Projects per year
Abstract
Machine unlearning aims to remove the influence
of specific training data from a deployed model in order to
satisfy privacy and regulatory requirements. While exact un
learning methods such as retraining provide strong guarantees,
they are computationally expensive and impractical at scale.
Recent approximate unlearning approaches improve efficiency
but typically rely on access to retained training data, limiting
their applicability in privacy-constrained settings. This paper
studies the more challenging zero-shot unlearning setting, where
only the trained model and the data to be forgotten are
available. We propose FINU, a Fisher-guided noise injection
based zero-shot unlearning framework that induces selective
forgetting without using the retain dataset. FINU is motivated
by the hierarchical structure of deep neural networks (DNNs)
and employs an adaptive, layer-wise masking strategy based
on Fisher Information to identify parameters most influential
for the forget set. Controlled, learnable noise is then injected
into the selected parameters to maximize the loss on forget
samples, effectively removing their influence while preserving
generalizable knowledge. We evaluate FINU across class-level,
subclass-level, and sample-level unlearning scenarios on CIFAR
100, CIFARSuper20, and ImageNet-1k using prominent DNNs.
of specific training data from a deployed model in order to
satisfy privacy and regulatory requirements. While exact un
learning methods such as retraining provide strong guarantees,
they are computationally expensive and impractical at scale.
Recent approximate unlearning approaches improve efficiency
but typically rely on access to retained training data, limiting
their applicability in privacy-constrained settings. This paper
studies the more challenging zero-shot unlearning setting, where
only the trained model and the data to be forgotten are
available. We propose FINU, a Fisher-guided noise injection
based zero-shot unlearning framework that induces selective
forgetting without using the retain dataset. FINU is motivated
by the hierarchical structure of deep neural networks (DNNs)
and employs an adaptive, layer-wise masking strategy based
on Fisher Information to identify parameters most influential
for the forget set. Controlled, learnable noise is then injected
into the selected parameters to maximize the loss on forget
samples, effectively removing their influence while preserving
generalizable knowledge. We evaluate FINU across class-level,
subclass-level, and sample-level unlearning scenarios on CIFAR
100, CIFARSuper20, and ImageNet-1k using prominent DNNs.
| Original language | English |
|---|---|
| Title of host publication | FINU: Fisher-Informed Noise Injection for Efficient Zero-Shot Unlearning |
| Publication status | Accepted/In press - 2026 |
| Event | The International Joint Conference on Neural Networks (IJCNN) - Maastricht, Netherlands Duration: 21. Jun 2026 → 27. Jun 2026 |
Conference
| Conference | The International Joint Conference on Neural Networks (IJCNN) |
|---|---|
| Country/Territory | Netherlands |
| City | Maastricht |
| Period | 21/06/2026 → 27/06/2026 |
Funding
This work received funding from the Novo Nordisk Foundation. (Project Reference Number: NNF24OC0095455).
Keywords
- Machine Unlearning
- Deep Learning
- Neural Networks
Fingerprint
Dive into the research topics of 'FINU: Fisher-Informed Noise Injection for Efficient Zero-Shot Unlearning'. Together they form a unique fingerprint.Related projects
- 1 Active
-
TRAI: Learn to Unlearn – Towards Responsible AI (Novo Nordisk Foundation)
Gogineni, V. C. (PI)
01/08/2025 → 31/07/2028
Project: Private Foundations
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver