{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T04:04:59Z","timestamp":1784952299316,"version":"3.55.0"},"reference-count":134,"publisher":"Association for Computing Machinery (ACM)","issue":"12","license":[{"start":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T00:00:00Z","timestamp":1778803200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372196"],"award-info":[{"award-number":["62372196"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,9,30]]},"abstract":"<jats:p>With growing demands for privacy, security, and legal compliance (e.g., GDPR), machine unlearning has become a critical technique for ensuring the controllability of learning systems. A central challenge in this area is verifying whether unlearning has been successfully performed. Although unlearning methods are widely studied, verification remains underexplored and lacks a unified framework. This survey addresses the gap by organizing existing methods into behavioral and parametric categories based on the evidence used. It compares representative approaches in terms of assumptions, strengths, and vulnerabilities, and concludes with open problems to support the development of more reliable verification mechanisms.<\/jats:p>","DOI":"10.1145\/3807451","type":"journal-article","created":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T16:03:28Z","timestamp":1778861008000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Towards Reliable Forgetting: A Survey on Machine Unlearning Verification"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0050-7146","authenticated-orcid":false,"given":"Lulu","family":"Xue","sequence":"first","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0042-9045","authenticated-orcid":false,"given":"Shengshan","family":"Hu","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-2759-8551","authenticated-orcid":false,"given":"Wei","family":"Lu","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-2870-9158","authenticated-orcid":false,"given":"Yan","family":"Shen","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-4997-2124","authenticated-orcid":false,"given":"Dongxu","family":"Li","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-5997-889X","authenticated-orcid":false,"given":"Peijin","family":"Guo","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6785-7306","authenticated-orcid":false,"given":"Ziqi","family":"Zhou","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1735-2024","authenticated-orcid":false,"given":"Minghui","family":"Li","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology","place":["Wuhan, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5611-3483","authenticated-orcid":false,"given":"Yanjun","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Technology Sydney","place":["Sydney, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9330-2662","authenticated-orcid":false,"given":"Leo","family":"Zhang","sequence":"additional","affiliation":[{"name":"Griffith University","place":["Brisbane, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,15]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"1","article-title":"General data protection regulation","volume":"25","year":"2018","unstructured":"2018. General data protection regulation. Intouch 25 (2018), 1\u20135.","journal-title":"Intouch"},{"key":"e_1_3_2_3_2","first-page":"7687","volume-title":"Proceedings of the 2021 IEEE\/CVF International Conference on Computer Vision","author":"Abusnaina Ahmed","year":"2021","unstructured":"Ahmed Abusnaina, Yuhang Wu, Sunpreet Arora, Yizhen Wang, Fei Wang, Hao Yang, and David Mohaisen. 2021. Adversarial example detection using latent neighborhood graph. In Proceedings of the 2021 IEEE\/CVF International Conference on Computer Vision. 7687\u20137696."},{"key":"e_1_3_2_4_2","doi-asserted-by":"crossref","unstructured":"Nasser Aldaghri Hessam Mahdavifar and Ahmad Beirami. 2021. Coded machine unlearning. IEEE Access 9 (2021) 88137\u201388150.","DOI":"10.1109\/ACCESS.2021.3090019"},{"key":"e_1_3_2_5_2","unstructured":"Haonan An Guang Hua Zhiping Lin and Yuguang Fang. 2024. Box-free model watermarks are prone to black-box removal attacks. arxiv:2405.09863. Retrieved from https:\/\/arxiv.org\/abs\/2405.09863"},{"key":"e_1_3_2_6_2","first-page":"4312","volume-title":"Proceedings of the 30th International Joint Conference on Artificial Intelligence.","author":"Bai Tao","year":"2021","unstructured":"Tao Bai, Jinqi Luo, Jun Zhao, Bihan Wen, and Qian Wang. 2021. Recent advances in adversarial training for adversarial robustness. In Proceedings of the 30th International Joint Conference on Artificial Intelligence.International Joint Conferences on Artificial Intelligence Organization, 4312\u20134321."},{"key":"e_1_3_2_7_2","unstructured":"Alexander Becker and Thomas Liebig. 2022. Evaluating machine unlearning via epistemic uncertainty. arxiv:2208.10836. Retrieved from https:\/\/arxiv.org\/abs\/2208.10836"},{"key":"e_1_3_2_8_2","first-page":"104995","volume-title":"Proceedings of the 38th Annual Conference on Neural Information Processing Systems","author":"Bertran Martin","year":"2024","unstructured":"Martin Bertran, Shuai Tang, Michael Kearns, Jamie H. Morgenstern, Aaron Roth, and Steven Z. Wu. 2024. Reconstruction attacks on machine unlearning: Simple models are vulnerable. In Proceedings of the 38th Annual Conference on Neural Information Processing Systems. 104995\u2013105016."},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1109\/SP40001.2021.00019","volume-title":"Proceedings of the 2021 IEEE Symposium on Security and Privacy","author":"Bourtoule Lucas","year":"2021","unstructured":"Lucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. 2021. Machine unlearning. In Proceedings of the 2021 IEEE Symposium on Security and Privacy. IEEE, 141\u2013159."