{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:15:00Z","timestamp":1766441700199,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272183, 62071192, 62171189"],"award-info":[{"award-number":["62272183, 62071192, 62171189"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key R&D Program of China","award":["2024YFE0103800"],"award-info":[{"award-number":["2024YFE0103800"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3744827","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:32:38Z","timestamp":1763854358000},"page":"2804-2817","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Prototype Surgery: Tailoring Neural Prototypes via Soft Labels for Efficient Machine Unlearning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2566-9360","authenticated-orcid":false,"given":"Gaoyang","family":"Liu","sequence":"first","affiliation":[{"name":"Hubei Key Laboratory of Internet of Intelligence, School of EIC, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7961-5074","authenticated-orcid":false,"given":"Xijie","family":"Wang","sequence":"additional","affiliation":[{"name":"Hubei Key Laboratory of Internet of Intelligence, School of EIC, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8132-3516","authenticated-orcid":false,"given":"Zixiong","family":"Wang","sequence":"additional","affiliation":[{"name":"Hubei Key Laboratory of Internet of Intelligence, School of EIC, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1963-4954","authenticated-orcid":false,"given":"Chen","family":"Wang","sequence":"additional","affiliation":[{"name":"Hubei Key Laboratory of Internet of Intelligence, School of EIC, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1374-1882","authenticated-orcid":false,"given":"Ahmed M.","family":"Abdelmoniem","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering and Computer Science, Queen Mary University of London, London, United Kingdom"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8288-2657","authenticated-orcid":false,"given":"Desheng","family":"Wang","sequence":"additional","affiliation":[{"name":"Hubei Key Laboratory of Internet of Intelligence, School of EIC, Huazhong University of Science and Technology, Wuhan, China"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"141","article-title":"Machine unlearning","author":"Bourtoule Lucas","year":"2021","unstructured":"Lucas Bourtoule, Varun Chandrasekaran, Christopher A Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. 2021. Machine unlearning. In Proceedings of IEEE S&P. 141-159.","journal-title":"Proceedings of IEEE S&P."},{"key":"e_1_3_2_1_2_1","first-page":"1092","article-title":"Machine unlearning for random forests","author":"Brophy Jonathan","year":"2021","unstructured":"Jonathan Brophy and Daniel Lowd. 2021. Machine unlearning for random forests. In Proceedings of ICML. 1092-1104.","journal-title":"Proceedings of ICML."},{"key":"e_1_3_2_1_3_1","first-page":"463","article-title":"Towards making systems forget with machine unlearning","author":"Cao Yinzhi","year":"2015","unstructured":"Yinzhi Cao and Junfeng Yang. 2015. Towards making systems forget with machine unlearning. In Proceedings of IEEE S&P. 463-480.","journal-title":"Proceedings of IEEE S&P."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i10.28996"},{"key":"e_1_3_2_1_5_1","first-page":"7766","article-title":"Boundary unlearning: Rapid forgetting of deep networks via shifting the decision boundary","author":"Chen Min","year":"2023","unstructured":"Min Chen, Weizhuo Gao, Gaoyang Liu, Kai Peng, and Chen Wang. 2023. Boundary unlearning: Rapid forgetting of deep networks via shifting the decision boundary. In Proceedings of IEEE\/CVF CVPR. 7766-7775.","journal-title":"Proceedings of IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_6_1","first-page":"499","article-title":"Graph unlearning","author":"Chen Min","year":"2022","unstructured":"Min Chen, Zhikun Zhang, Tianhao Wang, Michael Backes, Mathias Humbert, and Yang Zhang. 2022. Graph unlearning. In Proceedings of ACM CCS. 499-513.","journal-title":"Proceedings of ACM CCS."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i6.25879"},{"key":"e_1_3_2_1_8_1","first-page":"248","article-title":"Imagenet: A large-scale hierarchical image database","author":"Deng Jia","year":"2009","unstructured":"Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. Imagenet: A large-scale hierarchical image database. In Proceedings of IEEE\/CVF CVPR. 248-255.","journal-title":"Proceedings of IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"e_1_3_2_1_10_1","first-page":"3457","article-title":"SIFU","author":"Fraboni Yann","year":"2024","unstructured":"Yann Fraboni, Martin Van Waerebeke, Kevin Scaman, Richard Vidal, Laetitia Kameni, and Marco Lorenzi. 2024. SIFU: Sequential Informed Federated Unlearning for Efficient and Provable Client Unlearning in Federated Optimization. In Proceedings of AISTATS. 3457-3465.","journal-title":"In Proceedings of AISTATS."