{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T03:57:41Z","timestamp":1781150261730,"version":"3.54.1"},"reference-count":65,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/100022963","name":"Key Research and Development Program of Zhejiang Province","doi-asserted-by":"publisher","award":["2025C01083"],"award-info":[{"award-number":["2025C01083"]}],"id":[{"id":"10.13039\/100022963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.neunet.2026.108897","type":"journal-article","created":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T16:38:55Z","timestamp":1774543135000},"page":"108897","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["PRUNE: A patching based repair framework for certifiable and privacy-robust unlearning of neural networks"],"prefix":"10.1016","volume":"201","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-6055-7561","authenticated-orcid":false,"given":"Xuran","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7113-7635","authenticated-orcid":false,"given":"Jingyi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4866-245X","authenticated-orcid":false,"given":"Xiaohan","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5039-5651","authenticated-orcid":false,"given":"Peixin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.108897_bib0001","series-title":"Proceedings of the 2016\u202fACM SIGSAC conference on computer and communications security","first-page":"308","article-title":"Deep learning with differential privacy","author":"Abadi","year":"2016"},{"key":"10.1016\/j.neunet.2026.108897_bib0002","series-title":"Robust optimization","volume":"vol. 28","author":"Ben-Tal","year":"2009"},{"issue":"12","key":"10.1016\/j.neunet.2026.108897_bib0003","doi-asserted-by":"crossref","first-page":"6022","DOI":"10.1109\/TIP.2019.2924172","article-title":"DeepCorrect: Correcting DNN models against image distortions","volume":"28","author":"Borkar","year":"2019","journal-title":"IEEE Transactions on Image Processing"},{"key":"10.1016\/j.neunet.2026.108897_bib0004","series-title":"2021\u202fIEEE Symposium on security and privacy (SP)","first-page":"141","article-title":"Machine unlearning","author":"Bourtoule","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0005","series-title":"2018 2nd international symposium on multidisciplinary studies and innovative technologies (ismsit)","first-page":"1","article-title":"Human activity recognition using smartphones","author":"Bulbul","year":"2018"},{"key":"10.1016\/j.neunet.2026.108897_bib0006","series-title":"2015\u202fIEEE Symposium on security and privacy","first-page":"463","article-title":"Towards making systems forget with machine unlearning","author":"Cao","year":"2015"},{"key":"10.1016\/j.neunet.2026.108897_bib0007","series-title":"Proceedings of the ACM web conference 2022","first-page":"2768","article-title":"Recommendation unlearning","author":"Chen","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0008","unstructured":"Chen, M., Gao, W., Liu, G., Peng, K., & Wang, C. (2023). Boundary unlearning. arxiv: 2303.11570."},{"key":"10.1016\/j.neunet.2026.108897_bib0009","series-title":"Proceedings of the 2022\u202fACM SIGSAC conference on computer and communications security","first-page":"499","article-title":"Graph unlearning","author":"Chen","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0010","series-title":"International conference on learning representations","article-title":"Efficient model updates for approximate unlearning of graph-structured data","author":"Chien","year":"2023"},{"key":"10.1016\/j.neunet.2026.108897_bib0011","series-title":"2021\u202fIEEE 21st international conference on software quality, reliability and security (QRS)","first-page":"714","article-title":"Towards repairing neural networks correctly","author":"Dong","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0012","series-title":"Automata, languages and programming: 33rd international colloquium, ICALP 2006, Venice, Italy, july 10\u201314, 2006, proceedings, part II 33","first-page":"1","article-title":"Differential privacy","author":"Dwork","year":"2006"},{"key":"10.1016\/j.neunet.2026.108897_bib0013","first-page":"1","article-title":"Regulation (EU) 2016\/679 of the European Parliament and of the Council (General Data Protection Regulation)","volume":"L 119","author":"European Union","year":"2016","journal-title":"Official Journal of the European Union"},{"key":"10.1016\/j.neunet.2026.108897_bib0014","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"12043","article-title":"Fast