},{"key":"e_1_3_2_10_2","first-page":"51515","volume-title":"Proceedings of the 37th Annual Conference on Neural Information Processing Systems","author":"Buzaglo Gon","year":"2023","unstructured":"Gon Buzaglo, Niv Haim, Gilad Yehudai, Gal Vardi, Yakir Oz, Yaniv Nikankin, and Michal Irani. 2023. Deconstructing data reconstruction: Multiclass, weight decay and general losses. In Proceedings of the 37th Annual Conference on Neural Information Processing Systems. 51515\u201351535."},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.35"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.5555\/3600270.3601889"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","unstructured":"Aobo Chen Yangyi Li Chenxu Zhao and Mengdi Huai. 2025. A survey of security and privacy issues of machine unlearning. AI Magazine 46 1 (2025) e12209. Retrieved from 10.1002\/aaai.12209","DOI":"10.1002\/aaai.12209"},{"key":"e_1_3_2_14_2","unstructured":"Huili Chen Bita Darvish Rohani and Farinaz Koushanfar. 2018. DeepMarks: A digital fingerprinting framework for deep neural networks. Cryptology ePrint Archive (2018)."},{"key":"e_1_3_2_15_2","first-page":"7766","volume-title":"Proceedings of the 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Chen Min","year":"2023","unstructured":"Min Chen, Weizhuo Gao, Gaoyang Liu, Kai Peng, and Chen Wang. 2023. Boundary unlearning: Rapid forgetting of deep networks via shifting the decision boundary. In Proceedings of the 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 7766\u20137775."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484756"},{"key":"e_1_3_2_17_2","volume-title":"Proceedings of the 11st International Conference on Learning Representations","author":"Chien Eli","year":"2022","unstructured":"Eli Chien, Chao Pan, and Olgica Milenkovic. 2022. Efficient model updates for approximate unlearning of graph-structured data. In Proceedings of the 11st International Conference on Learning Representations."},{"key":"e_1_3_2_18_2","volume-title":"Proceedings of the 38th Neural Information Processing Systems","author":"Chien Eli","year":"2024","unstructured":"Eli Chien, Haoyu Wang, Ziang Chen, and Pan Li. 2024. Certified machine unlearning via noisy stochastic gradient descent. In Proceedings of the 38th Neural Information Processing Systems."},{"key":"e_1_3_2_19_2","volume-title":"Proceedings of the 38th Neural Information Processing Systems","author":"Chien Eli","year":"2024","unstructured":"Eli Chien, Haoyu Wang, Ziang Chen, and Pan Li. 2024. Langevin unlearning: A new perspective of noisy gradient descent for machine unlearning. In Proceedings of the 38th Neural Information Processing Systems."},{"key":"e_1_3_2_20_2","volume-title":"Proceedings of the 13th International Conference on Learning Representations","author":"Chowdhury Somnath Basu Roy","year":"2025","unstructured":"Somnath Basu Roy Chowdhury, Krzysztof Marcin Choromanski, Arijit Sehanobish, Kumar Avinava Dubey, and Snigdha Chaturvedi. 2025. Towards scalable exact machine unlearning using parameter-efficient fine-tuning. In Proceedings of the 13th International Conference on Learning Representations."},{"key":"e_1_3_2_21_2","first-page":"7210","volume-title":"Proceedings of the 2023 AAAI Conference on Artificial Intelligence","author":"Chundawat Vikram S.","year":"2023","unstructured":"Vikram S. Chundawat, Ayush K. Tarun, Murari Mandal, and Mohan Kankanhalli. 2023. Can bad teaching induce forgetting? unlearning in deep networks using an incompetent teacher. In Proceedings of the 2023 AAAI Conference on Artificial Intelligence. 7210\u20137217."},{"key":"e_1_3_2_22_2","doi-asserted-by":"crossref","unstructured":"Vikram S. Chundawat Ayush K. Tarun Murari Mandal and Mohan Kankanhalli. 2023. Zero-shot machine unlearning. IEEE Transactions on Information Forensics and Security 18 (2023) 2345\u20132354.","DOI":"10.1109\/TIFS.2023.3265506"},{"key":"e_1_3_2_23_2","unstructured":"Sumanth Dathathri Stephan Zheng Tianwei Yin Richard M. Murray and Yisong Yue. 2018. Detecting adversarial examples via neural fingerprinting. arxiv:1803.03870. Retrieved from https:\/\/arxiv.org\/abs\/1803.03870"},{"key":"e_1_3_2_24_2","volume-title":"Proceedings of the 13th International Conference on Learning Representations","author":"Di Zonglin","year":"2025","unstructured":"Zonglin Di, Sixie Yu, Yevgeniy Vorobeychik, and Yang Liu. 2025. Adversarial machine unlearning. In Proceedings of the 13th International Conference on Learning Representations."},{"key":"e_1_3_2_25_2","doi-asserted-by":"crossref","first-page":"621","DOI":"10.1145\/3637528.3671744","volume-title":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","author":"Dong Yushun","year":"2024","unstructured":"Yushun Dong, Binchi Zhang, Zhenyu Lei, Na Zou, and Jundong Li. 2024. Idea: A flexible framework of certified unlearning for graph neural networks. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 621\u2013630."},{"key":"e_1_3_2_26_2","first-page":"17108","volume-title":"Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision","author":"Dukler Yonatan","year":"2023","unstructured":"Yonatan Dukler, Benjamin Bowman, Alessandro Achille, Aditya Golatkar, Ashwin Swaminathan, and Stefano Soatto. 2023. Safe: Machine unlearning with shard graphs. In Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision. 17108\u201317118."},{"key":"e_1_3_2_27_2","first-page":"1","volume-title":"Proceedings of the 2006 International Colloquium on Automata, Languages, and Programming","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork. 2006. Differential privacy. In Proceedings of the 2006 International Colloquium on Automata, Languages, and Programming. Springer, 1\u201312."},{"key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1109\/SaTML64287.2025.00033","volume-title":"Proceedings of the 2025 IEEE Conference on Secure and Trustworthy Machine Learning","author":"Eisenhofer Thorsten","year":"2025","unstructured":"Thorsten Eisenhofer, Doreen Riepel, Varun Chandrasekaran, Esha Ghosh, Olga Ohrimenko, and Nicolas Papernot. 