},{"key":"e_1_3_2_1_11_1","first-page":"1322","article-title":"Model inversion attacks that exploit confidence information and basic countermeasures","author":"Fredrikson Matt","year":"2015","unstructured":"Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of ACM CCS. 1322-1333.","journal-title":"Proceedings of ACM CCS."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of NeurIPS","volume":"32","author":"Ginart Antonio","year":"2019","unstructured":"Antonio Ginart, Melody Guan, Gregory Valiant, and James Y Zou. 2019. Making ai forget you: Data deletion in machine learning. In Proceedings of NeurIPS, , Vol. 32."},{"key":"e_1_3_2_1_13_1","first-page":"9304","article-title":"Eternal sunshine of the spotless net: Selective forgetting in deep networks","author":"Golatkar Aditya","year":"2020","unstructured":"Aditya Golatkar, Alessandro Achille, and Stefano Soatto. 2020a. Eternal sunshine of the spotless net: Selective forgetting in deep networks. In Proceedings of IEEE\/CVF CVPR. 9304-9312.","journal-title":"Proceedings of IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_14_1","first-page":"383","article-title":"Forgetting outside the box: Scrubbing deep networks of information accessible from input-output observations","author":"Golatkar Aditya","year":"2020","unstructured":"Aditya Golatkar, Alessandro Achille, and Stefano Soatto. 2020b. Forgetting outside the box: Scrubbing deep networks of information accessible from input-output observations. In Proceedings of ECCV. 383-398.","journal-title":"Proceedings of ECCV."},{"key":"e_1_3_2_1_15_1","first-page":"3832","article-title":"Certified data removal from machine learning models","author":"Guo Chuan","year":"2020","unstructured":"Chuan Guo, Tom Goldstein, Awni Hannun, and Laurens Van Der Maaten. 2020. Certified data removal from machine learning models. In Proceedings of ICML. 3832-3842.","journal-title":"Proceedings of ICML."},{"key":"e_1_3_2_1_16_1","volume-title":"Selective forgetting of deep networks at a finer level than samples. CoRR, arXiv:2012.11849","author":"Hayase Tomohiro","year":"2020","unstructured":"Tomohiro Hayase, Suguru Yasutomi, and Takashi Katoh. 2020. Selective forgetting of deep networks at a finer level than samples. CoRR, arXiv:2012.11849 (2020)."},{"key":"e_1_3_2_1_17_1","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In Proceedings of IEEE\/CVF CVPR. 770-778.","journal-title":"Proceedings of IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3523273"},{"key":"e_1_3_2_1_19_1","volume-title":"Scaling laws for neural language models. CoRR, arXiv","author":"Kaplan Jared","year":"2001","unstructured":"Jared Kaplan, Sam McCandlish, Tom Henighan, Tom B Brown, Benjamin Chess, Rewon Child, Scott Gray, Alec Radford, Jeffrey Wu, and Dario Amodei. 2020. Scaling laws for neural language models. CoRR, arXiv: 2001.08361 (2020)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30118"},{"key":"e_1_3_2_1_21_1","unstructured":"Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images. Technical Report. University of Toronto Technical Report."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of NeurIPS.","author":"Kurmanji Meghdad","year":"2024","unstructured":"Meghdad Kurmanji, Peter Triantafillou, Jamie Hayes, and Eleni Triantafillou. 2024. Towards unbounded machine unlearning. In Proceedings of NeurIPS."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_24_1","first-page":"1","article-title":"Federaser: Enabling efficient client-level data removal from federated learning models","author":"Liu Gaoyang","year":"2021","unstructured":"Gaoyang Liu, Xiaoqiang Ma, Yang Yang, Chen Wang, and Jiangchuan Liu. 2021. Federaser: Enabling efficient client-level data removal from federated learning models. In Proceedings of IEEE\/ACM IWQOS. 1-10.","journal-title":"Proceedings of IEEE\/ACM IWQOS."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3155921"},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of NeurIPS","volume":"36","author":"Liu Jiancheng","year":"2024","unstructured":"Jiancheng Liu, Parikshit Ram, Yuguang Yao, Gaowen Liu, Yang Liu, PRANAY SHARMA, Sijia Liu, et al., 2024. Model sparsity can simplify machine unlearning. In Proceedings of NeurIPS, , Vol. 36."},{"key":"e_1_3_2_1_27_1","first-page":"1749","article-title":"The right to be forgotten in federated learning: An efficient realization with rapid retraining","author":"Liu Yi","year":"2022","unstructured":"Yi Liu, Lei Xu, Xingliang Yuan, Cong Wang, and Bo Li. 2022b. The right to be forgotten in federated learning: An efficient realization with rapid retraining. In Proceedings of IEEE INFOCOM. 1749-1758.","journal-title":"Proceedings of IEEE INFOCOM."},{"key":"e_1_3_2_1_28_1","first-page":"346","article-title":"Analyzing leakage of personally identifiable information in language models","author":"Lukas Nils","year":"2023","unstructured":"Nils Lukas, Ahmed Salem, Robert Sim, Shruti Tople, Lukas Wutschitz, and Santiago Zanella-B\u00e9guelin. 