arXiv AI

Leak-Resistant Unlearning: A New Benchmark for Evaluating Multi-Hop Reasoning Consistency and Recovery Robustness

arXiv:2608. 04519v1 Announce Type: new Abstract: Benchmarking machine unlearning methods is critical to understand whether sensitive knowledge is removed from large language models (LLMs) or not.

arXiv Machine Learning
Sep 3

GONE: Structural Knowledge Unlearning via Neighborhood-Expanded Distribution Shaping

The paper introduces GONE, a benchmark for evaluating knowledge unlearning in large language models using structured knowledge graphs, and presents Neighborhood-Expanded Distribution Shaping (NEDS), a framework that leverages graph connectivity to separate forgotten facts from their semantic neighborhood. GONE disentangles direct fact removal, reasoning-based leakage, and catastrophic forgetting, while NEDS achieves high unlearning efficacy and locality on LLaMA-3-8B and Mistral-7B. The dataset is publicly available on Hugging Face.

By Chahana Dahal, Ashutosh Balasubramaniam, Zuobin Xiong
arXiv Computation and Language
Aug 25

Can LLMs Truly Forget? Revealing Unlearning Gaps Through Adversarial Evaluation

arXiv:2608.21606v1 Announce Type: new Abstract: Machine unlearning aims to remove the influence of targeted training data from a model while preserving its remaining capabilities, but evaluating whet...

By Ayush Gupta, Hima Varshini Surisetty, Sreevidya Bollineni, Varad Ingale, Tuhina Tripathi, Abhishek Lalwani, Somya Chatterjee, Sadid Hasan
arXiv AI
Aug 28

Graph-Guided Selective Unlearning for Language Models: Controlling Support Routes Beyond Forget Seeds

The paper introduces GRAPHSU, a graph‑guided selective unlearning method for language models that expands deletion beyond explicitly identified forget seeds. By constructing a weighted support‑route graph and propagating deletion pressure, GRAPHSU applies graded forgetting to high‑risk neighboring examples. Experiments on the TOFU and PISTOL benchmarks with GPT‑2 Medium and Llama‑3.2‑3B‑Instruct show that GRAPHSU achieves the lowest utility‑feasible soft leakage, reducing leakage by up to 49.5 percentage points compared to a seed‑only baseline.

By Waqas Khan, Tabinda Sarwar, Jingyue Cong, Xun Yi, Estrid He
arXiv Computation and Language
Aug 27

Query-Side Attacks on GNN-Based KGQA: Tracing Failures from Entity Linking to Answer Generation

The paper investigates where failures occur in GNN‑based Knowledge Graph Question Answering pipelines when faced with adversarial question perturbations. By isolating stages—entity linking, subgraph retrieval, GNN reasoning, and answer generation—and applying two answer‑preserving attacks (Compositional Restructuring and Relation Synonym Swap), the authors find that subgraph construction is responsible for over 99% of end‑to‑end failures, even though the correct answer is often present in the retrieved subgraph. This challenges the assumption that reasoning models are the weak link and highlights subgraph construction as the critical mitigation target.

By Pankaj Kumar, Subhankar Mishra
arXiv AI
Sep 21

GUARD: Natural Forgetting in Large Reasoning Models via Guided Answer-Reasoning Distillation

The paper introduces GUARD, a method for natural forgetting in large reasoning models that transforms unsafe disclosures into safe-exit trajectories using guided answer‑reasoning distillation. It aligns a frozen model with guidance tokens and distills this behavior into the parameters, aiming for a coherent, non‑disclosing chain of thought followed by a refusal‑style answer. The authors also propose the Natural Forgetting Reasoning Score (NFRS) to evaluate structural stability, fluency, and unsupported substitutes, and demonstrate GUARD’s effectiveness on R‑TOFU and a STAR‑1‑derived harmful‑intent setting.

By Zeyu Yan, Guanghao Zhou, Minghui Qiu, Ming Gao, Cen Chen
arXiv Computation and Language
Sep 17

Multi-Hop Knowledge Composition is Bound by Pretraining Exposure

Large Language Models struggle with implicit multi‑hop reasoning, correctly answering individual facts but failing to combine them in a single pass. In a controlled setting, the authors show that this failure persists even with high 1‑hop accuracy, indicating it is due to pretraining exposure rather than missing knowledge. They test nine data‑centric augmentation formats and find that only individuals seen in compositional contexts during pretraining enable transfer to unseen questions, proving exposure to such contexts is necessary for implicit multi‑hop reasoning.

By Yannis Karmim, Luis Marti, Djam\'e Seddah, Valentin Barri\`ere