2025. Verifiable and provably secure machine unlearning. In Proceedings of the 2025 IEEE Conference on Secure and Trustworthy Machine Learning. IEEE, 479\u2013496."},{"key":"e_1_3_2_29_2","volume-title":"Proceedings of the 12th International Conference on Learning Representations","author":"Fan Chongyu","year":"2024","unstructured":"Chongyu Fan, Jiancheng Liu, Yihua Zhang, Eric Wong, Dennis Wei, and Sijia Liu. 2024. SalUn: Empowering machine unlearning via gradient-based weight saliency in both image classification and generation. In Proceedings of the 12th International Conference on Learning Representations."},{"key":"e_1_3_2_30_2","first-page":"1605","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to \\(\\lbrace\\) Byzantine-Robust \\(\\rbrace\\) federated learning. In Proceedings of the 29th USENIX Security Symposium. 1605\u20131622."},{"key":"e_1_3_2_31_2","first-page":"2881","volume-title":"Proceedings of the 34th Annual Conference on Neural Information Processing Systems","author":"Feldman Vitaly","year":"2020","unstructured":"Vitaly Feldman and Chiyuan Zhang. 2020. What neural networks memorize and why: Discovering the long tail via influence estimation. In Proceedings of the 34th Annual Conference on Neural Information Processing Systems. 2881\u20132891."},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"7","DOI":"10.5220\/0010419600002859","volume-title":"Proceedings of the 10th International Conference on Operations Research and Enterprise Systems .","author":"Felps Daniel","year":"2021","unstructured":"Daniel Felps, Amelia Schwickerath, Joyce Williams, Trung Vuong, Alan Briggs, Matthew Hunt, Evan Sakmar, David Saranchak, and Tyler Shumaker. 2021. Class clown: Data redaction in machine unlearning at enterprise scale. In Proceedings of the 10th International Conference on Operations Research and Enterprise Systems .SCITEPRESS-Science and Technology Publications, 7\u201314."},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_34_2","doi-asserted-by":"crossref","unstructured":"Xiangshan Gao Xingjun Ma Jingyi Wang Youcheng Sun Bo Li Shouling Ji Peng Cheng and Jiming Chen. 2024. Verifi: Towards verifiable federated unlearning. IEEE Transactions on Dependable and Secure Computing 21 6 (2024) 5720\u20135736.","DOI":"10.1109\/TDSC.2024.3382321"},{"key":"e_1_3_2_35_2","unstructured":"Jiahui Geng Qing Li Herbert Woisetschlaeger Zongxiong Chen Yuxia Wang Preslav Nakov Hans-Arno Jacobsen and Fakhri Karray. 2025. A comprehensive survey of machine unlearning techniques for large language models. arxiv:1409.0473. Retrieved from https:\/\/arxiv.org\/abs\/1701.00133"},{"key":"e_1_3_2_36_2","volume-title":"Proceedings of the 33rd Annual Conference on Neural Information Processing Systems","author":"Ginart Antonio","year":"2019","unstructured":"Antonio Ginart, Melody Guan, Gregory Valiant, and James Y. Zou. 2019. Making ai forget you: Data deletion in machine learning. In Proceedings of the 33rd Annual Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_37_2","unstructured":"Shashwat Goel Ameya Prabhu Amartya Sanyal Ser-Nam Lim Philip Torr and Ponnurangam Kumaraguru. 2022. Towards adversarial evaluations for inexact machine unlearning. arxiv:2201.06640. Retrieved from https:\/\/arxiv.org\/abs\/2201.06640"},{"key":"e_1_3_2_38_2","first-page":"9304","volume-title":"Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Golatkar Aditya","year":"2020","unstructured":"Aditya Golatkar, Alessandro Achille, and Stefano Soatto. 2020. Eternal sunshine of the spotless net: Selective forgetting in deep networks. In Proceedings of the 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 9304\u20139312."},{"key":"e_1_3_2_39_2","first-page":"383","volume-title":"Proceedings of the 2020 European Conference on Computer Vision","author":"Golatkar Aditya","year":"2020","unstructured":"Aditya Golatkar, Alessandro Achille, and Stefano Soatto. 2020. Forgetting outside the box: Scrubbing deep networks of information accessible from input-output observations. In Proceedings of the 2020 European Conference on Computer Vision. Springer, 383\u2013398."},{"key":"e_1_3_2_40_2","unstructured":"Aditya Golatkar Alessandro Achille Ashwin Swaminathan and Stefano Soatto. 2023. Training data protection with compositional diffusion models. arxiv:2308.01937. Retrieved from https:\/\/arxiv.org\/abs\/2308.01937"},{"key":"e_1_3_2_41_2","doi-asserted-by":"crossref","unstructured":"Xueluan Gong Ziyao Wang Shuaike Li Yanjiao Chen and Qian Wang. 2023. A gan-based defense framework against model inversion attacks. IEEE Transactions on Information Forensics and Security 18 (2023) 4475\u20134487.","DOI":"10.1109\/TIFS.2023.3295944"},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","unstructured":"Jianping Gou Baosheng Yu Stephen J. Maybank and Dacheng Tao. 2021. Knowledge distillation: A survey. International Journal of Computer Vision 129 6 (2021) 1789\u20131819.","DOI":"10.1007\/s11263-021-01453-z"},{"key":"e_1_3_2_43_2","first-page":"11516","volume-title":"Proceedings of the 2021 AAAI Conference on Artificial Intelligence","author":"Graves Laura","year":"2021","unstructured":"Laura Graves, Vineel Nagisetty, and Vijay Ganesh. 2021. Amnesiac machine learning. In Proceedings of the 2021 AAAI Conference on Artificial Intelligence. 11516\u201311524."},{"key":"e_1_3_2_44_2","first-page":"3832","volume-title":"Proceedings of the 2020 International Conference on Machine Learning","author":"Guo Chuan","year":"2020","unstructured":"Chuan Guo, Tom Goldstein, Awni Hannun, and Laurens Van Der Maaten. 2020. Certified data removal from machine learning models. In Proceedings of the 2020 International Conference on Machine Learning. PMLR, 3832\u20133842."