2023. Analyzing leakage of personally identifiable information in language models. In Proceedings of IEEE S&P. IEEE, 346-363.","journal-title":"Proceedings of IEEE S&P. IEEE"},{"key":"e_1_3_2_1_29_1","first-page":"10422","article-title":"Deep unlearning via randomized conditionally independent hessians","author":"Mehta Ronak","year":"2022","unstructured":"Ronak Mehta, Sourav Pal, Vikas Singh, and Sathya N Ravi. 2022. Deep unlearning via randomized conditionally independent hessians. In Proceedings of IEEE\/CVF CVPR. 10422-10431.","journal-title":"Proceedings of IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of IEEE S&P.","author":"M\u00fcller Rafael","year":"2019","unstructured":"Rafael M\u00fcller, Simon Kornblith, and Geoffrey E Hinton. 2019. When does label smoothing help?. In Proceedings of IEEE S&P."},{"key":"e_1_3_2_1_31_1","first-page":"16025","volume-title":"Proceedings of NeurIPS","volume":"33","author":"Nguyen Quoc Phong","year":"2020","unstructured":"Quoc Phong Nguyen, Bryan Kian Hsiang Low, and Patrick Jaillet. 2020. Variational Bayesian Unlearning. In Proceedings of NeurIPS, , Vol. 33. 16025-16036."},{"key":"e_1_3_2_1_32_1","first-page":"351","article-title":"Markov chain monte carlo-based machine unlearning: Unlearning what needs to be forgotten","author":"Nguyen Quoc Phong","year":"2022","unstructured":"Quoc Phong Nguyen, Ryutaro Oikawa, Dinil Mon Divakaran, Mun Choon Chan, and Bryan Kian Hsiang Low. 2022b. Markov chain monte carlo-based machine unlearning: Unlearning what needs to be forgotten. In Proceedings of ACM ASIACCS. 351-363.","journal-title":"Proceedings of ACM ASIACCS."},{"key":"e_1_3_2_1_33_1","volume-title":"Zhao Ren, Phi Le Nguyen, Alan Wee-Chung Liew, Hongzhi Yin, and Quoc Viet Hung Nguyen.","author":"Nguyen Thanh Tam","year":"2022","unstructured":"Thanh Tam Nguyen, Thanh Trung Huynh, Zhao Ren, Phi Le Nguyen, Alan Wee-Chung Liew, Hongzhi Yin, and Quoc Viet Hung Nguyen. 2022a. A survey of machine unlearning. CoRR, arXiv:2209.02299 (2022)."},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of NeurIPS.","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al., 2019. Pytorch: An imperative style, high-performance deep learning library. In Proceedings of NeurIPS."},{"key":"e_1_3_2_1_35_1","first-page":"7892","article-title":"On the difficulty of membership inference attacks","author":"Rezaei Shahbaz","year":"2021","unstructured":"Shahbaz Rezaei and Xin Liu. 2021. On the difficulty of membership inference attacks. In Proceedings of IEEE\/CVF CVPR. 7892-7900.","journal-title":"Proceedings of IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_36_1","first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In Proceedings of IEEE S&P. 3-18.","journal-title":"Proceedings of IEEE S&P."},{"key":"e_1_3_2_1_37_1","volume-title":"Very Deep Convolutional Networks for Large-Scale Image Recognition. CoRR, arXiv:1409.1556","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. CoRR, arXiv:1409.1556 (2014)."},{"key":"e_1_3_2_1_38_1","volume-title":"Proceedings of NeurIPS. 18892-18903","author":"Suriyakumar Vinith","year":"2022","unstructured":"Vinith Suriyakumar and Ashia C Wilson. 2022. Algorithms that approximate data removal: New results and limitations. In Proceedings of NeurIPS. 18892-18903."},{"volume-title":"The textEU general data protection regulation (textGDPR)-A Practical Guide","author":"Voigt Paul","key":"e_1_3_2_1_39_1","unstructured":"Paul Voigt and Axel Von dem Bussche. 2024. The textEU general data protection regulation (textGDPR)-A Practical Guide. Springer Cham."},{"key":"e_1_3_2_1_40_1","volume-title":"Unveiling security, privacy, and ethical concerns of ChatGPT. Journal of Information and Intelligence","author":"Wu Xiaodong","year":"2024","unstructured":"Xiaodong Wu, Ran Duan, and Jianbing Ni. 2024. Unveiling security, privacy, and ethical concerns of ChatGPT. Journal of Information and Intelligence (2024)."},{"key":"e_1_3_2_1_41_1","first-page":"10355","article-title":"Deltagrad: Rapid retraining of machine learning models","author":"Wu Yinjun","year":"2020","unstructured":"Yinjun Wu, Edgar Dobriban, and Susan Davidson. 2020. Deltagrad: Rapid retraining of machine learning models. In Proceedings of ICML. 10355-10366.","journal-title":"Proceedings of ICML."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/556"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3089942"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/s42979-023-01767-4"},{"key":"e_1_3_2_1_45_1","first-page":"253","article-title":"The secret revealer: Generative model-inversion attacks against deep neural networks","author":"Zhang Yuheng","year":"2020","unstructured":"Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, and Dawn Song. 2020. The secret revealer: Generative model-inversion attacks against deep neural networks. In Proceedings of IEEE\/CVF CVPR. 253-261.","journal-title":"Proceedings of IEEE\/CVF CVPR."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744827","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:11:21Z","timestamp":1766441481000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3744827"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":45,"alternative-id":["10.1145\/3719027.3744827","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3744827","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}