[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84024-en":3,"doc-seo-84024-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84024,13056703019404,"Miles","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Auditing of Unlearning Algorithms","Evaluating whether unlearning algorithms truly remove training-data influence remains challenging. This work introduces a practical auditor that computes data-dependent lower bounds on the unlearning parameter ε using membership inference attacks. Experiments across multiple unlearning methods show a sharp gap: certified approaches such as model clipping and rewind-to-delete yield very small ε bounds that preserve their guarantees, while heuristic and empirical techniques produce large bounds, indicating poor unlearning. The auditor enables empirical falsification via hypothesis testing and is validated on CIFAR-100 and Shakespeare text.","arXiv :2607 .05898v 1 [ cs .LG] 7 Jul 2026  \nAuditing of Unlearning Algorithms  \nSahasrajit Sarmasarkar Anastasia Koloskova  \nStanford University University of Zurich  \n[sahasras@stanford.edu](sahasras@stanford.edu) [anastasiia.koloskova@uzh.ch](anastasiia.koloskova@uzh.ch)  \nSanmi Koyejo  \nStanford University  \n[sanmi@cs.stanford.edu](sanmi@cs.stanford.edu)  \nJuly 8, 2026  \nAbstract  \nEvaluating whether unlearning algorithms truly remove training data influence remains an open challenge. We propose a practical auditor that computes data-dependent lower bounds on the unlearning parameter ε using membership inference attacks. Evaluating multiple unlearning algorithms, we find a sharp separation: algorithms with rigorous guarantees, such as model clipping and rewind-to-delete, achieve very small ε bounds that do not falsify their unlearning guarantees, whereas empirical methods such as Hessian-based unlearning, interleaved ascent–descent, ascent on the forget set, and fine-tuning on the retain set exhibit large bounds, indicating poor unlearning. Our auditor provides a practical tool for empirically falsifying unlearning claims through a hypothesis-testing framework, and we validate it on CIFAR-100 and Shakespeare text. 1.  \n1 Introduction  \nMachine unlearning is the task of removing the influence of specific training samples from an already-trained model, ideally yielding a model that behaves as if those samples had never been seen during training Cao and Yang [2015] . Simply deleting a data point from the training set does not achieve this: its information remains embedded in the learned parameters and can often be recovered by an adversary with query access, e.g. via membership inference attacks Shokri et al. [2016], Carlini et al. [2022] . This motivates exact unlearning, which produces a model with the same distribution as one retrained from scratch on the retained data Bourtoule et al. [2021], Ginart et al. [2019], and approximate unlearning, which relaxes this requirement in exchange for efficiency Guo et al. [2020], Sekhari et al.  \n[2021], Neel et al. [2021], Golatkar et al. [2020], Kurmanji et al. [2023] .  \nWhile exact unlearning offers the strongest guarantees, it is largely impractical at scale: existing schemes are either restricted to simple models such as k-means Ginart et al. [2019] or rely on data sharding Bourtoule et al. [2021], trading utility for cheap deletion. To scale to deep networks, a parallel line of work develops approximate unlearning algorithms, with two kinds of compromise. The first family is heuristic and provides no formal guarantee, including Fisher/Hessian-based parameter scrubbing Golatkar et al. [2020], gradient ascent on the forget set, fine-tuning on the retain set, and interleaved ascent–descent schemes such as SCRUB Kurmanji et al. [2023] . The second family adopts the certified (ε,δ)-indistinguishability notion of Guo et al. [2020], borrowed from differential privacy, which requires the unlearned model to be (ε,δ)-indistinguishable Dwork and Roth [2014] from one retrained from scratch. This guarantee bounds the distinguishing advantage of any test operating on the unlearnt model relative to the baseline retrained model. Most certified-unlearning algorithms require (strong) convexity of the loss Guo et al. [2020], Sekhari et al. [2021], Neel et al. [2021], Qiao et al. [2025], Zhang et al. [2025] or a unique minimiser Allouah et al. [2025]; only a handful of recent methods provide certified guarantees for genuinely nonconvex losses Koloskova et al. [2025], Mu and Klabjan [2025], Chien et al. [2024], Chourasia and Shah [2023] .  \n1 Code available at: [https://github.com/Sahasrajit123/audit-unlearning-code](https://github.com/Sahasrajit123/audit-unlearning-code)  \nWhile the bounds above are theoretical, our goal in this paper is to design an auditor that uses empirical evidence to test whether a claimed unlearning guarantee actually holds. Formally, our goal is to reject the hypothesis ε ","cbCaii56Ed4hGHSE","https://ap.wps.com/l/cbCaii56Ed4hGHSE","pdf",983870,5,1,28,"English","en",105,"# Abstract\n# Introduction\n# Related work","[{\"question\":\"What problem does the paper address in unlearning evaluation?\",\"answer\":\"It addresses the difficulty of verifying whether unlearning algorithms genuinely remove the influence of training data.\"},{\"question\":\"How does the proposed auditor test unlearning guarantees?\",\"answer\":\"It computes data-dependent lower bounds on the unlearning parameter ε using membership inference attacks within a hypothesis-testing framework.\"},{\"question\":\"What empirical finding distinguishes certified from uncertified unlearning algorithms?\",\"answer\":\"Certified methods such as model clipping and rewind-to-delete produce very small ε lower bounds, while heuristic or empirical methods often produce large bounds that suggest ineffective unlearning.\"}]",1784192089,71,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"auditing-of-unlearning-algorithms","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/auditing-of-unlearning-algorithms/84024/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the paper address in unlearning evaluation?","Question",{"text":76,"@type":77},"It addresses the difficulty of verifying whether unlearning algorithms genuinely remove the influence of training data.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the proposed auditor test unlearning guarantees?",{"text":81,"@type":77},"It computes data-dependent lower bounds on the unlearning parameter ε using membership inference attacks within a hypothesis-testing framework.",{"name":83,"@type":74,"acceptedAnswer":84},"What empirical finding distinguishes certified from uncertified unlearning algorithms?",{"text":85,"@type":77},"Certified methods such as model clipping and rewind-to-delete produce very small ε lower bounds, while heuristic or empirical methods often produce large bounds that suggest ineffective unlearning.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]