},{"key":"e_1_3_2_45_2","first-page":"3635","volume-title":"Proceedings of the 30th International Joint Conference on Artificial Intelligence","author":"Guo Shangwei","year":"2021","unstructured":"Shangwei Guo, Tianwei Zhang, Han Qiu, Yi Zeng, Tao Xiang, and Yang Liu. 2021. Fine-tuning is not enough: A simple yet effective watermark removal attack for DNN models. In Proceedings of the 30th International Joint Conference on Artificial Intelligence. Springer, 3635\u20133641."},{"key":"e_1_3_2_46_2","doi-asserted-by":"crossref","unstructured":"Yu Guo Yu Zhao Saihui Hou Cong Wang and Xiaohua Jia. 2023. Verifying in the dark: Verifiable machine unlearning by using invisible backdoor triggers. IEEE Transactions on Information Forensics and Security 19 (2023) 708\u2013721.","DOI":"10.1109\/TIFS.2023.3328269"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.5555\/3600270.3601935"},{"key":"e_1_3_2_48_2","doi-asserted-by":"crossref","unstructured":"Mengde Han Tianqing Zhu Lefeng Zhang Huan Huo and Wanlei Zhou. 2025. Vertical federated unlearning via backdoor certification. IEEE Transactions on Services Computing 18 2 (2025) 1110\u20131123.","DOI":"10.1109\/TSC.2025.3536312"},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"497","DOI":"10.1109\/SaTML64287.2025.00034","volume-title":"Proceedings of the 2025 IEEE Conference on Secure and Trustworthy Machine Learning","author":"Hayes Jamie","year":"2025","unstructured":"Jamie Hayes, Ilia Shumailov, Eleni Triantafillou, Amr Khalifa, and Nicolas Papernot. 2025. Inexact unlearning needs more careful evaluations to avoid a false sense of privacy. In Proceedings of the 2025 IEEE Conference on Secure and Trustworthy Machine Learning. IEEE, 497\u2013519."},{"key":"e_1_3_2_50_2","first-page":"3257","volume-title":"Proceedings of the 2024 IEEE Symposium on Security and Privacy","author":"Hu Hongsheng","year":"2024","unstructured":"Hongsheng Hu, Shuo Wang, Tian Dong, and Minhui Xue. 2024. Learn what you want to unlearn: Unlearning inversion attacks against machine unlearning. In Proceedings of the 2024 IEEE Symposium on Security and Privacy. IEEE, 3257\u20133275."},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548272"},{"key":"e_1_3_2_52_2","doi-asserted-by":"crossref","unstructured":"Thanh Trung Huynh Trong Bang Nguyen Thanh Toan Nguyen Phi Le Nguyen Hongzhi Yin Quoc Viet Hung Nguyen and Thanh Tam Nguyen. 2025. Certified unlearning for federated recommendation. ACM Transactions on Information Systems 43 2 (2025) 1\u201329.","DOI":"10.1145\/3706419"},{"key":"e_1_3_2_53_2","first-page":"2008","volume-title":"Proceedings of the 2021 International Conference on Artificial Intelligence and Statistics.","author":"Izzo Zachary","year":"2021","unstructured":"Zachary Izzo, Mary Anne Smart, Kamalika Chaudhuri, and James Zou. 2021. Approximate data deletion from machine learning models. In Proceedings of the 2021 International Conference on Artificial Intelligence and Statistics.PMLR, 2008\u20132016."},{"key":"e_1_3_2_54_2","first-page":"25","volume-title":"Proceedings of the 21st Learning and Technology Conference","author":"Jaman Layan","year":"2024","unstructured":"Layan Jaman, Reem Alsharabi, and Passent M. ElKafrawy. 2024. Machine unlearning: An overview of the paradigm shift in the evolution of AI. In Proceedings of the 21st Learning and Technology Conference. IEEE, 25\u201329."},{"key":"e_1_3_2_55_2","first-page":"22173","volume-title":"Proceedings of the 2026 AAAI Conference on Artificial Intelligence","author":"Jeon Dongjae","year":"2026","unstructured":"Dongjae Jeon, Wonje Jeung, Taeheon Kim, Albert No, and Jonghyun Choi. 2026. An information theoretic evaluation metric for strong unlearning. In Proceedings of the 2026 AAAI Conference on Artificial Intelligence. 22173\u201322181."},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00106"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"e_1_3_2_58_2","first-page":"13398","volume-title":"Proceedings of the 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Jia Xiaojun","year":"2022","unstructured":"Xiaojun Jia, Yong Zhang, Baoyuan Wu, Ke Ma, Jue Wang, and Xiaochun Cao. 2022. Las-at: Adversarial training with learnable attack strategy. In Proceedings of the 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 13398\u201313408."},{"key":"e_1_3_2_59_2","unstructured":"Ruinan Jin Minghui Chen Qiong Zhang and Xiaoxiao Li. 2023. Forgettable federated linear learning with certified data unlearning. arxiv:2306.02216. Retrieved from https:\/\/arxiv.org\/abs\/2306.02216"},{"key":"e_1_3_2_60_2","unstructured":"Minsung Kim Nakyeong Yang and Kyomin Jung. 2025. Rethinking post-unlearning behavior of large vision-language models. arxiv:2506.02541. Retrieved from https:\/\/arxiv.org\/abs\/2506.02541"},{"key":"e_1_3_2_61_2","doi-asserted-by":"crossref","first-page":"268","DOI":"10.18653\/v1\/2023.findings-ijcnlp.25","volume-title":"Findings of the Association for Computational Linguistics: IJCNLP-AACL 2023 (Findings)","author":"Kumar Vinayshekhar Bannihatti","year":"2023","unstructured":"Vinayshekhar Bannihatti Kumar, Rashmi Gangadharaiah, and Dan Roth. 2023. Privacy adhering machine un-learning in nlp. In Findings of the Association for Computational Linguistics: IJCNLP-AACL 2023 (Findings). 268\u2013277."},{"key":"e_1_3_2_62_2","first-page":"1957","volume-title":"Proceedings of the 37th Annual Conference on Neural Information Processing Systems","author":"Kurmanji Meghdad","year":"2023","unstructured":"Meghdad Kurmanji, Peter Triantafillou, Jamie Hayes, and Eleni Triantafillou. 2023. Towards unbounded machine unlearning. In Proceedings of the 37th Annual Conference on Neural Information Processing Systems. 1957\u20131987."