Pith. sign in

REVIEW 9 cited by

Certified Data Removal from Machine Learning Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1911.03030 v6 pith:FDSEYKHF submitted 2019-11-08 cs.LG stat.ML

classification cs.LGstat.ML
keywords datamodelremovalcertifiedlearningmachine-learningmechanismrequest
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Good data stewardship requires removal of data at the request of the data's owner. This raises the question if and how a trained machine-learning model, which implicitly stores information about its training data, should be affected by such a removal request. Is it possible to "remove" data from a machine-learning model? We study this problem by defining certified removal: a very strong theoretical guarantee that a model from which data is removed cannot be distinguished from a model that never observed the data to begin with. We develop a certified-removal mechanism for linear classifiers and empirically study learning settings in which this mechanism is practical.

Discussion (0). Sign in to comment.

Forward citations

Cited by 9 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Unlearning as Distribution Restoration: A Controlled Counterfactual Study, a Validated Selective Screen, and the Limits of Oracle-Free Certification

    cs.LG 2026-07 conditional novelty 7.0 of 10

    Matching a retrained oracle on trained probes can certify models that still retain held-out forget knowledge, and oracle-free unlearning certification is only possible for counterfactual, non-inferable facts.

  2. Invisible Watermarks, Visible Gains: Steering Machine Unlearning with Bi-Level Watermarking Design

    cs.CR 2025-08 conditional novelty 6.0 of 10

    Water4MU tunes an invisible watermark on data so that machine unlearning algorithms can remove requested images more effectively, beating prior methods on 'challenging forgets'.

  3. LoReUn: Data Itself Implicitly Provides Cues to Improve Machine Unlearning

    cs.LG 2025-07 conditional novelty 6.0 of 10

    LoReUn, a plug-in loss-based reweighting strategy, improves approximate machine unlearning by focusing updates on hard-to-forget low-loss data points.

  4. How to Protect Models against Adversarial Unlearning?

    cs.LG 2025-07 conditional novelty 6.0 of 10

    A 'healing' procedure that uses similar real examples as surrogates for unlearned data during fine-tuning mitigates accuracy loss from machine unlearning in several classification benchmarks.

  5. LLM Unlearning for Cyber Defense: A Survey on Methods, Challenges, and Emerging Threats

    cs.LG 2026-06 conditional novelty 4.0 of 10

    Most gradient-based LLM unlearning methods achieve behavioral suppression, not true forgetting, and current benchmarks cannot certify that knowledge has been removed.

  6. Membership Inference Attacks with False Discovery Rate Control

    stat.ML 2025-08 conditional novelty 4.0 of 10

    A post-hoc wrapper, MIAFdR, converts any membership inference attack scores into conformal p-values and applies a Benjamini-Hochberg correction, guaranteeing that the expected proportion of non-members among flagged m...

  7. Leveraging Distribution Matching to Make Approximate Machine Unlearning Faster

    cs.LG 2025-07 reject novelty 4.0 of 10

    A dual data and loss-centric method claims to speed up machine unlearning, but its MIA regularizer cancels itself and the test set is leaked into training.

  8. MRD-LiNet: A Novel Lightweight Hybrid CNN with Gradient-Guided Unlearning for Improved Drought Stress Identification

    cs.CV 2025-09 conditional novelty 3.0 of 10

    A 0.231M-parameter CNN achieves 90.0% accuracy on potato drought stress detection, and removing 5% of low-gradient-score training samples improves accuracy from 88.6% to 90.0%.

  9. Train Once, Forget Precisely: Anchored Optimization for Efficient Post-Hoc Unlearning

    cs.LG 2025-06 reject novelty 2.0 of 10

    FAMR uses a uniform-prediction KL loss plus an L2 anchor to original weights for class unlearning, but the theory is mis-derived and the method is a known variant of zero-shot unlearning.

Pith tools