[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-151785-en":3,"doc-seo-151785-105":30,"detail-sidebar-cat-0-en-105":96},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},151785,13056703019404,"Miles","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Invisible Watermarks - Visible Gains - Steering Machine Unlearning with Bi-Level Watermarking Design","Increasing demand for the right to be forgotten has made machine unlearning (MU) essential for removing sensitive data effects while preserving performance on unrelated data. Existing MU mainly updates model weights using in-training methods, leaving limited exploration of whether data-level adjustments help. This work proposes a watermarking-assisted MU framework that enables controlled removal of specified data. It introduces WATER4MU, a bi-level optimization that reduces unlearning difficulty by designing watermarks while keeping the model training independent. Experiments show improved MU effectiveness in image classification and generation, especially on challenging forgets.","This ICCV paper is the Open Access version, provided by the Computer Vision Foundation.  \nExcept for this watermark, it is identical to the accepted version; the final published version of the proceedings is available on IEEE Xplore.  \nInvisible Watermarks, Visible Gains: Steering Machine Unlearning with Bi-Level Watermarking Design  \nYuhao Sun 1 ,2 , Yihua Zhang3 , Gaowen Liu4 , Hongtao Xie 1 *†, Sijia Liu3∗  \n1University of Science and Technology of China,  \n2Institute of Artificial Intelligence, Hefei Comprehensive National Science Center, 3Michigan State University, 4 Cisco Research  \nAbstract  \nWith the increasing demand for the right to be forgotten, machine unlearning (MU) has emerged as a vital tool for enhancing trust and regulatory compliance by enabling the removal of sensitive data influences from machine learning (ML) models. However, most MU algorithms primarily rely on in-training methods to adjust model weights, with limited exploration of the benefits that data-level adjustments could bring to the unlearning process. To address this gap, we propose a novel approach that leverages digital watermarking to facilitate MU. By integrating watermarking, we establish a controlled unlearning mechanism that enables precise removal of specified data while maintaining model utility for unrelated tasks. We first examine the impact of watermarked data on MU, finding that MU effectively generalizes to watermarked data. Building on this, we introduce an unlearning-friendly watermarking framework, termed WATER4MU, to enhance unlearning effectiveness. The core of WATER4MU is a bi-level optimization (BLO) framework: at the upper level, the watermarking network is optimized to minimize unlearning difficulty, while at the lower level, the model itself is trained independently of watermarking. Experimental results demonstrate that WATER4MU is effective in MU across both image classification and image generation tasks. Notably, it outperforms existing methods in challenging MU scenarios, known as “challenging forgets”.  \n1. Introduction  \nMachine unlearning (MU), which aims to remove the influence of unwanted data from a pre-trained model while preserving the model’s utility on data unrelated to the unlearning request, has emerged as a promising approach for customizing and adapting machine learning (ML) models  \n*Equal advising  \n†Corresponding author  \nFigure 1 . An overview of the watermarking for machine unlearning framework via bi-level optimization proposed in this work.  \nto diverse contexts and requirements [1–4] . For example, MU is widely used to enhance model privacy, aligning with the right to be forgotten by removing private or copyrighted information from models to prevent privacy breaches [5–9] . It has also been applied to improve model generalization in transfer learning by removing the influence of undesired source data in pre-trained models, where removing nonsalient source data to downstream tasks improves fine-tuning performance [10, 11] . Furthermore, MU shows promise in enhancing model robustness, for instance, by removing the influence of backdoored training data to defend against backdoor attacks [12, 13] or eliminating harmful data to improve the model’s trust [14–16] .  \nThe expanding applications of MU across diverse domains and model types–including discriminative and generative models [17, 18]–are driven by its effectiveness in erasing specific data influence within ML models. That is, a key aspect of MU involves characterizing the influence of specific data on the model and leveraging this data-model  \ninteraction to adjust the model for effective unlearning. However, predominant research in MU focuses on model-based weight updating as the primary approach to achieve the unlearning objective [19–25], with less attention given to the impact of data modifications–such as watermarking, which we will investigate in this work–on MU effectiveness.  \nDigital watermarking, which embeds ownership signatures (kn","cbCaib3gLfzPYw8J","https://ap.wps.com/l/cbCaib3gLfzPYw8J","pdf",5330326,1,12,"English","en",105,"# Introduction\n## Problem motivation: right to be forgotten and machine unlearning\n## Data-level perspective: watermarking as a controllable modification\n## Research question and two integration paradigms\n## WATER4MU overview and bi-level optimization idea","[{\"question\":\"What problem does the paper address in machine unlearning?\",\"answer\":\"It addresses how to remove the influence of specified sensitive data while keeping utility on unrelated tasks, focusing on whether data-level modifications can improve MU rather than relying only on weight updates.\"},{\"question\":\"How does watermarking affect unlearning effectiveness according to the paper?\",\"answer\":\"The paper investigates watermarking in MU and finds that unlearning generalizes well to watermarked data, with watermarking behaving largely orthogonally to unlearning and causing minimal negative impact.\"},{\"question\":\"What is WATER4MU and how does it work?\",\"answer\":\"WATER4MU is an MU-aware watermarking framework built on bi-level optimization: the upper level optimizes the watermarking network to minimize unlearning difficulty, while the lower level trains the model independently of watermarking.\"},{\"question\":\"On what tasks and scenarios does the proposed method improve results?\",\"answer\":\"The experiments evaluate both image classification and image generation, and the method improves performance particularly in challenging forget scenarios called “challenging forgets”.\"}]","Invisible Watermarks - Visible Gains - Steering Machine Unlearning with Bi-Level Watermarking Design | PDF",1787849300,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":91,"head_meta":93,"extra_data":95,"updated_unix":28},"invisible-watermarks-visible-gains-steering-machine-unlearning-with-bi-level-watermarking-design","",{"@graph":36,"@context":90},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/invisible-watermarks-visible-gains-steering-machine-unlearning-with-bi-level-watermarking-design/151785/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-09-04","2026-08-27",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82,86],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the paper address in machine unlearning?","Question",{"text":76,"@type":77},"It addresses how to remove the influence of specified sensitive data while keeping utility on unrelated tasks, focusing on whether data-level modifications can improve MU rather than relying only on weight updates.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does watermarking affect unlearning effectiveness according to the paper?",{"text":81,"@type":77},"The paper investigates watermarking in MU and finds that unlearning generalizes well to watermarked data, with watermarking behaving largely orthogonally to unlearning and causing minimal negative impact.",{"name":83,"@type":74,"acceptedAnswer":84},"What is WATER4MU and how does it work?",{"text":85,"@type":77},"WATER4MU is an MU-aware watermarking framework built on bi-level optimization: the upper level optimizes the watermarking network to minimize unlearning difficulty, while the lower level trains the model independently of watermarking.",{"name":87,"@type":74,"acceptedAnswer":88},"On what tasks and scenarios does the proposed method improve results?",{"text":89,"@type":77},"The experiments evaluate both image classification and image generation, and the method improves performance particularly in challenging forget scenarios called “challenging forgets”.","https://schema.org",{"og:url":52,"og:type":92,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":94,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":97},[98,102,106,110,115,120,125,127,132,135,139],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Exam",70,"exam",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},5,"Comic",60,"comic",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},6,"Technology",50,"technology",{"id":121,"doc_module":4,"doc_module_name":46,"category_name":122,"show_sort_weight":123,"slug":124},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":126},"research-report",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":130,"slug":131},9,"Religion & Spirituality",20,"religion-spirituality",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":130,"slug":134},"World Cup","world-cup",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":136,"slug":138},10,"Lifestyle","lifestyle",{"id":140,"doc_module":4,"doc_module_name":46,"category_name":141,"show_sort_weight":111,"slug":142},19,"General","general"]