{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/hard-to-forget-poisoning-attacks-on-certified","title":"Hard to Forget: Poisoning Attacks on Certified Machine Unlearning","arxiv_id":"2109.08266","date":"2021-09-17","proceeding":null,"authors":["Neil G. Marchant","Benjamin I. P. Rubinstein","Scott Alfeld"],"abstract":"The right to erasure requires removal of a user's information from data held by organizations, with rigorous interpretations extending to downstream products such as learned models. Retraining from scratch with the particular user's data omitted fully removes its influence on the resulting model, but comes with a high computational cost. Machine \"unlearning\" mitigates the cost incurred by full retraining: instead, models are updated incrementally, possibly only requiring retraining when approximation errors accumulate. Rapid progress has been made towards privacy guarantees on the indistinguishability of unlearned and retrained models, but current formalisms do not place practical bounds on computation. In this paper we demonstrate how an attacker can exploit this oversight, highlighting a novel attack surface introduced by machine unlearning. We consider an attacker aiming to increase the computational cost of data removal. We derive and empirically investigate a poisoning attack on certified machine unlearning where strategically designed training data triggers complete retraining when removed.","url_abs":"https://arxiv.org/abs/2109.08266v2","url_pdf":"https://arxiv.org/pdf/2109.08266v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"hard-to-forget-poisoning-attacks-on-certified","repo_url":"https://github.com/ngmarchant/attack-unlearning","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"jax","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"machine-unlearning","task_name":"Machine Unlearning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2109.08266","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2109.08266"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ngmarchant/attack-unlearning","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"unverified":11},"by_repo_kind":{"official":{"samples":11,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"8a5e359aa5894852","entry":"fashion_mnist","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"datasets.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/datasets.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"8a5e359aa5894852"}},{"code_sha256_prefix":"fd3e40a8f8b31a66","entry":"l1_proj","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"projections.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/projections.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"fd3e40a8f8b31a66"}},{"code_sha256_prefix":"16544f7487331b0e","entry":"lbfgs_minimize","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"lbfgs_minimize.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/lbfgs_minimize.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"16544f7487331b0e"}},{"code_sha256_prefix":"ac0824e8d3c3c2b8","entry":"linf_proj","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"projections.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/projections.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"ac0824e8d3c3c2b8"}},{"code_sha256_prefix":"2d79a5710c3e0b38","entry":"mnist","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"datasets.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/datasets.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"2d79a5710c3e0b38"}},{"code_sha256_prefix":"9fa62c93e01e3e6b","entry":"mnist_binary","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"datasets.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/datasets.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"9fa62c93e01e3e6b"}},{"code_sha256_prefix":"efd91a4d57b99306","entry":"normalize","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"init_experiment.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/init_experiment.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"efd91a4d57b99306"}},{"code_sha256_prefix":"3936f0ddb76eb43a","entry":"proj_grad_descent","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"grad_descent.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/grad_descent.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"3936f0ddb76eb43a"}},{"code_sha256_prefix":"303a2ef6d3d8fe00","entry":"register_pytree_node_dataclass","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"util.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/util.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"303a2ef6d3d8fe00"}},{"code_sha256_prefix":"1e6c97b7639df426","entry":"soft_thresh","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"projections.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/projections.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"1e6c97b7639df426"}},{"code_sha256_prefix":"503701aad49b036e","entry":"tree_zeros_like","repo":"ngmarchant/attack-unlearning","repo_kind":"official","path":"util.py","file_url":"https://github.com/ngmarchant/attack-unlearning/blob/HEAD/util.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"503701aad49b036e"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}