machine unlearning without retraining through selective synaptic dampening","volume":"vol. 38","author":"Foster","year":"2024"},{"key":"10.1016\/j.neunet.2026.108897_bib0015","series-title":"International conference on learning representations","article-title":"Sound and complete neural network repair with minimality and locality guarantees","author":"Fu","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0016","doi-asserted-by":"crossref","first-page":"415","DOI":"10.56553\/popets-2022-0079","article-title":"Deletion inference, reconstruction, and compliance in machine (un) learning","volume":"3","author":"Gao","year":"2022","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"10.1016\/j.neunet.2026.108897_bib0017","series-title":"Proceedings of the 33rd international conference on neural information processing systems","first-page":"3518","article-title":"Making AI forget you: Data deletion in machine learning","author":"Ginart","year":"2019"},{"key":"10.1016\/j.neunet.2026.108897_bib0018","doi-asserted-by":"crossref","first-page":"260","DOI":"10.29007\/699q","article-title":"Minimal modifications of deep neural networks using verification","volume":"73","author":"Goldberger","year":"2020","journal-title":"EPiC Series in Computing"},{"key":"10.1016\/j.neunet.2026.108897_bib0019","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"11516","article-title":"Amnesiac machine learning","volume":"vol. 35","author":"Graves","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0020","unstructured":"Gu, T., Dolan-Gavitt, B., & Garg, S. (2017). BadNets: Identifying vulnerabilities in the machine learning model supply chain. arxiv: 1708.06733\">."},{"key":"10.1016\/j.neunet.2026.108897_bib0021","series-title":"International conference on machine learning","first-page":"3832","article-title":"Certified data removal from machine learning models","author":"Guo","year":"2020"},{"key":"10.1016\/j.neunet.2026.108897_bib0022","unstructured":"Hendrycks, D. (2016). Gaussian error linear units (gelus). arxiv: 1606.08415."},{"key":"10.1016\/j.neunet.2026.108897_bib0023","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"18252","article-title":"Separate the wheat from the chaff: Model deficiency unlearning via parameter-efficient module operation","volume":"vol. 38","author":"Hu","year":"2024"},{"key":"10.1016\/j.neunet.2026.108897_bib0024","series-title":"International conference on artificial intelligence and statistics","first-page":"2008","article-title":"Approximate data deletion from machine learning models","author":"Izzo","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0025","series-title":"Ultralytics\/YOLOv5: v4.0 - nn.siLU activations, weights & biases logging, pytorch hub integration","author":"Jocher","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0026","series-title":"Technical Report","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.neunet.2026.108897_bib0027","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009","journal-title":"https:\/\/www. cs. toronto. edu\/kriz\/learning-features-2009-TR. pdf"},{"issue":"11","key":"10.1016\/j.neunet.2026.108897_bib0028","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"LeCun","year":"1998","journal-title":"Proceedings of the IEEE"},{"key":"10.1016\/j.neunet.2026.108897_bib0029","series-title":"International conference on learning representations","article-title":"Towards robust, locally linear deep networks","author":"Lee","year":"2019"},{"key":"10.1016\/j.neunet.2026.108897_bib0030","unstructured":"Li, X. (2024). The repository of code and data to support patching based repair framework for certifiable unlearning. https:\/\/github.com\/dummyPRUNE\/PRUNE2024."},{"key":"10.1016\/j.neunet.2026.108897_bib0031","series-title":"2025 China automation congress (CAC)","article-title":"PRUNE: A patching based repair framework for certifiable unlearning of neural networks","author":"Li","year":"2025"},{"key":"10.1016\/j.neunet.2026.108897_bib0032","series-title":"International conference on artificial intelligence and statistics","first-page":"217","article-title":"Online forgetting process for linear regression models","author":"Li","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0033","series-title":"IEEE infocom 2022-IEEE conference on computer communications","first-page":"1749","article-title":"The right to be forgotten in federated learning: An efficient realization with rapid retraining","author":"Liu","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0034","series-title":"Proceedings