Saved in:
Bibliographic Details
Main Authors: Dolgova, Polina, Stich, Sebastian U.
Format: Preprint
Published: 2026
Subjects:
Online Access:https://arxiv.org/abs/2601.05134
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914617132843008
author Dolgova, Polina
Stich, Sebastian U.
author_facet Dolgova, Polina
Stich, Sebastian U.
contents Certified unlearning based on differential privacy offers strong guarantees but remains largely impractical: the noisy fine-tuning approaches proposed so far achieve these guarantees but severely reduce model accuracy. We propose sequential noise scheduling, which distributes the noise budget across orthogonal subspaces of the parameter space, rather than injecting it all at once. This simple modification mitigates the destructive effect of noise while preserving the original certification guarantees. We extend the analysis of noisy fine-tuning to the subspace setting, proving that the same $(\varepsilon,δ)$ privacy budget is retained. Empirical results on image classification benchmarks show that our approach substantially improves accuracy after unlearning while remaining robust to membership inference attacks. These results show that certified unlearning can achieve both rigorous guarantees and practical utility.
format Preprint
id arxiv_https___arxiv_org_abs_2601_05134
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Sequential Subspace Noise Injection Prevents Accuracy Collapse in Certified Unlearning
Dolgova, Polina
Stich, Sebastian U.
Machine Learning
Certified unlearning based on differential privacy offers strong guarantees but remains largely impractical: the noisy fine-tuning approaches proposed so far achieve these guarantees but severely reduce model accuracy. We propose sequential noise scheduling, which distributes the noise budget across orthogonal subspaces of the parameter space, rather than injecting it all at once. This simple modification mitigates the destructive effect of noise while preserving the original certification guarantees. We extend the analysis of noisy fine-tuning to the subspace setting, proving that the same $(\varepsilon,δ)$ privacy budget is retained. Empirical results on image classification benchmarks show that our approach substantially improves accuracy after unlearning while remaining robust to membership inference attacks. These results show that certified unlearning can achieve both rigorous guarantees and practical utility.
title Sequential Subspace Noise Injection Prevents Accuracy Collapse in Certified Unlearning
topic Machine Learning
url https://arxiv.org/abs/2601.05134