{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T05:02:06Z","timestamp":1779771726742,"version":"3.53.1"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032008275","type":"print"},{"value":"9783032008282","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T00:00:00Z","timestamp":1760659200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T00:00:00Z","timestamp":1760659200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-00828-2_7","type":"book-chapter","created":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T16:23:51Z","timestamp":1760631831000},"page":"101-122","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["PAMUS: An Entropy-Loss-Based Poisoning Attack for\u00a0Undermining Machine Unlearning"],"prefix":"10.1007","author":[{"given":"Xudong","family":"Jiang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuhang","family":"Ma","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiahui","family":"Wen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"key":"7_CR1","doi-asserted-by":"crossref","unstructured":"Alfeld, S., Zhu, X., Barford, P.: Data poisoning attacks against autoregressive models. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a030 (2016)","DOI":"10.1609\/aaai.v30i1.10237"},{"issue":"9","key":"7_CR2","doi-asserted-by":"publisher","first-page":"3203","DOI":"10.1007\/s10994-022-06178-9","volume":"111","author":"T Baumhauer","year":"2022","unstructured":"Baumhauer, T., Sch\u00f6ttle, P., Zeppelzauer, M.: Machine unlearning: linear filtration for logit-based classifiers. Mach. Learn. 111(9), 3203\u20133226 (2022)","journal-title":"Mach. Learn."},{"key":"7_CR3","unstructured":"Biggio, B., Nelson, B., Laskov, P.: Support vector machines under adversarial label noise. In: Asian Conference on Machine Learning, pp. 97\u2013112. PMLR (2011)"},{"key":"7_CR4","unstructured":"Biggio, B., Nelson, B., Laskov, P.: Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 (2012)"},{"key":"7_CR5","doi-asserted-by":"crossref","unstructured":"Bourtoule, L., et al.: Machine unlearning. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 141\u2013159. IEEE (2021)","DOI":"10.1109\/SP40001.2021.00019"},{"key":"7_CR6","doi-asserted-by":"crossref","unstructured":"Cao, Y., Yang, J.: Towards making systems forget with machine unlearning. In: 2015 IEEE Symposium on Security and Privacy, pp. 463\u2013480. IEEE (2015)","DOI":"10.1109\/SP.2015.35"},{"key":"7_CR7","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"7_CR8","doi-asserted-by":"crossref","unstructured":"Cin\u00e0, A.E., Vascon, S., Demontis, A., Biggio, B., Roli, F., Pelillo, M.: The hammer and the nut: is bilevel optimization really needed to poison linear classifiers? In: 2021 International Joint Conference on Neural Networks (IJCNN), pp.\u00a01\u20138. IEEE (2021)","DOI":"10.1109\/IJCNN52387.2021.9533557"},{"key":"7_CR9","doi-asserted-by":"publisher","first-page":"215","DOI":"10.1111\/j.2517-6161.1958.tb00292.x","volume":"20","author":"DR Cox","year":"1958","unstructured":"Cox, D.R.: The regression analysis of binary sequences. J. Roy. Stat. Soc.: Ser. B (Methodol.) 20, 215\u2013232 (1958)","journal-title":"J. Roy. Stat. Soc.: Ser. B (Methodol.)"},{"issue":"6","key":"7_CR10","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research. IEEE Signal Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Signal Process. Mag."},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Golatkar, A., Achille, A., Soatto, S.: Eternal sunshine of the spotless net: selective forgetting in deep networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 9304\u20139312 (2020)","DOI":"10.1109\/CVPR42600.2020.00932"},{"key":"7_CR12","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"7_CR13","doi-asserted-by":"crossref","unstructured":"Graves, L., Nagisetty, V., Ganesh, V.: Amnesiac machine learning. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a035, pp. 11516\u201311524 (2021)","DOI":"10.1609\/aaai.v35i13.17371"},{"key":"7_CR14","unstructured":"Guo, C., Goldstein, T., Hannun, A., Van Der\u00a0Maaten, L.: Certified data removal from machine learning models. arXiv preprint arXiv:1911.03030 (2019)"},{"key":"7_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/978-3-030-58583-9_9","volume-title":"Computer Vision \u2013 ECCV 2020","author":"J Guo","year":"2020","unstructured":"Guo, J., Liu, C.: Practical poisoning attacks on neural networks. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12372, pp. 142\u2013158. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58583-9_9"},{"key":"7_CR16","unstructured":"Guo, T., Guo, S., Zhang, J., Xu, W., Wang, J.: Efficient attribute unlearning: towards selective removal of input attributes from feature representations. arXiv preprint arXiv:2202.13295 (2022)"},{"key":"7_CR17","first-page":"16319","volume":"34","author":"V Gupta","year":"2021","unstructured":"Gupta, V., Jung, C., Neel, S., Roth, A., Sharifi-Malvajerdi, S., Waites, C.: Adaptive machine unlearning. Adv. Neural. Inf. Process. Syst. 34, 16319\u201316330 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"7_CR18","unstructured":"He, Y., Meng, G., Chen, K., He, J., Hu, X.: Deepobliviate: a powerful charm for erasing data residual memory in deep neural networks. arXiv preprint arXiv:2105.06209 (2021)"},{"key":"7_CR19","doi-asserted-by":"crossref","unstructured":"Hu, H., et al.: A duty to forget, a right to be assured? Exposing vulnerabilities in machine unlearning services. arXiv preprint arXiv:2309.08230 (2023)","DOI":"10.14722\/ndss.2024.24252"},{"key":"7_CR20","unstructured":"Huang, H., Ma, X., Erfani, S.M., Bailey, J., Wang, Y.: Unlearnable examples: making personal data unexploitable. arXiv preprint arXiv:2101.04898 (2021)"},{"key":"7_CR21","first-page":"12080","volume":"33","author":"WR Huang","year":"2020","unstructured":"Huang, W.R., Geiping, J., Fowl, L., Taylor, G., Goldstein, T.: Metapoison: practical general-purpose clean-label data poisoning. Adv. Neural. Inf. Process. Syst. 33, 12080\u201312091 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"7_CR22","doi-asserted-by":"crossref","unstructured":"Huang, Y., et al.: Perception-guided jailbreak against text-to-image models. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a039, pp. 26238\u201326247 (2025)","DOI":"10.1609\/aaai.v39i25.34821"},{"key":"7_CR23","unstructured":"Izzo, Z., Smart, M.A., Chaudhuri, K., Zou, J.: Approximate data deletion from machine learning models. In: International Conference on Artificial Intelligence and Statistics, pp. 2008\u20132016. PMLR (2021)"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Severi, G., Pousette\u00a0Harger, N., Oprea, A.: Subpopulation data poisoning attacks. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 3104\u20133122 (2021)","DOI":"10.1145\/3460120.3485368"},{"key":"7_CR25","unstructured":"Li, B., et al.: Purifying quantization-conditioned backdoors via layer-wise activation correction with distribution approximation. In: Forty-First International Conference on Machine Learning (2024)"},{"key":"7_CR26","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"Marchant, N.G., Rubinstein, B.I., Alfeld, S.: Hard to forget: poisoning attacks on certified machine unlearning. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a036, pp. 7691\u20137700 (2022)","DOI":"10.1609\/aaai.v36i7.20736"},{"key":"7_CR28","unstructured":"Neel, S., Roth, A., Sharifi-Malvajerdi, S.: Descent-to-delete: gradient-based methods for machine unlearning. In: Algorithmic Learning Theory, pp. 931\u2013962. PMLR (2021)"},{"key":"7_CR29","first-page":"16025","volume":"33","author":"QP Nguyen","year":"2020","unstructured":"Nguyen, Q.P., Low, B.K.H., Jaillet, P.: Variational bayesian unlearning. Adv. Neural. Inf. Process. Syst. 33, 16025\u201316036 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"7_CR30","unstructured":"Nguyen, T.T., Huynh, T.T., Nguyen, P.L., Liew, A.W.C., Yin, H., Nguyen, Q.V.H.: A survey of machine unlearning. arXiv preprint arXiv:2209.02299 (2022)"},{"key":"7_CR31","doi-asserted-by":"crossref","unstructured":"Rahal, C., Verhagen, M., Kirk, D.: The rise of machine learning in the academic social sciences. AI Soc. 1\u20133 (2022)","DOI":"10.31235\/osf.io\/gydve"},{"key":"7_CR32","doi-asserted-by":"crossref","unstructured":"Ren, Z., Nguyen, T.T., Nejdl, W.: Prototype learning for interpretable respiratory sound analysis. In: ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 9087\u20139091. IEEE (2022)","DOI":"10.1109\/ICASSP43922.2022.9747014"},{"key":"7_CR33","unstructured":"Akram, S., Ann, Q.U.: Newton raphson method. Int. J. Sci. Eng. Res. 6 (2015)"},{"key":"7_CR34","doi-asserted-by":"crossref","unstructured":"Schelter, S., Grafberger, S., Dunning, T.: Hedgecut: maintaining randomised trees for low-latency machine unlearning. In: Proceedings of the 2021 International Conference on Management of Data, pp. 1545\u20131557 (2021)","DOI":"10.1145\/3448016.3457239"},{"key":"7_CR35","first-page":"18075","volume":"34","author":"A Sekhari","year":"2021","unstructured":"Sekhari, A., Acharya, J., Kamath, G., Suresh, A.T.: Remember what you want to forget: algorithms for machine unlearning. Adv. Neural. Inf. Process. Syst. 34, 18075\u201318086 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"7_CR36","doi-asserted-by":"crossref","unstructured":"Thudi, A., Deza, G., Chandrasekaran, V., Papernot, N.: Unrolling SGD: understanding factors influencing machine unlearning. In: 2022 IEEE 7th European Symposium on Security and Privacy (EuroS &P), pp. 303\u2013319. IEEE (2022)","DOI":"10.1109\/EuroSP53844.2022.00027"},{"key":"7_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"480","DOI":"10.1007\/978-3-030-58951-6_24","volume-title":"Computer Security \u2013 ESORICS 2020","author":"V Tolpegin","year":"2020","unstructured":"Tolpegin, V., Truex, S., Gursoy, M.E., Liu, L.: Data poisoning attacks against federated learning systems. In: Chen, L., Li, N., Liang, K., Schneider, S. (eds.) ESORICS 2020. LNCS, vol. 12308, pp. 480\u2013501. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58951-6_24"},{"key":"7_CR38","unstructured":"Warnecke, A., Pirch, L., Wressnegger, C., Rieck, K.: Machine unlearning of features and labels. arXiv preprint arXiv:2108.11577 (2021)"}],"container-title":["Lecture Notes in Computer Science","Engineering of Complex Computer Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00828-2_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T04:03:35Z","timestamp":1779768215000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00828-2_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"ISBN":["9783032008275","9783032008282"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00828-2_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"17 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICECCS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Engineering of Complex Computer Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hangzhou","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iceccs2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/iceccs2025-hangzhou.github.io\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}