of the 46th IEEE\/ACM international conference on software engineering","first-page":"1","article-title":"VeRe: Verification guided synthesis for repairing deep neural networks","author":"Ma","year":"2024"},{"key":"10.1016\/j.neunet.2026.108897_bib0035","series-title":"Proceedings of the 2018 26th ACM joint meeting on european software engineering conference and symposium on the foundations of software engineering","first-page":"175","article-title":"MODE: Automated neural network model debugging via state differential analysis and input selection","author":"Ma","year":"2018"},{"key":"10.1016\/j.neunet.2026.108897_bib0036","series-title":"Algorithmic learning theory","first-page":"931","article-title":"Descent-to-delete: Gradient-based methods for machine unlearning","author":"Neel","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0037","series-title":"Proceedings of the 34th international conference on neural information processing systems","first-page":"16025","article-title":"Variational Bayesian unlearning","author":"Nguyen","year":"2020"},{"key":"10.1016\/j.neunet.2026.108897_bib0038","doi-asserted-by":"crossref","unstructured":"Ren, J., Dai, Z., Tang, X., Liu, H., Zeng, J., Li, Z., Goutam, R., Wang, S., Xing, Y., & He, Q. (2025). A general framework to enhance fine-tuning-based LLM unlearning. arxiv: 2502.17823.","DOI":"10.18653\/v1\/2025.findings-acl.949"},{"key":"10.1016\/j.neunet.2026.108897_bib0039","series-title":"2020\u202fIEEE International conference on software maintenance and evolution (ICSME)","first-page":"717","article-title":"Few-shot guided mix for DNN repairing","author":"Ren","year":"2020"},{"key":"10.1016\/j.neunet.2026.108897_bib0040","first-page":"1","article-title":"Explainable artificial intelligence: Understanding, visualizing and interpreting deep learning models","volume":"1","author":"Samek","year":"2017","journal-title":"ITU Journal: ICT Discoveries - Special Issue 1 - The Impact of Artificial Intelligence (AI) on Communication Networks and Services"},{"key":"10.1016\/j.neunet.2026.108897_bib0041","series-title":"30th international joint conference on artificial intelligence, IJCAI 2021","first-page":"989","article-title":"Learning with selective forgetting","author":"Shibata","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0042","series-title":"2017\u202fIEEE Symposium on security and privacy (SP)","first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"Shokri","year":"2017"},{"key":"10.1016\/j.neunet.2026.108897_bib0043","first-page":"18021","article-title":"Manipulating SGD with data ordering attacks","volume":"34","author":"Shumaylov","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"4","key":"10.1016\/j.neunet.2026.108897_bib0044","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3563210","article-title":"Arachne: Search based repair of deep neural networks","volume":"32","author":"Sohn","year":"2023","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10.1016\/j.neunet.2026.108897_bib0045","series-title":"NeurIPS 2019 workshop on safety and robustness in decision making","article-title":"Correcting deep neural networks with small, generalizing patches","author":"Sotoudeh","year":"2019"},{"key":"10.1016\/j.neunet.2026.108897_bib0046","series-title":"Proceedings of the 42nd ACM SIGPLAN international conference on programming language design and implementation","first-page":"588","article-title":"Provable repair of deep neural networks","author":"Sotoudeh","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0047","series-title":"Proceedings of the 44th international conference on software engineering","first-page":"338","article-title":"Causality-based neural network repair","author":"Sun","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0048","series-title":"2nd international conference on learning representations, ICLR 2014","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"issue":"9","key":"10.1016\/j.neunet.2026.108897_bib0049","doi-asserted-by":"crossref","first-page":"13046","DOI":"10.1109\/TNNLS.2023.3266233","article-title":"Fast yet effective machine unlearning","volume":"35","author":"Tarun","year":"2024","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"10.1016\/j.neunet.2026.108897_bib0050","series-title":"2022\u202fIEEE 7th European symposium on security and privacy (euros&p)","first-page":"303","article-title":"Unrolling SGD: Understanding factors influencing machine unlearning","author":"Thudi","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0051","series-title":"31st