PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 3, 20250 citationsOpen Access

SUA: Stealthy Multimodal Large Language Model Unlearning Attack

View Full Paper
XZXianren ZhangHLHui LiuDZDelvin Ce Zhang

Key Points

  • SUA effectively recovers sensitive information that was supposedly unlearned, raising privacy concerns.
  • The specific noise pattern can recover unlearned knowledge from multimodal models with consistent results.
  • This approach uses embedding alignment loss to ensure modifications remain undetectable to human observers.
  • Results indicate that once learned content can reappear, demonstrating inherent weaknesses in unlearning methods.

Abstract

Multimodal Large Language Models (MLLMs) trained on massive data may memorize sensitive personal information and photos, posing serious privacy risks. To mitigate this, MLLM unlearning methods are proposed, which fine-tune MLLMs to reduce the ``forget'' sensitive information. However, it remains unclear whether the knowledge has been truly forgotten or just hidden in the model. Therefore, we propose to study a novel problem of LLM unlearning attack, which aims to recover the unlearned knowledge of an unlearned LLM. To achieve the goal, we propose a novel framework Stealthy Unlearning Attack (SUA) framework that learns a universal noise pattern. When applied to input images, this noise can trigger the model to reveal unlearned content. While pixel-level perturbations may be visually subtle, they can be detected in the semantic embedding space, making such attacks vulnerable to potential defenses. To improve stealthiness, we introduce an embedding alignment loss that minimizes the difference between the perturbed and denoised image embeddings, ensuring the attack is semantically unnoticeable. Experimental results show that SUA can effectively recover unlearned information from MLLMs. Furthermore, the learned noise generalizes well: a single perturbation trained on a subset of samples can reveal forgotten content in unseen images. This indicates that knowledge reappearance is not an occasional failure, but a consistent behavior.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Zhang et al. (2025) studied this question.

synapsesocial.com/papers/68e040f7a99c246f578b3bcfhttps://doi.org/10.48550/arxiv.2506.17265
Ask AI
Helpful
Bookmark
Share
View Full Paper