{"id":"https://openalex.org/W3023153742","doi":"https://doi.org/10.1145/3460120.3484756","title":"When Machine Unlearning Jeopardizes Privacy","display_name":"When Machine Unlearning Jeopardizes Privacy","publication_year":2021,"publication_date":"2021-11-12","ids":{"openalex":"https://openalex.org/W3023153742","doi":"https://doi.org/10.1145/3460120.3484756","mag":"3023153742"},"language":"en","primary_location":{"id":"doi:10.1145/3460120.3484756","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3460120.3484756","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://serval.unil.ch/notice/serval:BIB_E901AD8FB769","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Min Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Min Chen","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Zhikun Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Zhikun Zhang","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Tianhao Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]},{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tianhao Wang","raw_affiliation_strings":["Carnegie Mellon University &amp; University of Virginia, Pittsburgh, PA, USA"],"affiliations":[{"raw_affiliation_string":"Carnegie Mellon University &amp; University of Virginia, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I74973139","https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Michael Backes","orcid":null},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Backes","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Mathias Humbert","orcid":null},"institutions":[{"id":"https://openalex.org/I97565354","display_name":"University of Lausanne","ror":"https://ror.org/019whta54","country_code":"CH","type":"education","lineage":["https://openalex.org/I97565354"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Mathias Humbert","raw_affiliation_strings":["University of Lausanne, Lausanne, Switzerland"],"affiliations":[{"raw_affiliation_string":"University of Lausanne, Lausanne, Switzerland","institution_ids":["https://openalex.org/I97565354"]}]},{"author_position":"last","author":{"id":null,"display_name":"Yang Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Yang Zhang","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security, Saarbr\u00fccken, Germany","institution_ids":["https://openalex.org/I4210128801"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I4210128801"],"apc_list":null,"apc_paid":null,"fwci":11.7562,"has_fulltext":true,"cited_by_count":143,"citation_normalized_percentile":{"value":0.98803321,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"896","last_page":"911"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.975600004196167,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7682999968528748},{"id":"https://openalex.org/keywords/notice","display_name":"Notice","score":0.6869999766349792},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.6068999767303467},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5759000182151794},{"id":"https://openalex.org/keywords/differential-privacy","display_name":"Differential privacy","score":0.5713000297546387},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.5491999983787537},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.5073999762535095}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.771399974822998},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7682999968528748},{"id":"https://openalex.org/C2779913896","wikidata":"https://www.wikidata.org/wiki/Q7063001","display_name":"Notice","level":2,"score":0.6869999766349792},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.6068999767303467},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5759000182151794},{"id":"https://openalex.org/C23130292","wikidata":"https://www.wikidata.org/wiki/Q5275358","display_name":"Differential privacy","level":2,"score":0.5713000297546387},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5579000115394592},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.5491999983787537},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5318999886512756},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.5073999762535095},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3910999894142151},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.38580000400543213},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.38499999046325684},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.32600000500679016},{"id":"https://openalex.org/C137822555","wikidata":"https://www.wikidata.org/wiki/Q2587068","display_name":"Information sensitivity","level":2,"score":0.32589998841285706},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.31520000100135803},{"id":"https://openalex.org/C3017597292","wikidata":"https://www.wikidata.org/wiki/Q25052250","display_name":"Privacy protection","level":2,"score":0.30959999561309814},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.28769999742507935},{"id":"https://openalex.org/C69360830","wikidata":"https://www.wikidata.org/wiki/Q1172237","display_name":"Data Protection Act 