Scrutinising Parametric Distance Verification in Unlearning: A Coupling Perspective
摘要
Parametric distance verification is a widely used auditing method in machine unlearning. It evaluates unlearning success by measuring the distance between the unlearned model and a retrained reference model in the parameter space. This paper shows that this verification approach has a fundamental blind spot. We propose an analytical framework based on coupling and decoupling, which shows that the effectiveness of forgotten parametric distance in limiting information leakage depends on the relationship between the encoded forgotten information and the main task’s functional representation. Specifically, when these two are coupled in the parameter space, the parametric distance can indirectly limit leakage. However, under decoupling conditions—where the information is carried through parameter directions that have negligible effect on the main task—distance-based verification method can fail. To demonstrate this, we introduce the PRIE attack (Pseudo-Random Image Encoding), which uses pseudo-random images as carriers to encode forgotten data into an output channel that is semantically decoupled from the main task. Experiments on CIFAR-10 show that PRIE can recover all forgotten data with high fidelity while still strictly following the \(L_2\) distance constraint. These results indicate that geometric proximity in parameters does not guarantee information removal. Therefore, relying only on parametric distance is insufficient for safe machine unlearning.