[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82702-en":3,"doc-seo-82702-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82702,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","PPE-Bench：评估在私人-公共纠缠下的多模态大语言模型遗忘基准","Multimodal Large Language Models (MLLMs) can memorize sensitive private information from web data, creating privacy and copyright risks. Machine unlearning removes private knowledge without full retraining, yet current MLLM unlearning benchmarks fall short: they use overly simplified images and assume a fully separated forget/retain split. PPE-Bench introduces entangled private-public scenes where the target to forget coexists with public figures and landmarks, plus methods to preserve public context. Experiments show prior approaches often leak less privacy but significantly degrade adjacent public information.","PPE-Bench: A Benchmark for Evaluating MLLM Unlearning under  \nPrivate-Public Entanglement  \nXianren Zhang1 , Delvin Ce Zhang2 , Dongwon Lee1 , Suhang Wang1  \n1The Pennsylvania State University 2 University of Sheffield  \n{xzz5508,dongwon,[szw494}@psu.edu](szw494}@psu.edu),  \n[delvin.ce.zhang@sheffield.ac.uk](delvin.ce.zhang@sheffield.ac.uk)  \narXiv :2607 .02897v 1 [ cs .CR] 3 Jul 2026  \nAbstract  \nMultimodal Large Language Models (MLLMs) have shown strong capabilities, but they may memorize private information from web data, raising privacy concerns. Machine unlearning offers a way to remove such private knowledge without retraining from scratch. However, existing MLLM unlearning benchmarks have two major limitations. First, they rely on simplified images that contain only the single target individual, failing to reflect the visual complexity of real-world photos. Second, they typically assume that the forget set and retain set are fully separated, ignoring the fact that private information is often visually entangled with benign public information. For example, a private individual may appear with a public figure orin front of a well-known landmark, where unlearning the private target should not damage the public context. To address these limitations, we propose PPE-Bench, a new benchmark for evaluating MLLM unlearning under privatepublic entanglement. Each image contains a target individual to be forgotten and public information to be preserved, including public figure and landmark. We further introduce two simple but effective methods to better preserve public information during unlearning. Through experiments, we find that existing unlearning methods can reduce private information leakage, but often substantially harm adjacent public information. 1  \n1 Introduction  \nMultimodal Large Language Models (MLLMs) have demonstrated strong performance on a wide range of multimodal tasks (Li et al., 2024a), such as visual question answering (Kuang et al., 2025) and image captioning (Sarto et al., 2025) . However, as MLLMs are trained on large-scale data from internet that may contain sensitive and private information, they can memorize and reproduce such  \n1Data: [https://github.com/Zood123/PPE_Bench](https://github.com/Zood123/PPE_Bench)  \ncontent (Huang et al., 2024), which raises significant privacy and copyright concerns. Privacy regulations like GDPR (Hoofnagle et al., 2019) and CCPA (Pardau, 2018) enforce the right to be forgotten (Dang, 2021) . For instance, personal images and online profile information shared on social media and websites could unintentionally be included in the training data (Caldarella et al., 2024 ; Yanet al., 2024), causing privacy issues. In such cases, image owners may request that MLLMs forget the influence of this data. However, retraining MLLMs from scratch to remove sensitive knowledge is often impractical due to the high computational cost.  \nAs a result, unlearning methods (Liu et al., 2025 ; Huo et al., 2025 ; Zhaopan Xu et al., 2025 ; Li et al., 2024b ; Wu et al., 2025) are applied to MLLM models to “forget” such sensitive information without retraining the model from scratch. For example, some methods (Liu et al., 2025 ; Huo et al., 2025) try to remove visual patterns associated with specific entities, such as personal information including home address, occupation, and age. These methods typically finetune MLLMs using different objectives, such as maximizing the loss on private information or minimizing preference scores for sensitive content. Gradient Ascent (GA) (Yao and Xu, 2024), Gradient Difference (GD) (Liu et al., 2022) or Negative Preference Optimization (NPO)(Zhang et al., 2024) are common approaches used for MLLM unlearning.  \nRecently, several benchmarks (Dontsov et al., 2025 ; Liu et al., 2025) have been designed to evaluate the effectiveness of unlearning methods under the multimodal setting. CLEAR (Dontsov et al., 2025) is the first open-sourced benchmark specifically for multi","cbCaiowJh3lYzBP5","https://ap.wps.com/l/cbCaiowJh3lYzBP5","pdf",1218647,1,14,"English","en",105,"# Introduction\n## Existing Benchmarks\n## Limitations of Current Benchmarks\n## Proposed PPE-Bench\n## Methods for Preserving Public Information\n## Experimental Findings","[{\"question\":\"PPE-Bench解决了哪些现有MLLM遗忘基准的主要不足？\",\"answer\":\"现有基准使用过于简化的图像（仅含目标个体），且将forget set与retain set完全分离，忽略私人信息与公共信息在真实场景中的视觉纠缠。\"},{\"question\":\"PPE-Bench的图像构建包含哪些元素？\",\"answer\":\"每张图像都包含需要遗忘的目标个体，同时包含需要保留的公共信息，例如公共人物与知名地标。\"},{\"question\":\"实验结果显示了什么权衡问题？\",\"answer\":\"实验表明，现有遗忘方法确实能降低私人信息泄露，但往往会显著损害与之相邻的公共信息。\"}]",1784182383,35,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"ppe-bench-a-benchmark-for-evaluating-mllm-unlearning-under-private-public-entanglement","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/ppe-bench-a-benchmark-for-evaluating-mllm-unlearning-under-private-public-entanglement/82702/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"PPE-Bench解决了哪些现有MLLM遗忘基准的主要不足？","Question",{"text":75,"@type":76},"现有基准使用过于简化的图像（仅含目标个体），且将forget set与retain set完全分离，忽略私人信息与公共信息在真实场景中的视觉纠缠。","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"PPE-Bench的图像构建包含哪些元素？",{"text":80,"@type":76},"每张图像都包含需要遗忘的目标个体，同时包含需要保留的公共信息，例如公共人物与知名地标。",{"name":82,"@type":73,"acceptedAnswer":83},"实验结果显示了什么权衡问题？",{"text":84,"@type":76},"实验表明，现有遗忘方法确实能降低私人信息泄露，但往往会显著损害与之相邻的公共信息。","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":45,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":45,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]