},{"key":"e_1_3_2_63_2","doi-asserted-by":"crossref","unstructured":"Chunxiao Li Haipeng Jiang Jiankang Chen Yu Zhao Shuxuan Fu Fangming Jing and Yu Guo. 2024. An overview of machine unlearning. High-Confidence Computing 2 (2024) 100254.","DOI":"10.1016\/j.hcc.2024.100254"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681344"},{"key":"e_1_3_2_65_2","doi-asserted-by":"crossref","unstructured":"Na Li Chunyi Zhou Yansong Gao Hui Chen Zhi Zhang Boyu Kuang and Anmin Fu. 2025. Machine unlearning: Taxonomy metrics applications challenges and prospects. IEEE Transactions on Neural Networks and Learning Systems 36 8 (2025) 13709\u201313729.","DOI":"10.1109\/TNNLS.2025.3530988"},{"key":"e_1_3_2_66_2","doi-asserted-by":"crossref","unstructured":"Hengzhu Liu Ping Xiong Tianqing Zhu and Philip S. Yu. 2025. A survey on machine unlearning: Techniques and new emerged privacy risks. Journal of Information Security and Applications 90 (2025) 104010.","DOI":"10.1016\/j.jisa.2025.104010"},{"key":"e_1_3_2_67_2","first-page":"62821","volume-title":"Proceedings of the 37th Annual Conference on Neural Information Processing Systems","author":"Liu Jiaqi","year":"2023","unstructured":"Jiaqi Liu, Jian Lou, Zhan Qin, and Kui Ren. 2023. Certified minimax unlearning with generalization rates and deletion capacity. In Proceedings of the 37th Annual Conference on Neural Information Processing Systems. 62821\u201362852."},{"key":"e_1_3_2_68_2","first-page":"4892","volume-title":"Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision","author":"Liu Junxu","year":"2023","unstructured":"Junxu Liu, Mingsheng Xue, Jian Lou, Xiaoyu Zhang, Li Xiong, and Zhan Qin. 2023. Muter: Machine unlearning on adversarially trained models. In Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision. 4892\u20134902."},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796974"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796721"},{"key":"e_1_3_2_71_2","unstructured":"Zheyuan Liu Guangyao Dou Zhaoxuan Tan Yijun Tian and Meng Jiang. 2024. Machine unlearning in generative ai: A survey. arxiv:2407.20516. Retrieved from https:\/\/arxiv.org\/abs\/2407.20516"},{"key":"e_1_3_2_72_2","doi-asserted-by":"crossref","unstructured":"Ziyao Liu Yu Jiang Jiyuan Shen Minyi Peng Kwok-Yan Lam Xingliang Yuan and Xiaoning Liu. 2024. A survey on federated unlearning: Challenges methods and future directions. Computing Surveys 57 1 (2024) 1\u201338.","DOI":"10.1145\/3679014"},{"key":"e_1_3_2_73_2","doi-asserted-by":"crossref","unstructured":"Ziyao Liu Huanyi Ye Chen Chen Yongsen Zheng and Kwok-Yan Lam. 2025. Threats attacks and defenses in machine unlearning: A survey. IEEE Open Journal of the Computer Society 6 (2025) 413\u2013425.","DOI":"10.1109\/OJCS.2025.3543483"},{"key":"e_1_3_2_74_2","volume-title":"Proceedings of the ICML 2025 Workshop on Machine Unlearning for Generative AI","author":"Lu Xinyang","year":"2025","unstructured":"Xinyang Lu, Xinyuan Niu, Gregory Kang Ruey Lau, Bui Thi Cam Nhung, Rachael Hwee Ling Sim, Fanyu Wen, Chuan-Sheng Foo, See-Kiong Ng, and Bryan Kian Hsiang Low. 2025. WaterDrum: Watermarking for Data-centric Unlearning Metric. In Proceedings of the ICML 2025 Workshop on Machine Unlearning for Generative AI."},{"key":"e_1_3_2_75_2","first-page":"167","volume-title":"Proceedings of the 2022 International Conference on Provable Security","author":"Lu Zhaobo","year":"2022","unstructured":"Zhaobo Lu, Yilei Wang, Qingzhe Lv, Minghao Zhao, and Tiancai Liang. 2022. Fp 2-mia: A membership inference attack free of posterior probability in machine unlearning. In Proceedings of the 2022 International Conference on Provable Security. Springer, 167\u2013175."},{"key":"e_1_3_2_76_2","first-page":"10422","volume-title":"Proceedings of the 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Mehta Ronak","year":"2022","unstructured":"Ronak Mehta, Sourav Pal, Vikas Singh, and Sathya N. Ravi. 2022. Deep unlearning via randomized conditionally independent hessians. In Proceedings of the 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 10422\u201310431."},{"key":"e_1_3_2_77_2","unstructured":"Salvatore Mercuri Raad Khraishi Ramin Okhrati Devesh Batra Conor Hamill Taha Ghasempour and Andrew Nowlan. 2022. An introduction to machine unlearning. arxiv:2209.00939. Retrieved from https:\/\/arxiv.org\/abs\/2209.00939"},{"key":"e_1_3_2_78_2","volume-title":"Proceedings of the 2025 Neural Information Processing Systems","author":"Mu Siqiao","year":"2025","unstructured":"Siqiao Mu and Diego Klabjan. 2025. Rewind-to-delete: Certified machine unlearning for nonconvex functions. In Proceedings of the 2025 Neural Information Processing Systems."},{"key":"e_1_3_2_79_2","first-page":"17176","volume-title":"Proceedings of the 34th Annual Conference on Neural Information Processing Systems","author":"Nguyen Quoc Phong","year":"2020","unstructured":"Quoc Phong Nguyen, Bryan Kian Hsiang Low, and Patrick Jaillet. 2020. Variational bayesian unlearning. In Proceedings of the 34th Annual Conference on Neural Information Processing Systems. 17176\u201317186."},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3517406"},{"key":"e_1_3_2_81_2","doi-asserted-by":"crossref","unstructured":"Thanh Tam Nguyen Thanh Trung Huynh Zhao Ren Phi Le Nguyen Alan Wee-Chung Liew Hongzhi Yin and Quoc Viet Hung Nguyen. 2025. A survey of machine unlearning. ACM Transactions on Intelligent Systems and Technology 16 5 (2025) 1\u201346.","DOI":"10.1145\/3749987"},{"key":"e_1_3_2_82_2","volume-title":"Proceedings of the NeurIPS 2021 Workshop Privacy in Machine Learning","author":"Peste Alexandra","unstructured":"Alexandra Peste, Dan Alistarh, and Christoph H. Lampert. [n.d.]. SSSE: Efficiently erasing samples from trained machine learning models. In Proceedings of the NeurIPS 2021 Workshop Privacy in Machine Learning."},{"key":"e_1_3_2_83_2","first-page":"5142","volume-title":"Proceedings of the 2019 International conference on Machine Learning.","author":"Phuong Mary","year":"2019","unstructured":"Mary Phuong and Christoph Lampert. 2019. Towards understanding knowledge distillation. In Proceedings of the 2019 International conference on Machine Learning.PMLR, 5142\u20135151."},{"key":"e_1_3_2_84_2","volume-title":"Proceedings of the 13th International Conference on Learning Representations","author":"Qiao Xinbao","year":"2025","unstructured":"Xinbao Qiao, Meng Zhang, Ming Tang, and Ermin Wei. 2025. Hessian-free online certified unlearning. In Proceedings of the 13th International Conference on Learning Representations."},{"key":"e_1_3_2_85_2","doi-asserted-by":"crossref","unstructured":"Youyang Qu Ming Ding Nan Sun Kanchana Thilakarathna Tianqing Zhu and Dusit Niyato. 2025. The frontier of data erasure: A survey on machine unlearning for large language models. Computer 58 1 (2025) 45\u201357.","DOI":"10.1109\/MC.2024.3405397"},{"key":"e_1_3_2_86_2","doi-asserted-by":"crossref","unstructured":"Nicol\u00f2 Romandini Alessio Mora Carlo Mazzocca Rebecca Montanari and Paolo Bellavista. 2024. Federated unlearning: A survey on methods design guidelines and evaluation metrics. IEEE Transactions on Neural Networks and Learning Systems 36 7 (2024) 11697\u201311718.","DOI":"10.1109\/TNNLS.2024.3478334"},{"key":"e_1_3_2_87_2","unstructured":"Anwar Said Yuying Zhao Tyler Derr Mudassir Shabbir Waseem Abbas and Xenofon Koutsoukos. 2023. A survey of graph unlearning. arxiv:2310.02164. Retrieved from https:\/\/arxiv.org\/abs\/2310.02164"},{"key":"e_1_3_2_88_2","first-page":"18075","volume-title":"Proceedings of the 35th Annual Conference on Neural Information Processing Systems","author":"Sekhari Ayush","year":"2021","unstructured":"Ayush Sekhari, Jayadev Acharya, Gautam Kamath, and Ananda Theertha Suresh. 2021. Remember what you want to forget: Algorithms for machine unlearning. In Proceedings of the 35th Annual Conference on Neural Information Processing Systems. 18075\u201318086."},{"key":"e_1_3_2_89_2","first-page":"3206","volume-title":"Proceedings of the 2025 IEEE\/CVF Winter Conference on Applications of Computer Vision","author":"Seo Seonguk","year":"2025","unstructured":"Seonguk Seo, Dongwan Kim, and Bohyung Han. 2025. Revisiting machine unlearning with dimensional alignment. In Proceedings of the 2025 IEEE\/CVF Winter Conference on Applications of Computer Vision. IEEE, 3206\u20133215."},{"key":"e_1_3_2_90_2","doi-asserted-by":"crossref","unstructured":"Thanveer Shaik Xiaohui Tao Haoran Xie Lin Li Xiaofeng Zhu and Qing Li. 2024. Exploring the landscape of machine unlearning: A comprehensive survey and taxonomy. IEEE Transactions on Neural Networks and Learning Systems 36 7 (2024) 11676\u201311696.","DOI":"10.1109\/TNNLS.2024.3486109"},{"key":"e_1_3_2_91_2","unstructured":"Rohan Sharma Shijie Zhou Kaiyi Ji and Changyou Chen. 2024. Discriminative adversarial unlearning. arxiv:2402.06864. Retrieved from https:\/\/arxiv.org\/abs\/2402.06864"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_93_2","doi-asserted-by":"crossref","unstructured":"David M. Sommer Liwei Song Sameer Wagh and Prateek Mittal. 2022. Athena: Probabilistic verification of machine unlearning. Proceedings on Privacy Enhancing Technologies 2022 3 (2022) 268\u2013290.","DOI":"10.56553\/popets-2022-0072"},{"key":"e_1_3_2_94_2","volume-title":"Proceedings of the IEEE International Conference on Acoustics, Speech, and Signal Processing","author":"Song Yufei","year":"2025","unstructured":"Yufei Song, Ziqi Zhou, Minghui Li, Xianlong Wang, Menghao Deng, Wei Wan, Shengshan Hu, and Leo Yu Zhang. 2025. PB-UAP: Hybrid universal adversarial attack for image segmentation.. In Proceedings of the IEEE International Conference on Acoustics, Speech, and Signal Processing."},{"key":"e_1_3_2_95_2","unstructured":"Kahou Tam Kewei Xu Li Li and Huazhu Fu. 2024. Towards federated domain unlearning: Verification methodologies and challenges. arxiv:2406.03078. Retrieved from https:\/\/arxiv.org\/abs\/2406.03078"},{"key":"e_1_3_2_96_2","doi-asserted-by":"crossref","unstructured":"Ayush K. Tarun Vikram S. Chundawat Murari Mandal and Mohan Kankanhalli. 2023. Fast yet effective machine unlearning. IEEE Transactions on Neural Networks and Learning Systems 35 9 (2023) 13046\u201313055.","DOI":"10.1109\/TNNLS.2023.3266233"},{"key":"e_1_3_2_97_2","first-page":"4007","volume-title":"Proceedings of the 31st USENIX Security Symposium","author":"Thudi Anvith","year":"2022","unstructured":"Anvith Thudi, Hengrui Jia, Ilia Shumailov, and Nicolas Papernot. 2022. On the necessity of auditable algorithmic definitions for machine unlearning. In Proceedings of the 31st USENIX Security Symposium. 4007\u20134022."},{"key":"e_1_3_2_98_2","first-page":"480","volume-title":"Proceedings of the 25th European Symposium on Research in Computer Security.","author":"Tolpegin Vale","year":"2020","unstructured":"Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. 2020. Data poisoning attacks against federated learning systems. In Proceedings of the 25th European Symposium on Research in Computer Security.Springer, 480\u2013501."},{"key":"e_1_3_2_99_2","unstructured":"Yiwen Tu Pingbang Hu and Jiaqi Ma. 2024. Towards reliable empirical machine unlearning evaluation: A game-theoretic view. arxiv:2404.11577. Retrieved from https:\/\/arxiv.org\/abs\/2404.11577"},{"key":"e_1_3_2_100_2","first-page":"458","volume-title":"Proceedings of the 2024 International Conference on Pattern Recognition","author":"Vidal \u00c0lex Pujol","year":"2024","unstructured":"\u00c0lex Pujol Vidal, Anders S. Johansen, Mohammad N. S. Jahromi, Sergio Escalera, Kamal Nasrollahi, and Thomas B. Moeslund. 2024. Verifying machine unlearning with explainable ai. In Proceedings of the 2024 International Conference on Pattern Recognition. Springer, 458\u2013473."},{"key":"e_1_3_2_101_2","first-page":"6481","volume-title":"Proceedings of the 34th USENIX Security Symposium","author":"Wang Cheng-Long","year":"2025","unstructured":"Cheng-Long Wang, Qi Li, Zihang Xiang, Yinzhi Cao, and Di Wang. 2025. Towards lifecycle unlearning commitment management: Measuring sample-level unlearning completeness. In Proceedings of the 34th USENIX Security Symposium. 6481\u20136500."