost all} existing unlearning methods fail to achieve true forgetting in practice. Specifically, while evaluations of these `unlearned' models under deterministic (greedy) decoding often suggest successful knowledge removal using standard benchmarks, we show that sensitive information reliably resurfaces when models are sampled with standa"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2511.04934","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2511.04934/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2511.04934","created_at":"2026-05-29T01:04:36.084396+00:00"},{"alias_kind":"arxiv_version","alias_value":"2511.04934v3","created_at":"2026-05-29T01:04:36.084396+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2511.04934","created_at":"2026-05-29T01:04:36.084396+00:00"},{"alias_kind":"pith_short_12","alias_value":"PFK7GKWIZ76D","created_at":"2026-05-29T01:04:36.084396+00:00"},{"alias_kind":"pith_short_16","alias_value":"PFK7GKWIZ76D72GZ","created_at":"2026-05-29T01:04:36.084396+00:00"},{"alias_kind":"pith_short_8","alias_value":"PFK7GKWI","created_at":"2026-05-29T01:04:36.084396+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2605.16776","citing_title":"Distinguishable Deletion: Unifying Knowledge Erasure and Refusal for Large Language Model Unlearning","ref_index":23,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY","json":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY.json","graph_json":"https://pith.science/api/pith-number/PFK7GKWIZ76D72GZUPSQUSS6PY/graph.json","events_json":"https://pith.science/api/pith-number/PFK7GKWIZ76D72GZUPSQUSS6PY/events.json","paper":"https://pith.science/paper/PFK7GKWI"},"agent_actions":{"view_html":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY","download_json":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY.json","view_paper":"https://pith.science/paper/PFK7GKWI","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2511.04934&json=true","fetch_graph":"https://pith.science/api/pith-number/PFK7GKWIZ76D72GZUPSQUSS6PY/graph.json","fetch_events":"https://pith.science/api/pith-number/PFK7GKWIZ76D72GZUPSQUSS6PY/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY/action/storage_attestation","attest_author":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY/action/author_attestation","sign_citation":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY/action/citation_signature","submit_replication":"https://pith.science/pith/PFK7GKWIZ76D72GZUPSQUSS6PY/action/replication_record"}},"created_at":"2026-05-29T01:04:36.084396+00:00","updated_at":"2026-05-29T01:04:36.084396+00:00"}