{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/towards-llm-unlearning-resilient-to","title":"Towards LLM Unlearning Resilient to Relearning Attacks: A Sharpness-Aware Minimization Perspective and Beyond","arxiv_id":"2502.05374","date":"2025-02-07","proceeding":null,"authors":["Chongyu Fan","Jinghan Jia","Yihua Zhang","Anil Ramakrishna","Mingyi Hong","Sijia Liu"],"abstract":"The LLM unlearning technique has recently been introduced to comply with data regulations and address the safety and ethical concerns of LLMs by removing the undesired data-model influence. However, state-of-the-art unlearning methods face a critical vulnerability: they are susceptible to ``relearning'' the removed information from a small number of forget data points, known as relearning attacks. In this paper, we systematically investigate how to make unlearned models robust against such attacks. For the first time, we establish a connection between robust unlearning and sharpness-aware minimization (SAM) through a unified robust optimization framework, in an analogy to adversarial training designed to defend against adversarial attacks. Our analysis for SAM reveals that smoothness optimization plays a pivotal role in mitigating relearning attacks. Thus, we further explore diverse smoothing strategies to enhance unlearning robustness. Extensive experiments on benchmark datasets, including WMDP and MUSE, demonstrate that SAM and other smoothness optimization approaches consistently improve the resistance of LLM unlearning to relearning attacks. Notably, smoothness-enhanced unlearning also helps defend against (input-level) jailbreaking attacks, broadening our proposal's impact in robustifying LLM unlearning. Codes are available at https://github.com/OPTML-Group/Unlearn-Smooth.","url_abs":"https://arxiv.org/abs/2502.05374v3","url_pdf":"https://arxiv.org/pdf/2502.05374v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"towards-llm-unlearning-resilient-to","repo_url":"https://github.com/optml-group/unlearn-smooth","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[],"methods":[{"method_slug":"sam","method_name":"SAM"},{"method_slug":"sharpness-aware-minimization","method_name":"Sharpness-Aware Minimization"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2502.05374","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2502.05374"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/optml-group/unlearn-smooth","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran":2,"unverified":5},"by_repo_kind":{"official":{"samples":7,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"88a4f13abd54a00c","entry":"compute_metrics","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"WMDP/src/unlearn/base.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/WMDP/src/unlearn/base.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"88a4f13abd54a00c"}},{"code_sha256_prefix":"650d5f6bfcd7d9bb","entry":"get_loss","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"WMDP/src/unlearn/base.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/WMDP/src/unlearn/base.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"650d5f6bfcd7d9bb"}},{"code_sha256_prefix":"e65d339c82c3590b","entry":"eval","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"MUSE/metrics/knowmem.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/MUSE/metrics/knowmem.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"e65d339c82c3590b"}},{"code_sha256_prefix":"224bff74610558a6","entry":"get_prefix_before_words_occur","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"MUSE/metrics/knowmem.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/MUSE/metrics/knowmem.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"224bff74610558a6"}},{"code_sha256_prefix":"16d37f44bb5f7c70","entry":"read_json","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"MUSE/utils.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/MUSE/utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"16d37f44bb5f7c70"}},{"code_sha256_prefix":"e5eddaddc316682b","entry":"read_text","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"MUSE/utils.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/MUSE/utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"e5eddaddc316682b"}},{"code_sha256_prefix":"6bb500242fe319ab","entry":"write_json","repo":"optml-group/unlearn-smooth","repo_kind":"official","path":"MUSE/utils.py","file_url":"https://github.com/optml-group/unlearn-smooth/blob/HEAD/MUSE/utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"6bb500242fe319ab"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}