1998","level":2,"score":0.27799999713897705},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2648000121116638}],"mesh":[],"locations_count":7,"locations":[{"id":"doi:10.1145/3460120.3484756","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3460120.3484756","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"pmh:oai:research.vu.nl:openaire_cris_publications/2d551ccb-d736-4bfc-ae19-67cd869a7f26","is_oa":false,"landing_page_url":"https://research.vu.nl/en/publications/2d551ccb-d736-4bfc-ae19-67cd869a7f26","pdf_url":null,"source":{"id":"https://openalex.org/S4306401107","display_name":"VU Research Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I865915315","host_organization_name":"Vrije Universiteit Amsterdam","host_organization_lineage":["https://openalex.org/I865915315"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Chen, M, Zhang, Z, Wang, T, Backes, M, Humbert, M & Zhang, Y 2021, When Machine Unlearning Jeopardizes Privacy. in CCS 2021 : Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. Proceedings of the ACM Conference on Computer and Communications Security, Association for Computing Machinery, pp. 896-911. https://doi.org/10.1145/3460120.3484756","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:oai:serval.unil.ch:BIB_E901AD8FB769","is_oa":true,"landing_page_url":"https://serval.unil.ch/notice/serval:BIB_E901AD8FB769","pdf_url":null,"source":{"id":"https://openalex.org/S4306401797","display_name":"SERVAL (Universit\u00e9 de Lausanne)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210093590","host_organization_name":"Swiss School of Archaeology in Greece","host_organization_lineage":["https://openalex.org/I4210093590"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"CCS \u201921: 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 896-911","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:oai:arXiv.org:2005.02205","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2005.02205","pdf_url":"https://arxiv.org/pdf/2005.02205","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:iris.unil.ch:iris/245260","is_oa":true,"landing_page_url":"https://iris.unil.ch/handle/iris/245260","pdf_url":"https://iris.unil.ch/bitstreams/1de37abc-0e0d-4ff0-8c28-21c2df3d8e43/download","source":{"id":"https://openalex.org/S7407055444","display_name":"IRIS","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"},{"id":"pmh:oai:research.vu.nl:openaire_cris_publications/055c70ed-cc28-464d-bd6f-bad318d949dd","is_oa":true,"landing_page_url":"https://research.vu.nl/en/publications/055c70ed-cc28-464d-bd6f-bad318d949dd","pdf_url":null,"source":{"id":"https://openalex.org/S4306401107","display_name":"VU Research Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I865915315","host_organization_name":"Vrije Universiteit Amsterdam","host_organization_lineage":["https://openalex.org/I865915315"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Chen , M , Zhang , Z , Wang , T , Backes , M , Humbert , M & Zhang , Y 2021 ' When Machine Unlearning Jeopardizes Privacy ' arXiv , pp. 896-911 . https://doi.org/10.1145/3460120.3484756","raw_type":"workingPaper"},{"id":"pmh:oai:research.vu.nl:publications/2d551ccb-d736-4bfc-ae19-67cd869a7f26","is_oa":false,"landing_page_url":"https://hdl.handle.net/1871.1/2d551ccb-d736-4bfc-ae19-67cd869a7f26","pdf_url":null,"source":{"id":"https://openalex.org/S4306401107","display_name":"VU Research Portal","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I865915315","host_organization_name":"Vrije Universiteit Amsterdam","host_organization_lineage":["https://openalex.org/I865915315"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Chen, M, Zhang, Z, Wang, T, Backes, M, Humbert, M & Zhang, Y 2021, When Machine Unlearning Jeopardizes Privacy. in CCS 2021 : Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. Proceedings of the ACM Conference on Computer and Communications Security, Association for Computing Machinery, pp. 896-911. https://doi.org/10.1145/3460120.3484756","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"pmh:oai:serval.unil.ch:BIB_E901AD8FB769","is_oa":true,"landing_page_url":"https://serval.unil.ch/notice/serval:BIB_E901AD8FB769","pdf_url":null,"source":{"id":"https://openalex.org/S4306401797","display_name":"SERVAL (Universit\u00e9 de Lausanne)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210093590","host_organization_name":"Swiss School of Archaeology in Greece","host_organization_lineage":["https://openalex.org/I4210093590"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"CCS \u201921: 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 