Life sciences · Preprint
arXiv · September 8, 2026
Early or partial results. Treat as a signal, not a conclusion.
This preprint identifies and formalizes a previously undocumented artifact in machine unlearning evaluation: a single forward pass over retained data modifies BatchNorm running statistics without altering weights, reversing apparent forgetting by up to 78 percentage points. The work provides mathematical formalization and empirical validation across nine methods, but lacks peer review and clarity on generalizability beyond the tested settings.
Methodological analysis with controlled empirical validation. Nine machine unlearning methods evaluated on BatchNorm-based architectures and standard benchmarks; attacker scenarios tested with 10 unlabeled images.. Intervention: Single forward pass over retain data (weight-preserving operation modifying only BatchNorm running statistics). Compared with: GroupNorm-based architectures (control reducing artifact to zero) and membership-inference attacks.
A weight-preserving forward pass over retain data deterministically rewrites normalization state and reverses apparent forgetting by up to 78 percentage points across nine evaluated methods An attacker with as few as 10 unlabeled images recovers most of the masked accuracy GroupNorm control reduces the artifact to zero across all methods tested
Safety was not reported in the material analysed. Check the source before drawing any conclusion about harm.
The source did not state who this applies to in practice.
A methodological study identifying a confound in machine unlearning evaluation via BatchNorm artifacts, with empirical demonstration but no peer review and impact limited to evaluation practices rather than clinical or translational application.
As stated by the source record.
Quoted from the source exactly as published.
Graded across the dimensions that decide whether you should act, each from what the source actually supports. There is no single score, and where a dimension was not assessed it says so.
Approximate machine unlearning aims to remove the influence of specific training data from a trained model without retraining from scratch. We identify a previously undocumented confound in how unlearning is evaluated on BatchNorm-based architectures: a single forward pass over retain data, an operation that modifies no weight, can deterministically rewrite the model's normalization state and reverse the apparent surface-metric forgetting. We formalize this operation as a weight-preserving fixed-point operator and prove that any pre-versus-post gap it induces is provably attributable to BN running statistics rather than to any modification the unlearning method made to the weights. This attribution claim cleanly separates measurement failure (BN artifact) from encoder failure (residual weight-encoded information, recently documented in concurrent work), and the same operator framework yields a unique decomposition of linear-probe elevation into BN-measurement-bias and encoder-geometry components. Empirically, the artifact reverses headline forget accuracy by up to 78 pp across nine evaluated methods on standard benchmarks; an attacker with as few as 10 unlabeled images recovers most of the masked accuracy; and a strict GroupNorm control reduces the artifact to zero across all methods. The tested membership-inference attacks change little under recalibration, locating the observed evaluation failure in forget accuracy and linear probing.
Taken from the source record, never inferred. Follow any of these and new work involving them reaches your briefing.