Reminiscence Attack on Residuals: Exploiting Approximate Machine Unlearning for Privacy
Xiao, Yaxin, Ye, Qingqing, Hu, Li, Zheng, Huadi, Hu, Haibo, Liang, Zi, Li, Haoyang, Jiao, Yijie
–arXiv.org Artificial Intelligence
Machine unlearning enables the removal of specific data from ML models to uphold the right to be forgotten . While approximate unlearning algorithms offer efficient alternatives to full retraining, this work reveals that they fail to adequately protect the privacy of unlearned data. In particular, these algorithms introduce implicit residuals which facilitate privacy attacks targeting at unlearned data. W e observe that these residuals persist regardless of model architectures, parameters, and unlearning algorithms, exposing a new attack surface beyond conventional output-based leakage. Based on this insight, we propose the Reminiscence Attack (ReA), which amplifies the correlation between residuals and membership privacy through targeted fine-tuning processes. ReA achieves up to 1. 90 and 1.12 higher accuracy than prior attacks when inferring class-wise and sample-wise membership, respectively. T o mitigate such residual-induced privacy risk, we develop a dual-phase approximate unlearning framework that first eliminates deep-layer unlearned data traces and then enforces convergence stability to prevent models from "pseudo-convergence", where their outputs are similar to retrained models but still preserve unlearned residuals. Our framework works for both classification and generation tasks. Experimental evaluations confirm that our approach maintains high unlearning efficacy, while reducing the adaptive privacy attack accuracy to nearly random guess, at the computational cost of 2 12% of full retraining from scratch.
arXiv.org Artificial Intelligence
Jul-29-2025
- Country:
- Asia > China
- Hong Kong (0.04)
- Europe > Austria
- Vienna (0.14)
- North America
- Canada > British Columbia
- Vancouver (0.04)
- United States
- California
- Orange County > Anaheim (0.04)
- San Diego County > San Diego (0.04)
- San Francisco County > San Francisco (0.14)
- Santa Clara County > San Jose (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- Virginia (0.04)
- Washington > King County
- Seattle (0.04)
- California
- Canada > British Columbia
- Oceania > Australia
- New South Wales > Sydney (0.04)
- Asia > China
- Genre:
- Research Report (1.00)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology:
- Information Technology
- Artificial Intelligence
- Machine Learning
- Neural Networks > Deep Learning (0.67)
- Performance Analysis > Accuracy (0.69)
- Natural Language (0.93)
- Representation & Reasoning (1.00)
- Vision (1.00)
- Machine Learning
- Security & Privacy (1.00)
- Sensing and Signal Processing (0.93)
- Artificial Intelligence
- Information Technology