{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:W3FSSJ6CGYI2QVJFWSNQ3OZCTO","short_pith_number":"pith:W3FSSJ6C","schema_version":"1.0","canonical_sha256":"b6cb2927c23611a85525b49b0dbb229b85a20152e4cbe5d4fce2ecff588626b6","source":{"kind":"arxiv","id":"2502.05374","version":4},"attestation_state":"computed","paper":{"title":"Towards LLM Unlearning Resilient to Relearning Attacks: A Sharpness-Aware Minimization Perspective and Beyond","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.LG","authors_text":"Anil Ramakrishna, Chongyu Fan, Jinghan Jia, Mingyi Hong, Sijia Liu, Yihua Zhang","submitted_at":"2025-02-07T23:03:55Z","abstract_excerpt":"The LLM unlearning technique has recently been introduced to comply with data regulations and address the safety and ethical concerns of LLMs by removing the undesired data-model influence. However, state-of-the-art unlearning methods face a critical vulnerability: they are susceptible to ``relearning'' the removed information from a small number of forget data points, known as relearning attacks. In this paper, we systematically investigate how to make unlearned models robust against such attacks. For the first time, we establish a connection between robust unlearning and sharpness-aware mini"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.05374","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-02-07T23:03:55Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"c74580974e8522b8f4dbfe3c3a2a4cd72da7543b0d37ed3433e2c7e60055d5f5","abstract_canon_sha256":"4177f31da9dfc04e0dd64c5f0f59e79dd28d78c645e04be04f3549026964c5f1"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:10:04.564925Z","signature_b64":"9mmXKWtl4Ko0j8eZVWu2DWvMPQSFK3suoYpsH4OaoICaVmDUsamsjG5KjwFrPpN6sFgHKQDbjOj4yzrxlXU6DQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b6cb2927c23611a85525b49b0dbb229b85a20152e4cbe5d4fce2ecff588626b6","last_reissued_at":"2026-07-05T11:10:04.563466Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:10:04.563466Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Towards LLM Unlearning Resilient to Relearning Attacks: A Sharpness-Aware Minimization Perspective and Beyond","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.LG","authors_text":"Anil Ramakrishna, Chongyu Fan, Jinghan Jia, Mingyi Hong, Sijia Liu, Yihua Zhang","submitted_at":"2025-02-07T23:03:55Z","abstract_excerpt":"The LLM unlearning technique has recently been introduced to comply with data regulations and address the safety and ethical concerns of LLMs by removing the undesired data-model influence. However, state-of-the-art unlearning methods face a critical vulnerability: they are susceptible to ``relearning'' the removed information from a small number of forget data points, known as relearning attacks. In this paper, we systematically investigate how to make unlearned models robust against such attacks. For the first time, we establish a connection between robust unlearning and sharpness-aware mini"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.05374","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.05374/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.05374","created_at":"2026-07-05T11:10:04.564290+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.05374v4","created_at":"2026-07-05T11:10:04.564290+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.05374","created_at":"2026-07-05T11:10:04.564290+00:00"},{"alias_kind":"pith_short_12","alias_value":"W3FSSJ6CGYI2","created_at":"2026-07-05T11:10:04.564290+00:00"},{"alias_kind":"pith_short_16","alias_value":"W3FSSJ6CGYI2QVJF","created_at":"2026-07-05T11:10:04.564290+00:00"},{"alias_kind":"pith_short_8","alias_value":"W3FSSJ6C","created_at":"2026-07-05T11:10:04.564290+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.07688","citing_title":"TRACER: Token ReAssignment for Concept ERasure in Generative Recommendation","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.14605","citing_title":"One Step to the Side: Why Defenses Against Malicious Finetuning Fail Under Adaptive Adversaries","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24614","citing_title":"Measuring the Depth of LLM Unlearning via Activation Patching","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15737","citing_title":"BARRIER: Bounded Activation Regions for Robust Information Erasure","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2510.00761","citing_title":"Downgrade to Upgrade: Optimizer Simplification Enhances Robustness in LLM Unlearning","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04982","citing_title":"CURE:Circuit-Aware Unlearning for LLM-based Recommendation","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09391","citing_title":"Efficient Unlearning through Maximizing Relearning Convergence Delay","ref_index":14,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO","json":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO.json","graph_json":"https://pith.science/api/pith-number/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/graph.json","events_json":"https://pith.science/api/pith-number/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/events.json","paper":"https://pith.science/paper/W3FSSJ6C"},"agent_actions":{"view_html":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO","download_json":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO.json","view_paper":"https://pith.science/paper/W3FSSJ6C","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.05374&json=true","fetch_graph":"https://pith.science/api/pith-number/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/graph.json","fetch_events":"https://pith.science/api/pith-number/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/action/storage_attestation","attest_author":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/action/author_attestation","sign_citation":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/action/citation_signature","submit_replication":"https://pith.science/pith/W3FSSJ6CGYI2QVJFWSNQ3OZCTO/action/replication_record"}},"created_at":"2026-07-05T11:10:04.564290+00:00","updated_at":"2026-07-05T11:10:04.564290+00:00"}