896-911","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G3994529929","display_name":null,"funder_award_id":"1931443","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5921281487","display_name":null,"funder_award_id":"number","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G6894402473","display_name":null,"funder_award_id":"Fellowship","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8301917259","display_name":null,"funder_award_id":"No.1931443","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G848032724","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":63,"referenced_works":["https://openalex.org/W1473189865","https://openalex.org/W1488996941","https://openalex.org/W2051267297","https://openalex.org/W2118858186","https://openalex.org/W2180612164","https://openalex.org/W2461943168","https://openalex.org/W2483058737","https://openalex.org/W2535690855","https://openalex.org/W2603766943","https://openalex.org/W2617174679","https://openalex.org/W2620038827","https://openalex.org/W2746021943","https://openalex.org/W2748789698","https://openalex.org/W2757528734","https://openalex.org/W2786233556","https://openalex.org/W2787698406","https://openalex.org/W2789304371","https://openalex.org/W2795435272","https://openalex.org/W2796004214","https://openalex.org/W2805779034","https://openalex.org/W2807096445","https://openalex.org/W2884943453","https://openalex.org/W2897830718","https://openalex.org/W2898291644","https://openalex.org/W2902543210","https://openalex.org/W2923095117","https://openalex.org/W2926319231","https://openalex.org/W2930926105","https://openalex.org/W2945693042","https://openalex.org/W2947227164","https://openalex.org/W2947642149","https://openalex.org/W2947693768","https://openalex.org/W2956128647","https://openalex.org/W2956311605","https://openalex.org/W2961073278","https://openalex.org/W2976822050","https://openalex.org/W2984055845","https://openalex.org/W2985940692","https://openalex.org/W2995395373","https://openalex.org/W3007299160","https://openalex.org/W3008580825","https://openalex.org/W3009148757","https://openalex.org/W3010489274","https://openalex.org/W3027379683","https://openalex.org/W3040639636","https://openalex.org/W3071470454","https://openalex.org/W3120302859","https://openalex.org/W3120806613","https://openalex.org/W3126152116","https://openalex.org/W3127447688","https://openalex.org/W3208464986","https://openalex.org/W6657138077","https://openalex.org/W6687483927","https://openalex.org/W6720608135","https://openalex.org/W6730467303","https://openalex.org/W6743986261","https://openalex.org/W6747732332","https://openalex.org/W6755343580","https://openalex.org/W6769833289","https://openalex.org/W6770444538","https://openalex.org/W6770880833","https://openalex.org/W6771961028","https://openalex.org/W7043248672"],"related_works":[],"abstract_inverted_index":{"The":[0],"right":[1,12,30],"to":[2,13,31,39,50,63,129,226],"be":[3,32],"forgotten":[4,33],"states":[5],"that":[6,73,118,159,172,191,202,235,250],"a":[7,55,113,132],"data":[8,16,42,44,69,82],"owner":[9,38],"has":[10],"the":[11,23,29,41,46,52,65,68,81,84,98,103,120,138,142,148,152,160,179,185,203,228,237],"erase":[14],"their":[15],"from":[17,45],"an":[18,35,124],"entity":[19],"storing":[20],"it.":[21],"In":[22,93],"context":[24],"of":[25,67,80,123,137,141,147,151,261],"machine":[26,74,109,192,262],"learning":[27],"(ML),":[28],"requires":[34],"ML":[36,53,85,125,187,211],"model":[37,86,144],"remove":[40],"owner's":[43],"training":[47,139,149],"set":[48,140,150],"used":[49],"build":[51],"model,":[54,188],"process":[56],"known":[57],"asmachine":[58],"unlearning.":[59,110,263],"While":[60],"originally":[61],"designed":[62],"protect":[64],"privacy":[66,91,204,231,245,256],"owner,":[70],"we":[71,96,170],"argue":[72],"unlearning":[75,193],"may":[76],"leave":[77],"some":[78],"imprint":[79],"in":[83,175,258],"and":[87,233,243],"thus":[88],"create":[89],"unintended":[90,104],"risks.":[92],"this":[94],"paper,":[95],"perform":[97,219],"first":[99],"study":[100],"on":[101,184,198],"investigating":[102],"information":[105],"leakage":[106],"caused":[107],"by":[108],"We":[111,200,221,248],"propose":[112],"novel":[114],"membership":[115,162,181,215],"inference":[116,163,182,216],"attack":[117,164,174,183],"leverages":[119],"different":[121],"outputs":[122],"model's":[126],"two":[127],"versions":[128],"infer":[130],"whether":[131],"target":[133],"sample":[134],"is":[135,206,266],"part":[136],"original":[143,186],"but":[145],"out":[146],"corresponding":[153],"unlearned":[154],"model.":[155],"Our":[156],"experiments":[157],"demonstrate":[158],"proposed":[161],"achieves":[165],"strong":[166],"performance.":[167],"More":[168],"importantly,":[169],"show":[171,234],"our":[173,251],"multiple":[176],"cases":[177],"outperforms":[178],"classical":[180,214],"which":[189],"indicates":[190],"can":[194,253],"have":[195],"counterproductive":[196],"effects":[197],"privacy.":[199],"notice":[201],"degradation":[205],"especially":[207],"significant":[208],"for":[209],"well-generalized":[210],"models":[212],"where":[213],"does":[217],"not":[218],"well.":[220],"further":[222],"investigate":[223],"four":[224],"mechanisms":[225],"mitigate":[227],"newly":[229],"discovered":[230],"risks":[232],"releasing":[236],"predicted":[238],"label":[239],"only,":[240],"temperature":[241],"scaling,":[242],"differential":[244],"are":[246],"effective.":[247],"believe":[249],"results":[252],"help":[254],"improve":[255],"protection":[257],"practical":[259],"implementations":[260],"\\footnoteOur":[264],"code":[265],"available":[267],"at":[268],"\\urlhttps://github.com/MinChen00/UnlearningLeaks.":[269]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":55},{"year":2024,"cited_by_count":42},{"year":2023,"cited_by_count":25},{"year":2022,"cited_by_count":12},{"year":2021,"cited_by_count":5}],"updated_date":"2026-04-06T07:47:59.780226","created_date":"2020-05-13T00:00:00"}
