Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning

SEI Report
This paper describes and proposes new methods to evaluate unlearning algorithms, revealing key limitations through experiments across state-of-the-art models and vision datasets.
Publisher

arxiv.org

DOI (Digital Object Identifier)
10.48550/arXiv.2405.19211

Abstract

Machine learning models are vulnerable to adversarial attacks, including attacks that leak information about the model’s training data. There has recently been an increase in interest about how to best address privacy concerns, especially in the presence of data-removal requests. Machine unlearning algorithms aim to efficiently update trained models to comply with data deletion requests while maintaining performance and without having to resort to retraining the model from scratch, a costly endeavor. Several algorithms in the machine unlearning literature demonstrate some level of privacy gains, but they are often evaluated only on rudimentary membership inference attacks, which do not represent realistic threats. In this paper we describe and propose alternative evaluation methods for three key shortcomings in the current evaluation of unlearning algorithms. We show the utility of our alternative evaluations via a series of experiments of state-of-the-art unlearning algorithms on different computer vision datasets, presenting a more detailed picture of the state of the field.

Part of a Collection

AI Division Publications

Cite This SEI Report

Grimes, K., Abidi, C., Frank, C., & Gallagher, S. (2024, May 29). Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning. Retrieved August 17, 2026, from https://doi.org/10.48550/arXiv.2405.19211.

@techreport{grimes_2024,
author={Grimes, Keltin and Abidi, Collin and Frank, Cole and Gallagher, Shannon},
title={Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning},
month={May},
year={2024},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.48550/arXiv.2405.19211},
url={https://doi.org/10.48550/arXiv.2405.19211},
note={Accessed: 2026-Aug-17}
}

Grimes, Keltin, Collin Abidi, Cole Frank, and Shannon Gallagher. "Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning." Software Engineering Institute, Carnegie Mellon University. arxiv.org, May 29, 2024. https://doi.org/10.48550/arXiv.2405.19211.

K. Grimes, C. Abidi, C. Frank, and S. Gallagher, "Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning," Software Engineering Institute, Carnegie Mellon University. arxiv.org, 29-May-2024 [Online]. Available: https://doi.org/10.48550/arXiv.2405.19211. [Accessed: 17-Aug-2026].

Grimes, Keltin, Collin Abidi, Cole Frank, and Shannon Gallagher. "Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning." Software Engineering Institute, Carnegie Mellon University, arxiv.org, 29 May. 2024. https://doi.org/10.48550/arXiv.2405.19211. Accessed 17 Aug. 2026.

Grimes, Keltin; Abidi, Collin; Frank, Cole; & Gallagher, Shannon. Gone but Not Forgotten: Improved Benchmarks for Machine Unlearning. arxiv.org. 2024. DOI: 10.48550/arXiv.2405.19211. https://doi.org/10.48550/arXiv.2405.19211