},{"key":"e_1_3_2_102_2","unstructured":"Linian Wang and Leye Wang. 2025. Forgetting any data at any time: A theoretically certified unlearning framework for vertical federated learning. arxiv:2502.17081. Retrieved from https:\/\/arxiv.org\/abs\/2502.17081"},{"key":"e_1_3_2_103_2","doi-asserted-by":"crossref","unstructured":"Ning Wang Yimin Chen Yang Xiao Yang Hu Wenjing Lou and Y. Thomas Hou. 2022. Manda: On adversarial example detection for network intrusion detection system. IEEE Transactions on Dependable and Secure Computing 20 2 (2022) 1139\u20131153.","DOI":"10.1109\/TDSC.2022.3148990"},{"key":"e_1_3_2_104_2","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714875"},{"key":"e_1_3_2_105_2","unstructured":"Weiqi Wang Zhiyi Tian Chenhan Zhang and Shui Yu. 2024. Machine unlearning: A comprehensive survey. arxiv:2405.07406. Retrieved from https:\/\/arxiv.org\/abs\/2405.07406"},{"key":"e_1_3_2_106_2","unstructured":"Xianlong Wang Hewen Pan Hangtao Zhang Minghui Li Shengshan Hu Ziqi Zhou Lulu Xue Peijin Guo Yichen Wang Wei Wan et\u00a0al. 2024. TrojanRobot: Backdoor attacks against robotic manipulation in the physical world. arxiv:2411.11683. Retrieved from https:\/\/arxiv.org\/abs\/2411.11683"},{"key":"e_1_3_2_107_2","volume-title":"Proceedings of the 39th Annual AAAI Conference on Artificial Intelligence","author":"Wang Yichen","year":"2025","unstructured":"Yichen Wang, Yuxuan Chou, Ziqi Zhou, Hangtao Zhang, Wei Wan, Shengshan Hu, and Minghui Li. 2025. Breaking barriers in physical-world adversarial examples: Improving robustness and transferability via robust feature. In Proceedings of the 39th Annual AAAI Conference on Artificial Intelligence."},{"key":"e_1_3_2_108_2","volume-title":"The Proceedings of the 13th International Conference on Learning Representations,","author":"Wei Stanley","year":"2025","unstructured":"Stanley Wei, Sadhika Malladi, Sanjeev Arora, and Amartya Sanyal. 2025. Provable unlearning in topic modeling and downstream tasks. In The Proceedings of the 13th International Conference on Learning Representations,."},{"key":"e_1_3_2_109_2","first-page":"551","volume-title":"Proceedings of the 2021 IEEE International Conference on Cyber Security and Resilience","author":"Wen Jing","year":"2021","unstructured":"Jing Wen, Siu-Ming Yiu, and Lucas C. K. Hui. 2021. Defending against model inversion attack by adversarial examples. In Proceedings of the 2021 IEEE International Conference on Cyber Security and Resilience. IEEE, 551\u2013556."},{"key":"e_1_3_2_110_2","doi-asserted-by":"crossref","unstructured":"Jiasi Weng Shenglong Yao Yuefeng Du Junjie Huang Jian Weng and Cong Wang. 2024. Proof of unlearning: Definitions and instantiation. IEEE Transactions on Information Forensics and Security 19 (2024) 3309\u20133323.","DOI":"10.1109\/TIFS.2024.3358993"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599271"},{"key":"e_1_3_2_112_2","first-page":"10355","volume-title":"Proceedings of the 2020 International Conference on Machine Learning","author":"Wu Yinjun","year":"2020","unstructured":"Yinjun Wu, Edgar Dobriban, and Susan Davidson. 2020. Deltagrad: Rapid retraining of machine learning models. In Proceedings of the 2020 International Conference on Machine Learning. PMLR, 10355\u201310366."},{"key":"e_1_3_2_113_2","doi-asserted-by":"crossref","unstructured":"Heng Xu Tianqing Zhu Lefeng Zhang and Wanlei Zhou. 2025. Really unlearned? verifying machine unlearning via influential sample pairs. IEEE Transactions on Dependable and Secure Computing 23 1 (2025) 1671\u20131686.","DOI":"10.1109\/TDSC.2025.3620308"},{"key":"e_1_3_2_114_2","unstructured":"Heng Xu Tianqing Zhu and Wanlei Zhou. 2024. Evaluating of machine unlearning: Robustness verification without prior modifications. arxiv:2410.10120. Retrieved from https:\/\/arxiv.org\/abs\/2410.10120"},{"key":"e_1_3_2_115_2","unstructured":"Yi Xu. 2024. Machine unlearning for traditional models and large language models: A short survey. arxiv:2404.01206. Retrieved from https:\/\/arxiv.org\/abs\/2404.01206"},{"key":"e_1_3_2_116_2","unstructured":"Hao Xuan and Xingyu Li. 2025. Verifying robust unlearning: Probing residual knowledge in unlearned models. arxiv:2504.14798. Retrieved from https:\/\/arxiv.org\/abs\/2504.14798"},{"key":"e_1_3_2_117_2","first-page":"19","volume-title":"Proceedings of the 2022 International Joint Conference on Artificial Intelligence","volume":"6","author":"Yan Haonan","year":"2022","unstructured":"Haonan Yan, Xiaoguang Li, Ziyao Guo, Hui Li, Fenghua Li, and Xiaodong Lin. 2022. ARCANE: An efficient architecture for exact machine unlearning. In Proceedings of the 2022 International Joint Conference on Artificial Intelligence Vol. 6. 19."},{"key":"e_1_3_2_118_2","first-page":"6399","volume-title":"Proceedings of the 34th USENIX Security Symposium","author":"Ye Dayong","year":"2025","unstructured":"Dayong Ye, Tianqing Zhu, Jiayang Li, Kun Gao, Bo Liu, Leo Yu Zhang, Wanlei Zhou, and Yang Zhang. 2025. Data duplication: A novel multi-purpose attack paradigm in machine unlearning. In Proceedings of the 34th USENIX Security Symposium. 6399\u20136418."},{"key":"e_1_3_2_119_2","volume-title":"The Proceedings of the 13th International Conference on Learning Representations","author":"Yi Lu","year":"2025","unstructured":"Lu Yi and Zhewei Wei. 2025. Scalable and certifiable graph unlearning: Overcoming the approximation error barrier. In The Proceedings of the 13th International Conference on Learning Representations."},{"key":"e_1_3_2_120_2","first-page":"58717","volume-title":"Proceedings of the 2024 International Conference on Machine Learning","author":"Zhang Binchi","year":"2024","unstructured":"Binchi Zhang, Zihan Chen, Cong Shen, and Jundong Li. 2024. Verification of machine unlearning is fragile. In Proceedings of the 2024 International Conference on Machine Learning. PMLR, 58717\u201358738."