AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Extracting Forgotten Prompts from Targeted Unlearned Models

arXiv · AI, language, vision and robotics · article · Sep 3, 2026 · UTC

Recent unlearning methods (e.g. NPO, DPO, LUNAR) make use of refusal alignment to suppress forgotten data. However, it has been shown that refusal responses might leave traces of unlearning, and recent attacks have been able to successfully recover some of the unlearned knowledge. In this paper, we uncover a new vulnerability. Existing attacks typically assume that the forgotten prompts are already known to the adversary and focus on recovering their answers. However, we show that the forgotten prompts themselves can be extracted by using the retained data and black-box access to the model. Ou

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-21T04:51:57.792Z. This is not the publication date.