USENIX security symposium (USENIX security 22)","first-page":"4007","article-title":"On the necessity of auditable algorithmic definitions for machine unlearning","author":"Thudi","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0052","series-title":"Computer aided verification: 33rd international conference, CAV 2021, virtual event, july 20\u201323, 2021, proceedings, part i 33","first-page":"3","article-title":"NN repair: Constraint-based repair of neural network classifiers","author":"Usman","year":"2021"},{"key":"10.1016\/j.neunet.2026.108897_bib0053","series-title":"Advances in neural information processing systems","article-title":"Attention is all you need","volume":"vol. 30","author":"Vaswani","year":"2017"},{"key":"10.1016\/j.neunet.2026.108897_bib0054","series-title":"Proc. of the 30th network and distributed system security (NDSS)","article-title":"Machine unlearning of features and labels","author":"Warnecke","year":"2023"},{"key":"10.1016\/j.neunet.2026.108897_bib0055","unstructured":"Wightman, R. (2019). Pytorch image models. 10.5281\/zenodo.4414861."},{"key":"10.1016\/j.neunet.2026.108897_bib0056","doi-asserted-by":"crossref","unstructured":"Wu, B., Zhang, H., Yang, X., Wang, S., Xue, M., Pan, S., & Yuan, X. (2023a). GraphGuard: Detecting and counteracting training data misuse in graph neural networks. arxiv: 2312.07861.","DOI":"10.14722\/ndss.2024.24441"},{"key":"10.1016\/j.neunet.2026.108897_bib0057","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"8675","article-title":"PUMA: Performance unchanged model augmentation for training data removal","volume":"vol. 36","author":"Wu","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0058","series-title":"Proceedings of the ACM web conference 2023","first-page":"651","article-title":"GIF: A general graph unlearning strategy via influence function","author":"Wu","year":"2023"},{"key":"10.1016\/j.neunet.2026.108897_bib0059","series-title":"Proceedings of the thirty-first international joint conference on artificial intelligence, IJCAI-22","first-page":"4006","article-title":"ARCANE: An efficient architecture for exact machine unlearning","author":"Yan","year":"2022"},{"key":"10.1016\/j.neunet.2026.108897_bib0060","series-title":"2018\u202fIEEE 31st computer security foundations symposium (CSF)","first-page":"268","article-title":"Privacy risk in machine learning: Analyzing the connection to overfitting","author":"Yeom","year":"2018"},{"key":"10.1016\/j.neunet.2026.108897_bib0061","first-page":"4944","article-title":"Efficient neural network robustness certification with general activation functions","volume":"31","author":"Zhang","year":"2018","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.108897_bib0062","series-title":"Proceedings of the ACM on web conference","first-page":"931","article-title":"Dynamic graph unlearning: A general and efficient post-processing method via gradient transformation","author":"Zhang","year":"2025"},{"key":"10.1016\/j.neunet.2026.108897_bib0063","first-page":"13433","article-title":"Prompt certified machine unlearning with randomized gradient smoothing and quantization","volume":"35","author":"Zhang","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.108897_bib0064","doi-asserted-by":"crossref","unstructured":"Zhou, J., Li, H., Liao, X., Zhang, B., He, W., Li, Z., Zhou, L., & Gao, X. (2023). Audit to forget: A unified method to revoke patients\u2019 private data in intelligent healthcare. 14(1), 6255.","DOI":"10.1038\/s41467-023-41703-x"},{"key":"10.1016\/j.neunet.2026.108897_bib0065","series-title":"Proceedings of the computer vision and pattern recognition conference","first-page":"20350","article-title":"Decoupled distillation to erase: A general unlearning method for any class-centric tasks","author":"Zhou","year":"2025"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026003588?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026003588?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T03:10:37Z","timestamp":1781147437000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026003588"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":65,"alternative-id":["S0893608026003588"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.108897","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"PRUNE: A patching based repair framework for certifiable and privacy-robust unlearning of neural networks","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.108897","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"108897"}}