},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.5555\/3692070.3694496"},{"key":"e_1_3_2_122_2","volume-title":"Proceedings of the 33rd International Joint Conference on Artificial Intelligence","author":"Zhang Hangtao","year":"2024","unstructured":"Hangtao Zhang, Shengshan Hu, Yichen Wang, Leo Yu Zhang, Ziqi Zhou, Xianlong Wang, Yanjun Zhang, and Chao Chen. 2024. Detector collapse: Backdooring object detection to catastrophic overload or blindness. In Proceedings of the 33rd International Joint Conference on Artificial Intelligence."},{"key":"e_1_3_2_123_2","doi-asserted-by":"crossref","unstructured":"Haibo Zhang Toru Nakamura Takamasa Isohara and Kouichi Sakurai. 2023. A review on machine unlearning. SN Computer Science 4 4 (2023) 337.","DOI":"10.1007\/s42979-023-01767-4"},{"key":"e_1_3_2_124_2","first-page":"24377","volume-title":"Proceedings of the 2025 Computer Vision and Pattern Recognition Conference","author":"Zhang Hangtao","year":"2025","unstructured":"Hangtao Zhang, Yichen Wang, Shihui Yan, Chenyu Zhu, Ziqi Zhou, Linshan Hou, Shengshan Hu, Minghui Li, Yanjun Zhang, and Leo Yu Zhang. 2025. Test-time backdoor detection for object detection models. In Proceedings of the 2025 Computer Vision and Pattern Recognition Conference. 24377\u201324386."},{"key":"e_1_3_2_125_2","doi-asserted-by":"crossref","unstructured":"Xiaoyu Zhang Chenyang Zhang Jian Lou Kai Wu Zilong Wang and Xiaofeng Chen. 2024. DuplexGuard: Safeguarding deletion right in machine unlearning via duplex watermarking. IEEE Transactions on Dependable and Secure Computing 22 2 (2024) 1717\u20131731.","DOI":"10.1109\/TDSC.2024.3456811"},{"key":"e_1_3_2_126_2","first-page":"385","volume-title":"Proceedings of the 2020 European Conference on Computer Vision","author":"Zhang Yimeng","year":"2024","unstructured":"Yimeng Zhang, Jinghan Jia, Xin Chen, Aochuan Chen, Yihua Zhang, Jiancheng Liu, Ke Ding, and Sijia Liu. 2024. To generate or not? safety-driven unlearned diffusion models are still easy to generate unsafe images... for now. In Proceedings of the 2020 European Conference on Computer Vision. Springer, 385\u2013403."},{"key":"e_1_3_2_127_2","unstructured":"Yang Zhao Jiaxi Yang Yiling Tao Lixu Wang Xiaoxiao Li and Dusit Niyato. 2023. A survey of federated unlearning: A taxonomy challenges and future directions. arxiv:2310.19218. Retrieved from https:\/\/arxiv.org\/abs\/2310.19218"},{"key":"e_1_3_2_128_2","first-page":"175","volume-title":"Proceedings of the 2022 European Conference on Computer Vision","author":"Zheng Runkai","year":"2022","unstructured":"Runkai Zheng, Rongjun Tang, Jianze Li, and Li Liu. 2022. Data-free backdoor removal based on channel lipschitzness. In Proceedings of the 2022 European Conference on Computer Vision. Springer, 175\u2013191."},{"key":"e_1_3_2_129_2","doi-asserted-by":"crossref","first-page":"3433","DOI":"10.1145\/3627673.3679804","volume-title":"Proceedings of the 33rd ACM International Conference on Information and Knowledge Management","author":"Zhong Da","year":"2024","unstructured":"Da Zhong, Xiuling Wang, Zhichao Xu, Jun Xu, and Wendy Hui Wang. 2024. Interaction-level membership inference attack against recommender systems with long-tailed distribution. In Proceedings of the 33rd ACM International Conference on Information and Knowledge Management. 3433\u20133442."},{"key":"e_1_3_2_130_2","doi-asserted-by":"crossref","unstructured":"Chunyi Zhou Yansong Gao Anmin Fu Kai Chen Zhi Zhang Minhui Xue Zhiyang Dai Shouling Ji and Yuqing Zhang. 2025. TruVRF: Towards triple-granularity verification on machine unlearning. IEEE Transactions on Information Forensics and Security 20 (2025) 4844\u20134859.","DOI":"10.1109\/TIFS.2025.3565991"},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612454"},{"key":"e_1_3_2_132_2","first-page":"4345","volume-title":"Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision","author":"Zhou Ziqi","year":"2023","unstructured":"Ziqi Zhou, Shengshan Hu, Ruizhi Zhao, Qian Wang, Leo Yu Zhang, Junhui Hou, and Hai Jin. 2023. Downstream-agnostic adversarial examples. In Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision. 4345\u20134355."},{"key":"e_1_3_2_133_2","volume-title":"Proceedings of the 39th Annual AAAI Conference on Artificial Intelligence","author":"Zhou Ziqi","year":"2025","unstructured":"Ziqi Zhou, Bowen Li, Yufei Song, Shengshan Hu, Wei Wan, Leo Yu Zhang, Dezhong Yao, and Hai Jin. 2025. NumbOD: A spatial-frequency fusion attack against object detectors. In Proceedings of the 39th Annual AAAI Conference on Artificial Intelligence."},{"key":"e_1_3_2_134_2","volume-title":"Proceedings of the 2024 IEEE Symposium on Security and Privacy","author":"Zhou Ziqi","year":"2024","unstructured":"Ziqi Zhou, Minghui Li, Wei Liu, Shengshan Hu, Yechao Zhang, Wei Wan, Lulu Xue, Leo Yu Zhang, Dezhong Yao, and Hai Jin. 2024. Securely fine-tuning pre-trained encoders against adversarial examples. In Proceedings of the 2024 IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_135_2","volume-title":"Proceedings of the 38th Annual Conference on Neural Information Processing Systems","author":"Zhou Ziqi","year":"2024","unstructured":"Ziqi Zhou, Yufei Song, Minghui Li, Shengshan Hu, Xianlong Wang, Leo Yu Zhang, Dezhong Yao, and Hai Jin. 2024. Darksam: Fooling segment anything model to segment nothing. In Proceedings of the 38th Annual Conference on Neural Information Processing Systems."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3807451","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T16:11:28Z","timestamp":1778861488000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3807451"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,15]]},"references-count":134,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2026,9,30]]}},"alternative-id":["10.1145\/3807451"],"URL":"https:\/\/doi.org\/10.1145\/3807451","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,15]]},"assertion":[{"value":"2025-07-13","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-24","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}