{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,3]],"date-time":"2026-09-03T15:13:53Z","timestamp":1788448433805,"version":"build-2803163510"},"reference-count":58,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Science and Technology Development Fund of Macau SAR","award":["fdct0080\/2024\/RIA2"],"award-info":[{"award-number":["fdct0080\/2024\/RIA2"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1109\/tdsc.2025.3620832","type":"journal-article","created":{"date-parts":[[2025,10,20]],"date-time":"2025-10-20T17:59:31Z","timestamp":1760983171000},"page":"2030-2045","source":"Crossref","is-referenced-by-count":5,"title":["When Machine Unlearning Meets Retrieval-Augmented Generation (RAG): Keep Secret or Forget Knowledge?"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5114-4659","authenticated-orcid":false,"given":"Shang","family":"Wang","sequence":"first","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3411-7947","authenticated-orcid":false,"given":"Tianqing","family":"Zhu","sequence":"additional","affiliation":[{"name":"Faculty of Data Science, City University of Macau, Macao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7561-0992","authenticated-orcid":false,"given":"Dayong","family":"Ye","sequence":"additional","affiliation":[{"name":"Faculty of Data Science, City University of Macau, Macao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1680-2521","authenticated-orcid":false,"given":"Wanlei","family":"Zhou","sequence":"additional","affiliation":[{"name":"Faculty of Data Science, City University of Macau, Macao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3773080"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3477912"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.457"},{"key":"ref4","article-title":"Semantic uncertainty: Linguistic invariances for uncertainty estimation in natural language generation","volume-title":"Proc. 11th Int. Conf. Learn. Representations","author":"Kuhn","year":"2023"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3360454"},{"key":"ref6","article-title":"LLM self defense: By self examination, LLMs know they are being tricked","volume-title":"Proc. 2nd Tiny Papers Track ICLR 2024","author":"Phute","year":"2023"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3175616"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3582829"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3346"},{"key":"ref10","article-title":"Offset unlearning for large language models","author":"Huang","year":"2025","journal-title":"Trans. Mach. Learn. Res."},{"key":"ref11","first-page":"40034","article-title":"In-context unlearning: Language models as few-shot unlearners","volume-title":"Proc. 41st Int. Conf. Mach. Learn.","volume":"235","author":"Pawelczyk","year":"2024"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.107"},{"key":"ref13","article-title":"Who\u2019s Harry Potter? Approximate unlearning in LLMs","author":"Eldan","year":"2023"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.738"},{"key":"ref15","article-title":"On large language model continual unlearning","volume-title":"Proc. 13th Int. Conf. Learn. Representations","author":"Gao","year":"2025"},{"key":"ref16","article-title":"SoK: Machine unlearning for large language models","author":"Ren","year":"2025"},{"key":"ref17","article-title":"Ununlearning: Unlearning is not sufficient for content regulation in advanced generative AI","author":"Shumailov","year":"2024"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW63382.2024.00014"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671470"},{"key":"ref20","first-page":"1709","article-title":"Data-free model-related attacks: Unleashing the potential of generative AI","volume-title":"Proc. 34th USENIX Secur. Symp.","author":"Ye","year":"2025"},{"key":"ref21","first-page":"3827","article-title":"PoisonedRAG: Knowledge poisoning attacks to retrieval-augmented generation of large language models","volume-title":"Proc. 34th USENIX Secur. Symp.","author":"Zou","year":"2025"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-96-9101-2_8"},{"key":"ref23","article-title":"BadRAG: Identifying vulnerabilities in retrieval augmented generation of large language models","author":"Xue","year":"2024"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00019"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230080"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559352"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3603620"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3265506"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23087"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512222"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3328269"},{"key":"ref32","first-page":"3832","article-title":"Certified data removal from machine learning models","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","author":"Guo","year":"2020"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref34","first-page":"2633","article-title":"Extracting training data from large language models","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur. 21)","author":"Carlini","year":"2021"},{"key":"ref35","article-title":"Do membership inference attacks work on large language models?","volume-title":"Proc. 1st Conf. Lang. Model.","author":"Duan","year":"2024"},{"key":"ref36","article-title":"Detecting pretraining data from large language models","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Shi","year":"2024"},{"key":"ref37","article-title":"TrojanRAG: Retrieval-augmented generation can be backdoor driver in large language models","author":"Cheng","year":"2024"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3690624.3709194"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00530"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3764113"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670361"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/MIPR62202.2024.00031"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/tip.2025.3644175"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-emnlp.432"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121364"},{"key":"ref46","article-title":"Measuring massive multitask language understanding","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Hendrycks","year":"2020"},{"key":"ref47","article-title":"Think you have solved question answering? Try arc, the AI2 reasoning challenge","author":"Clark","year":"2018"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670388"},{"key":"ref49","article-title":"Rag-Flow","year":"2023"},{"key":"ref50","article-title":"Erasing concepts from text-to-image diffusion models with few-shot unlearning","volume-title":"Proc. 35th Brit. Mach. Vision Conf.","author":"Fuchi","year":"2024"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW63382.2024.00182"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10095889"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/s41019-025-00335-5"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-industry.103"},{"key":"ref55","article-title":"Deepseek LLM: Scaling open-source language models with longtermism","author":"Bi","year":"2024"},{"key":"ref56","first-page":"1831","article-title":"Formalizing and benchmarking prompt injection attacks and defenses","volume-title":"Proc. 33rd USENIX Secur. Symp. (USENIX Secur.)","author":"Liu","year":"2024"},{"key":"ref57","article-title":"Self-RAG: Learning to retrieve, generate, and critique through self-reflection","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Asai","year":"2024"},{"key":"ref58","article-title":"Unsupervised dense information retrieval with contrastive learning","author":"Izacard","year":"2022","journal-title":"Trans. Mach. Learn. Res."}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11434575\/11207222.pdf?arnumber=11207222","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T01:16:01Z","timestamp":1773710161000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11207222\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":58,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3620832","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]}}}