GUARD: Generation-time LLM Unlearning via Adaptive Restriction and Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Deng, Zhijie, Liu, Chris Yuhao, Pang, Zirui, He, Xinlei, Feng, Lei, Xuan, Qi, Zhu, Zhaowei, Wei, Jiaheng
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916744426160128
author Deng, Zhijie
Liu, Chris Yuhao
Pang, Zirui
He, Xinlei
Feng, Lei
Xuan, Qi
Zhu, Zhaowei
Wei, Jiaheng
author_facet Deng, Zhijie
Liu, Chris Yuhao
Pang, Zirui
He, Xinlei
Feng, Lei
Xuan, Qi
Zhu, Zhaowei
Wei, Jiaheng
contents Large Language Models (LLMs) have demonstrated strong capabilities in memorizing vast amounts of knowledge across diverse domains. However, the ability to selectively forget specific knowledge is critical for ensuring the safety and compliance of deployed models. Existing unlearning efforts typically fine-tune the model with resources such as forget data, retain data, and a calibration model. These additional gradient steps blur the decision boundary between forget and retain knowledge, making unlearning often at the expense of overall performance. To avoid the negative impact of fine-tuning, it would be better to unlearn solely at inference time by safely guarding the model against generating responses related to the forget target, without destroying the fluency of text generation. In this work, we propose Generation-time Unlearning via Adaptive Restriction and Detection (GUARD), a framework that enables dynamic unlearning during LLM generation. Specifically, we first employ a prompt classifier to detect unlearning targets and extract the corresponding forbidden token. We then dynamically penalize and filter candidate tokens during generation using a combination of token matching and semantic matching, effectively preventing the model from leaking the forgotten content. Experimental results on copyright content unlearning tasks over the Harry Potter dataset and the MUSE benchmark, as well as entity unlearning tasks on the TOFU dataset, demonstrate that GUARD achieves strong forget quality across various tasks while causing almost no degradation to the LLM's general capabilities, striking an excellent trade-off between forgetting and utility.
format Preprint
id arxiv_https___arxiv_org_abs_2505_13312
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle GUARD: Generation-time LLM Unlearning via Adaptive Restriction and Detection
Deng, Zhijie
Liu, Chris Yuhao
Pang, Zirui
He, Xinlei
Feng, Lei
Xuan, Qi
Zhu, Zhaowei
Wei, Jiaheng
Computation and Language
Large Language Models (LLMs) have demonstrated strong capabilities in memorizing vast amounts of knowledge across diverse domains. However, the ability to selectively forget specific knowledge is critical for ensuring the safety and compliance of deployed models. Existing unlearning efforts typically fine-tune the model with resources such as forget data, retain data, and a calibration model. These additional gradient steps blur the decision boundary between forget and retain knowledge, making unlearning often at the expense of overall performance. To avoid the negative impact of fine-tuning, it would be better to unlearn solely at inference time by safely guarding the model against generating responses related to the forget target, without destroying the fluency of text generation. In this work, we propose Generation-time Unlearning via Adaptive Restriction and Detection (GUARD), a framework that enables dynamic unlearning during LLM generation. Specifically, we first employ a prompt classifier to detect unlearning targets and extract the corresponding forbidden token. We then dynamically penalize and filter candidate tokens during generation using a combination of token matching and semantic matching, effectively preventing the model from leaking the forgotten content. Experimental results on copyright content unlearning tasks over the Harry Potter dataset and the MUSE benchmark, as well as entity unlearning tasks on the TOFU dataset, demonstrate that GUARD achieves strong forget quality across various tasks while causing almost no degradation to the LLM's general capabilities, striking an excellent trade-off between forgetting and utility.
title GUARD: Generation-time LLM Unlearning via Adaptive Restriction and Detection
topic Computation and Language
url https://arxiv.org/abs/2505.13312