Do not trust “deleted.” Measure forgotten.

Machine unlearning aims to remove selected training influence without rebuilding everything. Choose a forget set, compare methods against exact retraining, and watch removal quality collide with retained utility, privacy leakage, and compute cost.

unlearned ≈ retrained without Dᶠverify removal + utility + privacy
Method
0.72
8%

Training influence map

Select records to include in the forget set.

Forget confidence0%
Retain utility0%
Leakage score0%

Deletion trajectory

Distance to the exact retrain reference across optimization steps.

Ready
Step 0Cost 1×

Current result

Awaiting update

Run the method to compare it with the retrained reference.

Verification gate

Not evaluated

A deletion claim needs removal, retained performance, and attack-based evidence.

Retrain distance1.00
Membership AUC0.85
Utility drop0%
Compute

Deletion is a comparison, not a ceremony.

The strongest reference trains from scratch without the forget set. Approximate methods are useful only when their outputs, attacks, and retained-task behavior stay acceptably close to that counterfactual.

One score cannot certify forgetting.

Pair forget-set performance with retained utility, membership inference, output distance, and targeted probes. A model can fail one signal while looking clean on another.

Exact deletion is expensive.

Full retraining is the clean baseline, but it repeats almost all original compute.

≈100%

Collateral damage matters.

Destroying broad capability can make forget accuracy look excellent for the wrong reason.

Privacy attacks are evidence.

Membership inference tests whether forgotten examples still look unusually familiar.

Threat models differ.

Record deletion, class removal, poisoning repair, and generative memorization need different probes.

Audit the counterfactual.

Freeze the original checkpoint, forget set, retained set, attack suite, random seeds, and exact retrain baseline before comparing approximate deletion.

Measure the forgotten subset

Inspect loss, confidence, calibration, extraction, and task-specific behavior on the requested records.

Protect unrelated capability

Use held-out retained data and downstream tasks to expose broad degradation disguised as deletion.

Run adversarial verification

Membership inference and targeted extraction can reveal influence that average accuracy misses.

Methods trade guarantees for speed.

Hover or focus each method to expand the mechanism and its verification burden.

Export a deletion audit.

Preserve the method, threat model, evidence, and failure threshold. Then see how Superpowers builds inspectable agent tools and caches repeatable computer-use evaluations.

0 of 4 ready