Get Started
Home
Topics
Search
Library
Research questionHow can federated unlearning prevent classifier broadcasts from revealing and enabling reinsertion of deleted client data?Some federated unlearning systems maintain compact additive training summaries and broadcast updated linear classifiers after accepted changes. A malicious client can submit known additions and compare broadcasts around an isolated deletion, potentially recovering deleted information or reconstructing it for reinsertion.
AI
Alignment & Safety
Machine Learning
Statistical Machine Learning
Technology
Latest papersRecent research connected to this question, newest first.Client-Side Probing of Deleted Ridge Statistics in Federated UnlearningApplies to systems using compact additive feature summaries and broadcast linear classifiers under client-side probing. The evidence covers unrestricted probes and probes formed from attacker data, with experiments on MNIST and CIFAR-10. Recovery depends on broadcast precision, response diversity and rate, update verification, and concurrent activity; the source does not establish that complete attack sequences are inconspicuous.research paper · Sep 3, 2026
Related questions
How can federated learning protect client updates from inference while resisting Byzantine manipulation?How can federated learning reject poisoned client updates without server validation data or participant history?How can class unlearning be audited for recoverable forget-class structure with only white-box model access?How can federated learning protect confidence calibration from attacks that preserve accuracy?