[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84138-en":3,"doc-seo-84138-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84138,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","POPS: Recovering Unlearned Multi-Modality Knowledge in MLLMs with Prompt-Optimized Parameter Shaking","Multimodal Large Language Models (MLLMs) can unintentionally encode privacy-sensitive examples from large-scale training data, motivating Multi-modality Machine Unlearning (MMU) to erase private information. Existing MMU is not fully robust after model release, since malicious users may attempt to recover supposedly removed knowledge. This paper introduces Prompt-Optimized Parameter Shaking (POPS), which uses prompt-suffix optimization to elicit candidate private examples and then fine-tunes the model to disclose true sensitive content, revealing major weaknesses across MMU benchmarks.","arXiv :2607 .06649v 1 [ cs .CR] 7 Jul 2026  \nPOPS: Recovering Unlearned Multi-Modality Knowledge in MLLMs with Prompt-Optimized Parameter Shaking  \nZhangheng Li  \nUniversity of Texas at Austin  \nJianing Zhu  \nUniversity of Texas at Austin  \nJunyuan Hong  \nUniversity of Texas at Austin  \nSungmin Eum  \nDEVCOM Army Research Laboratory  \nShuowen Hu  \nDEVCOM Army Research Laboratory  \nSuya You  \nDEVCOM Army Research Laboratory  \nZhangyang Wang  \nUniversity of Texas at Austin  \n[zoharli@utexas. edu](zoharli@utexas. edu)  \n[jianing.zhu@austin.utexas. edu](jianing.zhu@austin.utexas. edu)  \n[jyhong@utexas. edu](jyhong@utexas. edu)  \n[sungmin. eum.civ@army.mil](sungmin. eum.civ@army.mil)  \n[shuowen.hu.civ@army.mil](shuowen.hu.civ@army.mil)  \n[Suya.you.civ@army.mil](Suya.you.civ@army.mil)  \n[atlaswang@utexas. edu](atlaswang@utexas. edu)  \nAbstract  \nMultimodal Large Language Models (MLLMs) have demonstrated impressive performance on cross-modal tasks by jointly training on large-scale textual and visual data, where privacysensitive examples could be unintentionally encoded, raising concerns about privacy or copyright violation. To this end, Multi-modality Machine Unlearning (MMU) was proposed as a mitigation that can effectively force MLLMs to forget private information. However, the robustness of such unlearning methods is not fully exploited when the model is published and accessible to malicious users. In this paper, we propose a novel adversarial strategy, namely Prompt-Optimized Parameter Shaking (POPS), aiming to recover the supposedly unlearned multi-modality knowledge from the MLLMs. Our method elicits the victim MLLMs to generate potential private examples via prompt-suffix optimization, and then exploits these synthesized outputs to fine-tune the models so they disclose the true private information. The experiments on the different MMU benchmarks reveal substantial weaknesses in the existing MMU algorithms. Our POPS can even achieve a near-complete recovery of supposedly erased sensitive information on the unlearned MLLMs, exposing fundamental vulnerabilities that challenge the foundational robustness of representative MMU-based privacy protections.  \n1 Introduction  \nRecent advances in Multimodal Large Language Models (MLLMs), which take multimodal information as input and answer user questions like LLMs, have successfully integrated visual and textual components, achieving remarkable performance and generalization capabilities on tasks including multimodal conversation (Moon et al. , 2020 ; Sundar & Heck, 2022 ; Zhan et al. , 2024 ; Talmor et al. , 2021), visual reasoning (Liu et al. , 2023 ; Kil et al. , 2024 ; Gupta & Kembhavi, 2023), and cross-modal content understanding (Zhang et al. , 2024a; Liu et al. , 2024a; Jing et al. , 2024) . The success of MLLMs typically relies on massive datasets that  \nmay inadvertently contain sensitive or private information. Regulations like the General Data Protection Regulation (GDPR) (Hoofnagle et al. , 2019) underscore the critical need for methods to effectively protect privacy-sensitive data. However, the development of MLLMs further enriches the risks of privacy leakage beyond conventional single-modality scenarios due to complex cross-modal dependencies (Li et al. , 2024a;b) .  \nWhen sensitive information has already been encoded in an MLLM, Machine Unlearning (MU) emerges as a post-hoc solution and has seen substantial research interest (Bourtoule et al. , 2021) . Recent work on MMU has proposed adaptations of unimodal unlearning methods (Bourtoule et al. , 2021 ; Nguyen et al. , 2022 ; Zhang et al. , 2024b; Fan et al. , 2023 ; Yao et al. , 2024), as well as dedicated multimodal methods and benchmarks (Dontsov et al. , 2024 ; Patil et al. , 2025), with evaluation typically focusing on whether unlearned models can still directly recall targeted instances. For instance, Dontsov et al. (2024) developed the first benchmark to evaluate MU methods in multi-modality setups, showing that j","cbCaifI8tQudSh1e","https://ap.wps.com/l/cbCaifI8tQudSh1e","pdf",748492,6,1,21,"English","en",105,"# Introduction\n# Abstract\n# Background and Related Work\n# Problem Setting and Threat Model","[{\"question\":\"What privacy risk do multimodal large language models face?\",\"answer\":\"They may inadvertently encode privacy-sensitive or copyrighted examples from training data, leading to potential privacy leakage even across modalities.\"},{\"question\":\"What does POPS aim to do against unlearning methods?\",\"answer\":\"POPS targets the supposed erasure of sensitive knowledge by recovering it, using prompt-suffix optimization to generate candidate private examples and then fine-tuning to force disclosure.\"},{\"question\":\"How is POPS evaluated and what do the results show?\",\"answer\":\"Experiments on multiple MMU benchmarks show substantial weaknesses in existing MMU algorithms, with POPS achieving near-complete recovery of erased sensitive information in unlearned MLLMs.\"}]",1784193266,53,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"pops-recovering-unlearned-multi-modality-knowledge-in-mllms-with-prompt-optimized-parameter-shaking","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/pops-recovering-unlearned-multi-modality-knowledge-in-mllms-with-prompt-optimized-parameter-shaking/84138/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What privacy risk do multimodal large language models face?","Question",{"text":76,"@type":77},"They may inadvertently encode privacy-sensitive or copyrighted examples from training data, leading to potential privacy leakage even across modalities.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What does POPS aim to do against unlearning methods?",{"text":81,"@type":77},"POPS targets the supposed erasure of sensitive knowledge by recovering it, using prompt-suffix optimization to generate candidate private examples and then fine-tuning to force disclosure.",{"name":83,"@type":74,"acceptedAnswer":84},"How is POPS evaluated and what do the results show?",{"text":85,"@type":77},"Experiments on multiple MMU benchmarks show substantial weaknesses in existing MMU algorithms, with POPS achieving near-complete recovery of erased sensitive information in unlearned MLLMs.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]