How Secure is Forgetting? Linking Machine Unlearning to Machine Learning Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: P., Muhammed Shafi K., Nicolazzo, Serena, Nocera, Antonino, P, Vinod
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914084706844672
author P., Muhammed Shafi K.
Nicolazzo, Serena
Nocera, Antonino
P, Vinod
author_facet P., Muhammed Shafi K.
Nicolazzo, Serena
Nocera, Antonino
P, Vinod
contents As Machine Learning (ML) evolves, the complexity and sophistication of security threats against this paradigm continue to grow as well, threatening data privacy and model integrity. In response, Machine Unlearning (MU) is a recent technology that aims to remove the influence of specific data from a trained model, enabling compliance with privacy regulations and user requests. This can be done for privacy compliance (e.g., GDPR's right to be forgotten) or model refinement. However, the intersection between classical threats in ML and MU remains largely unexplored. In this Systematization of Knowledge (SoK), we provide a structured analysis of security threats in ML and their implications for MU. We analyze four major attack classes, namely, Backdoor Attacks, Membership Inference Attacks (MIA), Adversarial Attacks, and Inversion Attacks, we investigate their impact on MU and propose a novel classification based on how they are usually used in this context. Finally, we identify open challenges, including ethical considerations, and explore promising future research directions, paving the way for future research in secure and privacy-preserving Machine Unlearning.
format Preprint
id arxiv_https___arxiv_org_abs_2503_20257
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle How Secure is Forgetting? Linking Machine Unlearning to Machine Learning Attacks
P., Muhammed Shafi K.
Nicolazzo, Serena
Nocera, Antonino
P, Vinod
Cryptography and Security
As Machine Learning (ML) evolves, the complexity and sophistication of security threats against this paradigm continue to grow as well, threatening data privacy and model integrity. In response, Machine Unlearning (MU) is a recent technology that aims to remove the influence of specific data from a trained model, enabling compliance with privacy regulations and user requests. This can be done for privacy compliance (e.g., GDPR's right to be forgotten) or model refinement. However, the intersection between classical threats in ML and MU remains largely unexplored. In this Systematization of Knowledge (SoK), we provide a structured analysis of security threats in ML and their implications for MU. We analyze four major attack classes, namely, Backdoor Attacks, Membership Inference Attacks (MIA), Adversarial Attacks, and Inversion Attacks, we investigate their impact on MU and propose a novel classification based on how they are usually used in this context. Finally, we identify open challenges, including ethical considerations, and explore promising future research directions, paving the way for future research in secure and privacy-preserving Machine Unlearning.
title How Secure is Forgetting? Linking Machine Unlearning to Machine Learning Attacks
topic Cryptography and Security
url https://arxiv.org/abs/2503.20257