{"id":"https://openalex.org/W7163044181","doi":"https://doi.org/10.4230/lipics.forc.2026.17","title":"Protecting the Undeleted in Machine Unlearning","display_name":"Protecting the Undeleted in Machine Unlearning","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7163044181","doi":"https://doi.org/10.4230/lipics.forc.2026.17"},"language":"en","primary_location":{"id":"pmh:oai:drops-oai.dagstuhl.de:25990","is_oa":true,"landing_page_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.FORC.2026.17","pdf_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.17/LIPIcs.FORC.2026.17.pdf","source":{"id":"https://openalex.org/S4377196569","display_name":"DROPS (Schloss Dagstuhl \u2013 Leibniz Center for Informatics)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2799853480","host_organization_name":"Schloss Dagstuhl \u2013 Leibniz Center for Informatics","host_organization_lineage":["https://openalex.org/I2799853480"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"},"type":"article","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.17/LIPIcs.FORC.2026.17.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5086202086","display_name":"Aloni Cohen","orcid":"https://orcid.org/0000-0002-3492-2447"},"institutions":[{"id":"https://openalex.org/I40347166","display_name":"University of Chicago","ror":"https://ror.org/024mw5h28","country_code":"US","type":"education","lineage":["https://openalex.org/I40347166"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Cohen, Aloni","raw_affiliation_strings":["University of Chicago, IL, USA"],"raw_orcid":"https://orcid.org/0000-0002-3492-2447","affiliations":[{"raw_affiliation_string":"University of Chicago, IL, USA","institution_ids":["https://openalex.org/I40347166"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041717137","display_name":"Refael Kohen","orcid":null},"institutions":[{"id":"https://openalex.org/I16391192","display_name":"Tel Aviv University","ror":"https://ror.org/04mhzgx49","country_code":"IL","type":"education","lineage":["https://openalex.org/I16391192"]}],"countries":["IL"],"is_corresponding":false,"raw_author_name":"Kohen, Refael","raw_affiliation_strings":["Tel Aviv University, Israel"],"raw_orcid":"https://orcid.org/0000-0002-3469-312X","affiliations":[{"raw_affiliation_string":"Tel Aviv University, Israel","institution_ids":["https://openalex.org/I16391192"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066000219","display_name":"Kobbi Nissim","orcid":"https://orcid.org/0000-0002-6632-8645"},"institutions":[{"id":"https://openalex.org/I184565670","display_name":"Georgetown University","ror":"https://ror.org/05vzafd60","country_code":"US","type":"education","lineage":["https://openalex.org/I184565670"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nissim, Kobbi","raw_affiliation_strings":["Dept. of Computer Science, Georgetown University, Washington, DC, USA"],"raw_orcid":"https://orcid.org/0000-0002-6632-8645","affiliations":[{"raw_affiliation_string":"Dept. of Computer Science, Georgetown University, Washington, DC, USA","institution_ids":["https://openalex.org/I184565670"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5019495492","display_name":"Uri Stemmer","orcid":"https://orcid.org/0000-0001-7584-8768"},"institutions":[{"id":"https://openalex.org/I16391192","display_name":"Tel Aviv University","ror":"https://ror.org/04mhzgx49","country_code":"IL","type":"education","lineage":["https://openalex.org/I16391192"]}],"countries":["IL"],"is_corresponding":false,"raw_author_name":"Stemmer, Uri","raw_affiliation_strings":["Tel Aviv University, Israel"],"raw_orcid":"https://orcid.org/0000-0001-7584-8768","affiliations":[{"raw_affiliation_string":"Tel Aviv University, Israel","institution_ids":["https://openalex.org/I16391192"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.89112249,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.392300009727478,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.392300009727478,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.14569999277591705,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.06759999692440033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7135000228881836},{"id":"https://openalex.org/keywords/retraining","display_name":"Retraining","score":0.5473999977111816},{"id":"https://openalex.org/keywords/carry","display_name":"Carry (investment)","score":0.45100000500679016},{"id":"https://openalex.org/keywords/mechanism","display_name":"Mechanism (biology)","score":0.35850000381469727},{"id":"https://openalex.org/keywords/data-security","display_name":"Data security","score":0.33340001106262207},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.32850000262260437},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3091000020503998}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7422999739646912},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7135000228881836},{"id":"https://openalex.org/C2778712577","wikidata":"https://www.wikidata.org/wiki/Q3505966","display_name":"Retraining","level":2,"score":0.5473999977111816},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.52920001745224},{"id":"https://openalex.org/C2776299755","wikidata":"https://www.wikidata.org/wiki/Q432449","display_name":"Carry (investment)","level":2,"score":0.45100000500679016},{"id":"https://openalex.org/C89611455","wikidata":"https://www.wikidata.org/wiki/Q6804646","display_name":"Mechanism (biology)","level":2,"score":0.35850000381469727},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3452000021934509},{"id":"https://openalex.org/C10511746","wikidata":"https://www.wikidata.org/wiki/Q899388","display_name":"Data security","level":3,"score":0.33340001106262207},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.32850000262260437},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3091000020503998},{"id":"https://openalex.org/C71745522","wikidata":"https://www.wikidata.org/wiki/Q2476929","display_name":"Confidentiality","level":2,"score":0.2883000075817108},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.2870999872684479},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.27410000562667847},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.27390000224113464},{"id":"https://openalex.org/C21080849","wikidata":"https://www.wikidata.org/wiki/Q13611879","display_name":"Data point","level":2,"score":0.25850000977516174},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.2558000087738037},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.25369998812675476}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:drops-oai.dagstuhl.de:25990","is_oa":true,"landing_page_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.FORC.2026.17","pdf_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.17/LIPIcs.FORC.2026.17.pdf","source":{"id":"https://openalex.org/S4377196569","display_name":"DROPS (Schloss Dagstuhl \u2013 Leibniz Center for Informatics)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2799853480","host_organization_name":"Schloss Dagstuhl \u2013 Leibniz Center for Informatics","host_organization_lineage":["https://openalex.org/I2799853480"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"},{"id":"doi:10.4230/lipics.forc.2026.17","is_oa":true,"landing_page_url":"https://doi.org/10.4230/lipics.forc.2026.17","pdf_url":null,"source":{"id":"https://openalex.org/S7407052059","display_name":"Dagstuhl Research Online Publication Server","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":""}],"best_oa_location":{"id":"pmh:oai:drops-oai.dagstuhl.de:25990","is_oa":true,"landing_page_url":"https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.FORC.2026.17","pdf_url":"https://drops.dagstuhl.de/storage/00lipics/lipics-vol368-forc2026/LIPIcs.FORC.2026.17/LIPIcs.FORC.2026.17.pdf","source":{"id":"https://openalex.org/S4377196569","display_name":"DROPS (Schloss Dagstuhl \u2013 Leibniz Center for Informatics)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2799853480","host_organization_name":"Schloss Dagstuhl \u2013 Leibniz Center for Informatics","host_organization_lineage":["https://openalex.org/I2799853480"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"publishedVersion"},"sustainable_development_goals":[{"score":0.7415188550949097,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7163044181.pdf","grobid_xml":"https://content.openalex.org/works/W7163044181.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Machine":[0],"unlearning":[1],"aims":[2],"to":[3,14,75,86,109,115],"remove":[4],"specific":[5],"data":[6,30,53,84,136],"points":[7,85],"from":[8],"a":[9,57,72,128],"trained":[10],"model,":[11],"often":[12],"striving":[13],"emulate":[15],"\"perfect":[16],"retraining\",":[17],"i.e.,":[18],"producing":[19],"the":[20,28,50,89,141],"model":[21],"that":[22,36,42,61,132,148],"would":[23],"have":[24],"been":[25,32],"obtained":[26],"had":[27],"deleted":[29],"never":[31],"included.":[33],"We":[34,55,97,146],"demonstrate":[35],"this":[37,124],"approach,":[38],"and":[39,160],"security":[40,130],"definitions":[41,100],"enable":[43],"it,":[44],"carry":[45],"significant":[46],"privacy":[47],"risks":[48],"for":[49,62,101],"remaining":[51],"(undeleted)":[52],"points.":[54,145],"present":[56],"reconstruction":[58],"attack":[59],"showing":[60,104],"certain":[63],"tasks,":[64],"which":[65],"can":[66],"be":[67],"computed":[68],"securely":[69],"without":[70],"deletions,":[71],"mechanism":[73],"adhering":[74],"perfect":[76],"retraining":[77],"allows":[78],"an":[79],"adversary":[80],"controlling":[81],"merely":[82],"\u03c9(1)":[83],"reconstruct":[87],"almost":[88],"entire":[90],"dataset":[91],"simply":[92],"by":[93,140],"issuing":[94],"deletion":[95,142],"requests.":[96],"survey":[98],"existing":[99],"machine":[102],"unlearning,":[103],"they":[105],"are":[106],"either":[107],"susceptible":[108],"such":[110,155],"attacks":[111],"or":[112],"too":[113],"restrictive":[114],"support":[116],"basic":[117],"functionalities":[118],"like":[119],"exact":[120],"summation.":[121],"To":[122],"address":[123],"problem,":[125],"we":[126],"propose":[127],"new":[129],"definition":[131,150],"specifically":[133],"safeguards":[134],"undeleted":[135],"against":[137],"leakage":[138],"caused":[139],"of":[143],"other":[144],"show":[147],"our":[149],"permits":[151],"several":[152],"essential":[153],"functionalities,":[154],"as":[156],"bulletin":[157],"boards,":[158],"summations,":[159],"statistical":[161],"learning.":[162]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-06-02T00:00:00"}
